category: Data Enrichment & Threat Intelligence provider: Microsoft sectionorder: - Connect - Collect commonfields: id: Microsoft Management Activity API (O365 Azure Events) version: -1 configuration: - defaultvalue: https://manage.office.com/api/v1.0/ display: Base URL name: base_url type: 0 section: Connect required: false - display: Application ID or Client ID additionalinfo: See the Help tab. name: auth_id type: 4 section: Connect hidden: true required: false - displaypassword: Application ID or Client ID additionalinfo: See the Help tab. name: credentials_auth_id hiddenusername: true section: Connect type: 9 required: false - display: Token or Tenant ID additionalinfo: See the Help tab. name: refresh_token type: 4 section: Connect hidden: true required: false - displaypassword: Token or Tenant ID additionalinfo: See the Help tab. name: credentials_refresh_token hiddenusername: true type: 9 section: Connect required: false - display: Key or Client Secret additionalinfo: See the Help tab. name: enc_key type: 4 section: Connect hidden: true required: false - displaypassword: Key or Client Secret additionalinfo: See the Help tab. name: credentials_enc_key hiddenusername: true type: 9 section: Connect required: false - additionalinfo: Used for certificate authentication as it appears in the "Certificates & secrets" page of the app. display: Certificate Thumbprint name: certificate_thumbprint type: 4 hidden: true section: Connect required: false - displaypassword: Certificate Thumbprint additionalinfo: Used for certificate authentication as it appears in the "Certificates & secrets" page of the app. name: credentials_certificate_thumbprint hiddenusername: true type: 9 section: Connect required: false - additionalinfo: Used for certificate authentication. The private key of the registered certificate. display: Private Key name: private_key type: 14 section: Connect required: false - additionalinfo: Select this checkbox if you are using a self-deployed Azure application. display: Use a self-deployed Azure application name: self_deployed type: 8 section: Connect advanced: false required: false - display: Application redirect URI (for self-deployed mode) name: redirect_uri type: 0 section: Connect advanced: true required: false - display: Authorization code (for self-deployed mode) additionalinfo: Run the !ms-management-activity-generate-login-url command to generate the Authorization code. name: auth_code type: 4 section: Connect hidden: true required: false - displaypassword: Authorization code (for self-deployed mode) additionalinfo: Run the !ms-management-activity-generate-login-url command to generate the Authorization code. name: credentials_auth_code hiddenusername: true type: 9 required: false section: Connect - additionalinfo: Relevant only if the integration is running on Azure VM. If selected, authenticates based on the value provided for the Azure Managed Identities Client ID field. If no value is provided for the Azure Managed Identities Client ID field, authenticates based on the System Assigned Managed Identity. For additional information, see the Help tab. display: Use Azure Managed Identities name: use_managed_identities type: 8 section: Connect required: false - additionalinfo: The Managed Identities client ID for authentication - relevant only if the integration is running on Azure VM. displaypassword: Azure Managed Identities Client ID name: managed_identities_client_id hiddenusername: true type: 9 section: Connect required: false - display: Trust any certificate (not secure) name: insecure type: 8 section: Connect advanced: true required: false - display: Use system proxy settings name: proxy type: 8 section: Connect advanced: true required: false - defaultvalue: 10 minutes display: First fetch time range additionalinfo: