[Investigation] Wdatp connector 403: what Defender capabilities are accessible?

Open
#46 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Quiet
Tech stack
azure, csharp
Domain
api, backend, security

Research direction

Start with the reported GET https://sdk-connector-samples.azurewebsites.net/api/wdatp/alerts failure and the wdatp-test connection details, then investigate which Defender permission grants ViewData and which APIs the current account can access. Done means documenting the accessible read operation or confirming that the connection must be recreated with Security Reader permissions.

Written by the indexing model from the issue text.

Description

Summary

The wdatp/alerts endpoint returns 403 Forbidden because the connection's account is missing the Defender ViewData permission.

Repro

GET https://sdk-connector-samples.azurewebsites.net/api/wdatp/alerts

Error

[wdatp] GET /api/alerts failed with status 403: {"error":{"code":"Forbidden","message":"Missing user permissions. API required permissions: ViewData, user permissions: None."}}

Connection

  • Namespace: sdk-test-gateway-prod (nsUrlId: bedc0f9f130e4bba93ea8046573db2d0)
  • Connection: wdatp-test

Investigation needed

  1. What Defender role/permission grants ViewData? (Likely requires Microsoft Defender for Endpoint P1/P2 license and Security Reader role)
  2. Are there any Wdatp APIs accessible without elevated Defender permissions (e.g., machine groups, investigation packages)?
  3. Can we use the Wdatp connector to demonstrate any read operation with the current connection setup?
  4. Should the wdatp-test connection be re-created with an account that has Defender Security Reader permissions?
Dominant language
C#
Stars
3
Forks
3
Avg merge
1h 8m
Merged PRs (30d)
2

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Azure/Connectors-NET-Samples

All issues in Azure/Connectors-NET-Samples

Similar issues

More C# issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.