Skip to main content

Incident ResponderIncident Responder Documentation

Table of Contents

Prerequisites for Configuring Incident Responder Microsoft Services with OAuth2.0 Authentication

If your Microsoft Exchange Online account uses OAuth2.0 modern authentication, ensure you complete certain tasks before you configure Microsoft services.

To integrate Exabeam with Microsoft Azure Active Directory, register an application on the Microsoft identity platform. If you use the same email account for Microsoft services as email ingest and incident email, you may use the same application you configured for that account and ensure you configure additional permissions. Under Supported account types, ensure that you select Accounts in this organizational directory only.

After you register the application, ensure that you:

  • Save the client ID for the application you created. You use this client ID later.

  • Add a client secret and save it. You use this client secret later.

  • Restrict the application to the email account you use for Microsoft services in your Azure AD tenant. Ensure that you also enable Visible to users? settings.

  • Configure the Office 365 Exchange Online full_access_as_app permission for your application.

    Follow the same steps to configure Microsoft Graph permissions, but instead of selecting Microsoft Graph, click the APIs my organization uses tab, select Application permissions, then select Office 365 Exchange Online. Select the full_access_as_app permission, then click Add permissions.

  • Grant administration consent to the permissions you configured for your application.