Assign permissions to the WindowsDefenderATPSiemConnector application
Last updated
Last updated
1. Log in to the Microsoft Azure Portal at https://portal.azure.com with a user account that has either the Application Administrator or Global Administrator Role assigned.
2. Type App registrations in the Search bar.
3. Click App Registrations in the search results.
4. Click All applications on the App registrations page
5. Select WindowsDefenderATPSiemConnector from the Application list.
6. Select A PI permissions from the left-hand menu.
7. Click the Add a permission button.
8. Select the APIs my organization uses tab on the Request API permissions fly-out.
9. Type W indowsDefender in the Search field.
10. Select WindowsDefenderATP from the search results.
11. Select the Delegated permissions category.
12. Expand the AdvancedQuery permission and select the AdvancedQuery.Read checkbox.
13. Select the Application permissions category.
14. Expand the AdvancedQuery permission and select the AdvancedQuery.Read.All checkbox.
15. Expand the Alerts permission and select the Alert.Read.All checkbox.
16. Expand the Machine permission and select the Machine.Read.All checkbox.
17. Click the Add permissions button.
18. Click the Grant admin consent for… button.