Skip to content

What scope to use to acquire token for resource R with permission P? For example, MS Defender API? #570

Description

@dt-flo

Hello,

is it possible to gain an access token for https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/get-machines?view=o365-worldwide via interactive auth? I can't provide any other resource than microsoft graph and so I can't specify the correct scopes.

Activity

  1. rayluo commented on Jun 2, 2023

    @rayluo
    Contributor
  2. dt-flo commented on Jun 2, 2023

    @dt-flo
    Author

    But that same doc already describes the scopes, although they use the term "permissions". Do they not work?

    Unfortunately, they do not work, because those permissions are not valid graph API scopes. Requesting those permissions at graph API results in an error: Scopes not valid.

  3. dt-flo commented on Jun 2, 2023

    @dt-flo
    Author

    The following get request works:
    https://login.microsoftonline.com/TENANT_ID/oauth2/authorize?client_id=CLIENT_ID&response_type=token&resource=https%3A%2F%2Fapi.securitycenter.microsoft.com

    The important part is the parameter "resource" that specifies exactly what resource the requested API key is for.

  4. rayluo commented on Jun 3, 2023

    @rayluo
    Contributor

    The resource parameter is for an older version of token endpoint. MSAL libraries all use scope.

    Generally speaking, a scope can be concatenated by resource R and permission P, so you use R/P. For example, MS Defender API's resource is https://api.securitycenter.microsoft.com and a permission is Machine.Read. I tried https://api.securitycenter.microsoft.com/Machine.Read with MSAL Python and it at least yielded a meaningful error ("need admin approval") which is probably due to my existing test app was not set up for consuming Defender API. Regardless, you can try that scope and see if it can carry you further.

  5. dt-flo commented on Jun 3, 2023

    @dt-flo
    Author

    It worked! Thank you very much!

  6. changed the title [-]MS Defender API[/-] [+]What scope to use to acquire token for resource R with permission P? For example, MS Defender API?[/+] on Jun 6, 2023
  7. locked and limited conversation to collaborators on Jun 6, 2023
  8. converted this issue into a discussion #572 on Jun 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions