Skip to main content

Am I the only one that uses Microsoft Graph Security Integration?

  • December 21, 2024
  • 6 replies
  • 87 views

mccrilb
Forum|alt.badge.img+12

Because it doesn't work for us unless we modify the API endpoint. The correct API endpoint is

 
I opened a ticket on this issue, and an updated version of the Integration was released, but it still points to the wrong endpoint and fails to get or update alerts.
 
 
 
 

6 replies

Dmitry_Sarakeev
Staff
Forum|alt.badge.img+9

hi @mccrilb thanks for reaching out, i know there were some changes to the ms graph security integration recently, i will ask the team to check additionally


Dmitry_Sarakeev
Staff
Forum|alt.badge.img+9

Hey, following up on this ticket - our team will work on the fix, we will push to address it in the next closest releases.


_eo
Forum|alt.badge.img+4
  • Bronze 2
  • March 18, 2025

Hi @Dmitry_Sarakeev - Is there any news on when this update will occur?


ylandovskyy
Staff
Forum|alt.badge.img+16
  • Staff
  • March 19, 2025

Hi @Dmitry_Sarakeev - Is there any news on when this update will occur?


Hey @_eo ,

Just confirmed internally that this change wasn't released. Putting it into our backlog for March/April.

In the meantime, what kind of information are you planning to ingest? We have other integrations with Microsoft stack, so potentially there is a solution in those integrations for your use case.


_eo
Forum|alt.badge.img+4
  • Bronze 2
  • March 19, 2025

Hey @_eo ,

Just confirmed internally that this change wasn't released. Putting it into our backlog for March/April.

In the meantime, what kind of information are you planning to ingest? We have other integrations with Microsoft stack, so potentially there is a solution in those integrations for your use case.


Thanks for the update. We are using the M365 Defender connector and the Office365 Security and Compliance connector. We are filtering out alert service sources in the M365 Defender connector as we see duplicates when using both connectors mentioned above. Office365 S&C tends to provide better/more information compared to the same alert when ingested with M365 Defender. Does Google have a recommendation on what integrations to use for the MS stack?


ylandovskyy
Staff
Forum|alt.badge.img+16
  • Staff
  • March 19, 2025

Thanks for the update. We are using the M365 Defender connector and the Office365 Security and Compliance connector. We are filtering out alert service sources in the M365 Defender connector as we see duplicates when using both connectors mentioned above. Office365 S&C tends to provide better/more information compared to the same alert when ingested with M365 Defender. Does Google have a recommendation on what integrations to use for the MS stack?


Overall, M365 Defender is better for M365 Defender alerts, because it will try to group alerts from the same incident under the same case.

Also, it supports ability to track updates to alerts (for example, if a new artifact was added to the alert). This can be enabled/disable, because sometimes it's too noisy and currently, the only way to get updates is to create a new SecOps alert.

But it depends on the use case, we tend to not strip any data from 3rd party products, so if you see that one connector doesn't return good enough info, it can be tied to the limitations of that particular API.