Overview
Torii integrates with Microsoft Defender for Cloud Apps and syncs data for cloud apps discovered users.
- Torii supports syncing multiple Microsoft Defender for Cloud Apps accounts.
- You can constantly stay updated with application information from our Integrations Page
>> Integration Capabilities button >> Integration Capabilities table.
Requirements
Accounts & Permissions
- To connect this integration, we require the following:
- Tenant ID
- Client ID
- Client Secret
How to Generate the Required Values
- Go to App registrations in Microsoft Entra Admin Center > Click New registration
- In the Register an application form:
- Name the app Torii
- Under Supported account types, select:
Accounts in this organizational directory only (Single tenant) - Under Redirect URI, select Web and enter:
https://api.toriihq.com/api/auth/microsoftDefenderForCloudApps/callback - Click Register
- Go to API permissions > Click Add a permission:
- Choose Microsoft APIs > Microsoft Graph
- Choose Application permissions > Select CloudApp-Discovery.Read.All > Click Add permissions
- Click Add a permission again
- Choose APIs my organization uses, search for Microsoft Cloud App Security > Application permissions > Select investigation.read > Click Add permissions
- Choose Microsoft APIs > Microsoft Graph
- Click Grant admin consent and confirm.
- Go to Certificates & secrets > Click New client secret
- Enter a description and expiration
- Click Add
- Copy the Value (not the Secret ID) – this is your Client Secret
- From the Overview page, copy the Client ID and Tenant ID
How to Connect the Integration
- Go to the Integrations page in Torii
- Select the Microsoft Defender for Cloud Apps tile
- Click Connect
- Enter the following credentials:
- Tenant ID
- Client ID
-
Client Secret
- Click Connect to finalize the integration.
In the new consent screen, press Consent on behalf of your organization to proceed. - Once the integration is connected and synced, a green checkbox will appear
Known Limitations
- This integration relies on uploaded streams that have been modified in the last 90 days only
- The logs within uploaded streams are from the last 90 days only
- Torii does not process uploaded streams that anonymize user data
Q&A
Q: What happens if the client secret expires?
A: You will need to provide a new client secret and reconnect the integration.
For any further questions, please contact Torii Support.