Skip to content

[Microsoft Defender XDR]: (m365_defender) make OAuth2 endpoint params configurable #16134

Description

@a03nikki

Integration Name

Microsoft Defender XDR [m365_defender]

Dataset Name

Integration Version

5.1.1

Agent Version

9.2.1

OS Version and Architecture

Debian

User Goal

Configure the integration to work with Microsoft's Partner Center and its granular delegated admin privileges (GDAP) constructs to authorize and collect tenant information.

Existing Features

Similar to work we previously did for both Microsoft Office 365 (#14924) and Microsoft Defender Endpoint (#15605), we need to expose the "OAuth2 Endpoint Params" via the integration to allow users to modify the grant_type and the refresh_token value.

What did you see?

This integrations options: https://www.elastic.co/docs/reference/integrations/m365_defender

The other integration options:

Anything else?

Similar to #15605 and #14924.
Depends on #16408, elastic/beats#47256, and #16586.
Depends on elastic/beats#48479.

Activity

  1. elasticmachine commented on Nov 27, 2025

    @elasticmachine

    Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

  2. added
    Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]
    on Dec 17, 2025
  3. kcreddy commented on Dec 17, 2025

    @kcreddy
    Contributor

    Support for configurable Oauth2 endpoint params is added for vulnerability data stream in: #15667.

    Need to add support for alert and incident data streams. See #15667 for similar implementation.

  4. removed
    Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]
    on Dec 17, 2025
  5. narph commented on Oct 9, 2026

    @narph
    Contributor

    @a03nikki can we close this issue?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions