Splunk SOAR

Microsoft Exchange On-Premise EWS: HTTP Code: 401. Reason: Unauthorized

recv7353
New Member

We are setting up the Phantom App Microsoft Exchange On-Premise EWS version: 3.0.3 to talk to our On Prem Exchange EWS instance and we are getting the below error when we do a test connection:

"HTTP Code: 401. Reason: Unauthorized. Details: . Toggling the impersonation configuration on the asset might help, or login user does not have privileges to the mailbox."

 

I toggled the impersonation settings but the error is the same is there any specific permissions that need to be given to the Exchange account as so far the Exchange admin team confirmed the ID has rights to impersonate?

Labels (1)
0 Karma

Iñigo
Explorer

Hi

Did you get any solution for this issue? We are getting the same error message at the EWS Office365 app for a specific mail account that is apparently configured in the same way that others that allow access without issues.

We are missing something but can't figure out what.

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...