Microsoft Entra
Connect your Microsoft Entra instance to Verosint for real-time identity threat detection and response, enabling faster and more efficient remediation.
This integration enables:
- STREAMING EVENTS: Stream Microsoft Entra events into Verosint for proactive threat detection and response
- ENRICHED USER PROFILES: Enrich user profiles with key metadata for better visibility and analysis
- THREAT RESPONSE:Take action directly from Verosint by revoking sessions or suspending accounts in real time.
In your Microsoft Entra admin center, navigate to the Entra Overview
-
Select Enterprise applications
-
Select New application
-
Select Create your own application
-
Type Verosint in the What's the name of your app? box and click Create
-
After creating the application, you will be redirected to the application's overview page. Select Permissions
-
Select Application registration
-
Select Add a permission
-
Select Microsoft Graph
-
Select Application permissions
-
☑️ Check the box next to the following permissions:
-
Directory.Read.All
-
AuditLog.Read.All
-
User.EnableDisableAccount.All
-
User.RevokeSessions.All
Then select Add permissions
-
-
Select Grant admin consent for Verosint
-
Copy the Application (client) ID and Directory (tenant) ID for later, then select Certificates & secrets
-
Select New client secret
-
Type Verosint with the date and select Add.
⚠️ Note the Expires value here. You will need to repeat this process and update Verosint with the new secret at this interval to keep the integration active. -
Copy the Value of the new secret. ⚠️ This is the one and only time this secret will be available.
-
Login to Verosint and navigate to the Settings page (top right corner of the browser window).
-
Select Microsoft Entra and populate the Client ID, Client Secret, and Tenant ID fields with the values you copied earlier.
Updated 3 days ago