Azure / Azure/Connectors-NET-Samples
[Investigation] Wdatp connector 403: what Defender capabilities are accessible?
- Dominant language
- C#
- Stars
- 3
- Forks
- 3
- Avg merge
- 4d 14h
- Merged PRs (30d)
- 3
Description
## Summary
The `wdatp/alerts` endpoint returns 403 Forbidden because the connection's account is missing the Defender `ViewData` permission.
## Repro
`GET https://sdk-connector-samples.azurewebsites.net/api/wdatp/alerts`
## Error
`[wdatp] GET /api/alerts failed with status 403: {"error":{"code":"Forbidden","message":"Missing user permissions. API required permissions: ViewData, user permissions: None."}}`
## Connection
- Namespace: `sdk-test-gateway-prod` (nsUrlId: `bedc0f9f130e4bba93ea8046573db2d0`)
- Connection: `wdatp-test`
## Investigation needed
1. What Defender role/permission grants `ViewData`? (Likely requires Microsoft Defender for Endpoint P1/P2 license and Security Reader role)
2. Are there any Wdatp APIs accessible without elevated Defender permissions (e.g., machine groups, investigation packages)?
3. Can we use the Wdatp connector to demonstrate any read operation with the current connection setup?
4. Should the `wdatp-test` connection be re-created with an account that has Defender Security Reader permissions?
Contributor guide
Assessment
This issue has not been assessed yet.