# Filebeat Microsoft Module - Documents Incomplete

**URL:** https://discuss.elastic.co/t/filebeat-microsoft-module-documents-incomplete/372900
**Category:** Beats
**Tags:** filebeat
**Created:** [January 7, 2025, 5:26pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-documents-incomplete/372900 "2025-01-07T17:26:05Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)
#### Post date: [January 7, 2025, 5:26pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-documents-incomplete/372900/1 "2025-01-07T17:26:05Z")

</div>

Posting as FYI. The instructions for the Filebeat Microsoft Module at [Microsoft module | Filebeat Reference [8.17] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-microsoft.html) are incomplete.  
You need to also add the permissions for the WindowsDefenderATP API \> Alerts \> Alert.Read.All and Alert.ReadWrite.All.  
So your final permissions would look like:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6e617ad1552da37d28b089b83fb00851d014c500.png)

---

<div class="post-metadata">

### Author: ![Trevor\_Blackford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trevor_blackford/32/120087_2.png) [@Trevor\_Blackford](https://discuss.elastic.co/u/Trevor_Blackford)
#### Post date: [January 8, 2025, 5:37pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-documents-incomplete/372900/2 "2025-01-08T17:37:44Z")

</div>

Looking at the documentation, it does look like the WindowsDefenderATP instructions include Alert.Read.All

> **[Microsoft module | Filebeat Reference \[8.17\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-microsoft.html#_defender_atp_fileset_settings)**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88df2da5afcd171cc12a964ff55c6010d44dc95c.png)

Are you certain that AlertReadWriteAll is necessary? It shouldn't require write access.

---

<div class="post-metadata">

### Author: ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)
#### Post date: [January 8, 2025, 7:17pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-documents-incomplete/372900/3 "2025-01-08T19:17:48Z")

</div>

You're right on the documentation. Not sure how I missed that.

However, when I didnt have Alert.Read.All and Alert.ReadWrite.All, I would see error messages saying that I didn't have those permissions.

---

<div class="post-metadata">

### Author: ![Trevor\_Blackford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trevor_blackford/32/120087_2.png) [@Trevor\_Blackford](https://discuss.elastic.co/u/Trevor_Blackford)
#### Post date: [January 9, 2025, 7:48pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-documents-incomplete/372900/4 "2025-01-09T19:48:32Z")

</div>

It's a little confusing, with the m365\_defender and the defender\_atp settings in different sections. Could you share the error message you got when Write access was not given

---

<div class="post-metadata">

### Author: ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)
#### Post date: [January 10, 2025, 3:00pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-documents-incomplete/372900/5 "2025-01-10T15:00:49Z")

</div>

Jan 7 15:32:11 LOGGER filebeat[2510619]: {"log.level":"error","@timestamp":"2025-01-07T15:32:11.971Z","log.logger":"input.httpjson-cursor","log.origin":{"function":"[github.com/elastic/beats/v7/x-pack/filebeat/input/httpjson.run.func1","file.name":"httpjson/input.go","file.line":181},"message":"Error](http://github.com/elastic/beats/v7/x-pack/filebeat/input/httpjson.run.func1%22,%22file.name%22:%22httpjson/input.go%22,%22file.line%22:181%7D,%22message%22:%22Error) while processing http request: failed to collect first response: failed to execute http GET: server responded with status code 403: {"error":{"code":"Forbidden","message":"Missing application roles. API required roles: Alert.Read.All,Alert.ReadWrite.All, application roles: .","target":"|3c365647-11111."}}","service.name":"filebeat","id":"xxxxxxxx","input\_source":"[https://api.securitycenter.windows.com/api/alerts","input\_url":"https://api.securitycenter.windows.com/api/alerts","ecs.version":"1.6.0](https://api.securitycenter.windows.com/api/alerts%22,%22input_url%22:%22https://api.securitycenter.windows.com/api/alerts%22,%22ecs.version%22:%221.6.0)"}

---

<div class="post-metadata">

### Author: ![Trevor\_Blackford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trevor_blackford/32/120087_2.png) [@Trevor\_Blackford](https://discuss.elastic.co/u/Trevor_Blackford)
#### Post date: [January 14, 2025, 11:50pm UTC](https://discuss.elastic.co/t/filebeat-microsoft-module-documents-incomplete/372900/6 "2025-01-14T23:50:50Z")

</div>

Thanks! Since it's a GET method, it does seem like Alert.Read.All should be sufficient. From the windows documentation, it seems like only one is required. Did you get this error when Alert.Read.All was enabled? [Get alert information by ID API - Microsoft Defender for Endpoint | Microsoft Learn](https://learn.microsoft.com/en-us/defender-endpoint/api/get-alert-info-by-id)
