Overview
Thanks to Matt_Lowe (Program Manager - Azure Sentinel) and BenjiSec (Program Manager - Azure Sentinel) for the technical brainstorming, contribution, implementation and proof reading!...
Hi wondering if you can help me? I have got the everything running perfectly in my own tenant (Great job by the way! love the workbook). I am looking to replicate this in a second tenant but I would like to use the same Service principal I have registered in my own tenant.
I have registered the app in the second tenant (with a Global administrator account) using this link https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=<your client id>&scope=https://graph.microsoft.com/.default.
When I run the logic app I use the same client secret and the same application ID but the tenant ID of the second tenant. It comes back as 403 forbidden when attempting the first GET request to security/SecureScores endpoint. Is there anything I am missing I would need to do when using this method? In the enterprise applications section in the second tenant, all of the permissions are there: