Forum Discussion
jbender
Mar 29, 2021Copper Contributor
AAD Risky User Playbook Authorization Reqest Denied
Hello, New to Azure Sentinel, setting up the AAD Risky User Playbook. I did the app registration. Not sure how to connect the registration to Playbook. When I ran the playbook I got the follow...
Thijs Lecomte
Mar 30, 2021Bronze Contributor
What permissions did you provide to the app registration? Can you provide us a screenshot
jbender
Mar 30, 2021Copper Contributor
- Thijs LecomteMar 31, 2021Bronze ContributorPermissions look okay to me! You have configuration authentication within that HTTP action in the Playbook? Could you share it (with the secret removed ofcourse)
- jbenderMar 31, 2021Copper Contributor
- Thijs LecomteApr 03, 2021Bronze ContributorHave you given the Managed Identity the correct permissions/role?
Right now you are not utilizing the app registration you showed in a previous step.
You should either:
- Provide the correct permissions to the Managed Identity (https://docs.microsoft.com/en-us/azure/active-directory/managed-identities-azure-resources/how-to-manage-ua-identity-portal)
- Use the app registration for authentication (use the Active Directory OAuth authentication option)