Skip to main content
Panther Knowledge Base

Error "http status: 403 Forbidden code: UnknownError" when setting up Microsoft Graph API source in Panther

Issue

When trying to set up a new Microsoft Graph API log source, the following error appears:

failed api response - http status: 403 Forbidden code: UnknownError

How can I fix this?

Resolution

To resolve the issue, please follow these instructions:

  1. Start by checking the following parameters:

    • Verify if the credentials have expired or been changed. This is the first parameter to investigate.
    • Refer to the documentation's Prerequisites section, which recommends using an application-only authentication token. Make sure the token being used satisfies this requirement.
    • Confirm that the token has both Delegated permissions with SecurityEvents.Read.All and Application permissions with SecurityEvents.Read.All.
    • Detailed instructions for this process can be found at Step 1: Create an Azure AD application in the documentation.
  2. Ensure that an admin has granted permissions (authorized) to the App Registration. Note that the person creating the App Registration may not always be the same person adding the data source to Panther.

Additionally, if you want to receive logs from a restricted user instead of the admin account, follow these additional steps:

  1. Create a new user with the Security Reader role.
    clipboard_e083bc6d63ab6d15b8341f0896fdc3f61.png
  2. In the app registration, add the security user as an owner.
    clipboard_e2dddf154aa9a5991d7b2f9d10f1ddc48.png
  3. Recreate the Microsoft Graph Log Source, follow these steps:

    1. Input the necessary credentials and proceed until the following screen is displayed.

      clipboard_e11a0747247fa78f3cf27a5a7151ad93e.png

    2. Ensure that you log in using the credentials of the security user.
      • Note: If running into an Internal Server Error after Granting Access, please retry copying and pasting the Client ID and Secret.

Cause

This issue might occur when an admin has not granted permissions to the App Registration. The individual creating the App Registration is not always the same individual adding the data source to panther.