Note: Our guide was accurate at the time of writing, but changes happen. If you find the instructions are outdated, leave a description in the comment field below and let us know!
Step 1: Enable console access
Having read-only access to the interface of your technology allows Expel to dig deeper when performing incident investigations. Our device health team uses this access to investigate potential health issues with your tech.
You can create either a local account or an AD user through portal.azure.com.
- Go to admin.microsoft.com to create a new user.
- Scroll to Users and click Active Users.
- Select Add a user.
- Set Expel as first name and SOC as last name.
- Scroll to the bottom and grant global reader role for the user.
Step 2: Generate API credentials
To integrate the technology with Expel, we need to create secure credentials to the API. Depending on the permissions allowed in Step 1, Expel may be able to generate API credentials. If you're unsure, reach out to your Expel Customer Success Engineer, or email customerhealth@expel.io.
- Go to the MDCA portal http://portal.cloudappsecurity.com/ using the account credentials created in Step 1.
- Go to the Settings menu and select Security extensions and then API tokens.
- Generate a new token and provide a name to identify the token and click Next.
- Copy the token value and save it somewhere safe. You need this later.
- After you generate a new token, you're provided with a new URL to access Microsoft Defender for Cloud Apps. Be aware the token has the privileges of the user created in Step 1 who issued it.
Step 3: Configure the technology in Workbench
Now that we have all the correct access configured and have noted the credentials, we can integrate your tech with Expel.
Register device in Expel Workbench
- In a new browser tab, login to https://workbench.expel.io.
- On the console page, navigate to Settings and click Security Devices.
- At the top right of the page, select Add Security Device.
- Search for and select your technology.
- Click Save.
After a few minutes, refresh the Security Devices page and you see your device status reporting as Healthy, or if there is an issue, you see details of what the issue may be.
To check if alerts are coming through, navigate to Alerts on the console page. Click the icon in the upper right to switch to grid view, then check the list for device alerts.
Related terms:
MCAS, MS Cloud App Security, MS Defender
Comments
0 comments
Please sign in to leave a comment.