<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MS Defender XSOAR Integration daily re-auth. in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ms-defender-xsoar-integration-daily-re-auth/m-p/579634#M3131</link>
    <description>&lt;P&gt;Awesome thanks for the reply and additional documentation. The permissions are fine, now I am having other issues with XSOAR telling me the App integration giving me this error - "&lt;SPAN&gt;No tenant-identifying information found in either the request or implied by any provided credentials." Just had this functioning earlier today and nothing was changed. Im going to remove it entirely and start from scratch, also waiting on upgraded to XSOAR 8 starting next Tuesday so hopefully some of these odd occasional issues disappear.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Mar 2024 13:13:19 GMT</pubDate>
    <dc:creator>STeegarden</dc:creator>
    <dc:date>2024-03-07T13:13:19Z</dc:date>
    <item>
      <title>MS Defender XSOAR Integration daily re-auth.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ms-defender-xsoar-integration-daily-re-auth/m-p/579305#M3121</link>
      <description>&lt;P&gt;Hello, used this integration guide (&lt;A href="https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender" target="_blank"&gt;https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender&lt;/A&gt;) and the integration pulls incidents just fine. Currently using a self-deployed application and device code flow. Problem I am running into is a daily re-auth for a user account using the device code flow. I suspect it might have to do with token reauth for the user account used in device code flow along with our conditional access policies. Anyone have any ideas to get the integration to just pull incidents without having to use an account to reauth every day?&amp;nbsp; Checked the self-deployed application box, and device code flow box off and on and reinstalled the integration as well as generated new keys etc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 13:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ms-defender-xsoar-integration-daily-re-auth/m-p/579305#M3121</guid>
      <dc:creator>STeegarden</dc:creator>
      <dc:date>2024-03-05T13:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: MS Defender XSOAR Integration daily re-auth.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ms-defender-xsoar-integration-daily-re-auth/m-p/579493#M3127</link>
      <description>&lt;P&gt;Good morning.&amp;nbsp; &amp;nbsp;Do you have offline_access scope provisioned for the self deployed app?&amp;nbsp; &amp;nbsp; &amp;nbsp;I would doublecheck that and then confirm with your AAD admin&amp;nbsp; that offline_access was provisioned as well as confirm what policies exist that might impact token expiration.&amp;nbsp; &amp;nbsp; Let us know if that resolves the issue.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here's the resources to read up on offline access and refresh tokens.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/1118562/how-to-extend-the-expiry-of-access-token-so-i-dont" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/answers/questions/1118562/how-to-extend-the-expiry-of-access-token-so-i-dont&lt;/A&gt;&amp;nbsp;(a little dated but bhanu Kiran provided a clear description of refresh tokens and also points to this article &lt;A href="https://learn.microsoft.com/en-us/entra/identity-platform/configurable-token-lifetimes" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/entra/identity-platform/configurable-token-lifetimes&lt;/A&gt;)&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 16:41:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ms-defender-xsoar-integration-daily-re-auth/m-p/579493#M3127</guid>
      <dc:creator>cpayne26</dc:creator>
      <dc:date>2024-03-06T16:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: MS Defender XSOAR Integration daily re-auth.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ms-defender-xsoar-integration-daily-re-auth/m-p/579634#M3131</link>
      <description>&lt;P&gt;Awesome thanks for the reply and additional documentation. The permissions are fine, now I am having other issues with XSOAR telling me the App integration giving me this error - "&lt;SPAN&gt;No tenant-identifying information found in either the request or implied by any provided credentials." Just had this functioning earlier today and nothing was changed. Im going to remove it entirely and start from scratch, also waiting on upgraded to XSOAR 8 starting next Tuesday so hopefully some of these odd occasional issues disappear.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 13:13:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ms-defender-xsoar-integration-daily-re-auth/m-p/579634#M3131</guid>
      <dc:creator>STeegarden</dc:creator>
      <dc:date>2024-03-07T13:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: MS Defender XSOAR Integration daily re-auth.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ms-defender-xsoar-integration-daily-re-auth/m-p/619570#M3770</link>
      <description>&lt;P&gt;Good afternoon.&amp;nbsp; Did you ever find a resolution to the&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;No tenant-identifying information found in either the request or implied by any provided credentials."&amp;nbsp;.&amp;nbsp; I'm having the same issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 17:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/ms-defender-xsoar-integration-daily-re-auth/m-p/619570#M3770</guid>
      <dc:creator>mkjones</dc:creator>
      <dc:date>2024-11-15T17:25:08Z</dc:date>
    </item>
  </channel>
</rss>

