To get the credentials required for setting up a Microsoft Sentinel Data Plane to be used in Attack Detective or in Automation (ex Continuous Content Management) and for direct deployment from a Sigma rule page, follow these steps:
Register your app in Azure Active Directory:
Copy your app credentials in Azure Active Directory:
Go to App registrations > Owned applications and select your app from the list.
In the Essentials section of the Overview page, copy Application (client) ID and Directory (tenant) ID
Paste the value of Application (client) ID into the Client ID field and the value of the Directory (tenant) ID into the Tenant ID field in your Data Plane profile on the SOC Prime Platform.
Create and copy your client secret in Azure Active Directory:
Go to Certificates & secrets > Client secrets and add a client secret by clicking New client secret.
Enter the secret description and expiration date, and then click Add.
Copy the client secret Value. Attention: ensure you've copied and saved the Value at this step since it will be impossible to access it once again.
Paste the client secret Value into the Client Secret field in your Data Plane profile on the SOC Prime Platform.
Assign the required permission to your app (the steps below describe the process via Sentinel, but you can also do it directly in your Log Analytics workspace):
In Azure Active Directory, go to API permissions and ensure there are no existing permissions.
Go to Microsoft Sentinel and select your workspace
Select Settings > Workspace settings
Select Access control (IAM) > Role assignments
Select Add > Add role assignment
Select the role to be assigned to your app:
Microsoft Sentinel Contributor β if you're going to deploy content from the SOC Prime Platform
Microsoft Sentinel Reader β if you're not going to deploy content from the SOC Prime Platform and will use the integration only for Attack Detective
and click Next
Click Select members, select your app to assign the permission, and click Next
Copy and paste the URL of your Microsoft Sentinel web console:

