Are there any API permissions to assign to the Splunk Add-on for Microsoft Cloud Services? I did grant the Active Directory Application read access as a role under IAM, but there is nothing in the documentation that states if API permissions for the app in Azure is needed at all.
When I check the app's API permissions, the only right I see is for Microsoft Graph, User.Read with Type set to 'Delegated' and Description set to 'Sign in and read user profile'.
Just wondering if any additional API permissions need to be assigned.
Thx
Here is a spreadsheet detailing the necessary permissions for various add-on's and their inputs.
http://bit.ly/Splunk_Azure_Permissions
For the Splunk Add-on for Microsoft Cloud Services, you do not need any special API permissions, but you do need to grant your Azure AD app registration Reader access to your subscription.
Do you have the same matrix for authentication extensions where Azure SSO is the IdP and SAML is the used?
TYVM or posting!