MS365 Graph API
Last updated
This guide walks you through enabling Microsoft Graph API access in CybrHawk SIEM, including onboarding the "User Isolator" functionality.
Requirements:
Access to Microsoft 365 services (Microsoft 365 Compliance Center, Azure Active Directory)
E5 or P1/P2 Licensing (CybrHawk will automatically extract available security events based on your license).
Create an Application ID and secret as described in the Microsoft 365 Integration Guide.

In your app registration, go to API permissions.
Select Microsoft Graph.

Click Application permissions.
Add the following permissions:
Permissions
Data
Requirement
Application.Read.All
Application details and registrations
Required
ConsentRequest.Read.All
Allows the app to read consent requests and approvals without a signed-in user.
Required
Directory.Read.All
Read directory data (users, groups, apps)
Required
deviceAppManagement DeviceManagementConfiguration.Read.All DeviceManagementManagedDevices.Read.All
Access Intune device configuration, compliance policies, assignments, and the properties of Intune-managed devices.
Optional
SecurityAlert.Read.All
Access all security alerts without needing a signed-in user.
Required
SecurityIncident.Read.All
Access all security incidents without needing a signed-in user.
Required
IdentityRiskyUser.Read.All
Access your organisation's risky user data without a signed-in user.
Required
IdentityRiskyServicePrincipal.Read.All
Access your organisation's risky service principal information without a signed-in user.
Required
IdentityRiskEvent.Read.All
Access identity risk event information for the organisation.
Required
User.EnableDisableAccount.All User.RevokeSessions.All
Allows the app to revoke all sign-in sessions for a user and enable or disable user accounts, without requiring a signed-in user.
Optional
User.Read.All
Allows the app to read user profiles without a signed in user.
Required
Device.Read.All
Read your organisation’s device configuration information without a signed-in user.
Required
Reports.Read.All
Allows an app to read all service usage reports without a signed-in user. Services that provide usage reports include Office 365 and Azure Active Directory.
Required
SecurityEvents.Read.All
Allows the app to read your organization's security events without a signed-in user.
Required
AuditLog.Read.All
Allows the app to read and query your audit log activities, without a signed-in user.
Required
To enable User Isolation (Threat Containment by CybrHawk 24/7 SOC) features, also add:

Click Grant admin consent and confirm.

Log in to your CybrHawk SIEM Portal.
Navigate to Deployments > Integrations.
Click Add and select Microsoft Graph.
If you have any questions or need further assistance, please contact CybrHawk Support.
Last updated
User.EnableDisableAccount.All
User.RevokeSessions.All