It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda XDR

Setting up SOAR for Microsoft 365 Cloud

  • Last updated on

The documentation below outlines the requirements for Barracuda XDR Cloud Automated Threat Response.

For additional background, see Cloud Automated Threat Response Microsoft 365.

These instructions are for customers using the Microsoft 365 Integration.

To configure the Microsoft 365 Integration to support remediation actions for Automated Threat Response, you must add additional API permissions to the registered application, by following the instructions below.

Add the new permissions in the Microsoft portal

  1. Log in to the Microsoft portal.

  2. Click Add a permission.

  3. Click Microsoft Graph.

  4. Select Application permissions (not delegated).

  5. Select the following:

    • User.ReadWrite.All

    • User.EnableDisableAccount.All

  6. Click Add permissions to save the changes.

    SOARM365API.png

    SOARM365API1.png

  7. After adding the new permissions, click Grant admin consent.
    This also applies to updates made to previously configured applications.

    SOARM365API2.png

  8. Ensure that the Graph API roles show the following new permissions:

    • Graph API Roles: User.ReadWrite.All, User.EnableDisableAccount.All

  9. Click Save.

To enable SOAR in XDR Dashboard

  1. Log in to XDR Dashboard.

  2. Navigate to Integrations > Microsoft 365.

  3. Ensure that the Graph API roles show the following new permissions:

    • Graph API Roles: User.ReadWrite.All, User.EnableDisableAccount.All

  4. If the Graph API roles are correct, select the Auto Remediation Enabled checkbox.

    SOARM365API3.png

  5. Click Save.