# Missing application roles. API required roles: Incident.Read.All,Incident.ReadWrite.All, application roles

**URL:** https://discuss.elastic.co/t/missing-application-roles-api-required-roles-incident-read-all-incident-readwrite-all-application-roles/360019
**Category:** Beats
**Tags:** filebeat
**Created:** [May 22, 2024, 7:01pm UTC](https://discuss.elastic.co/t/missing-application-roles-api-required-roles-incident-read-all-incident-readwrite-all-application-roles/360019 "2024-05-22T19:01:38Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Van\_Howell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/van_howell/32/126765_2.png) [@Van\_Howell](https://discuss.elastic.co/u/Van_Howell)
#### Post date: [May 22, 2024, 7:01pm UTC](https://discuss.elastic.co/t/missing-application-roles-api-required-roles-incident-read-all-incident-readwrite-all-application-roles/360019/1 "2024-05-22T19:01:38Z")

</div>

I am using the Filebeat Microsoft module to ingest Defender Endpoint logs. I have setup an App on the Azure AD site and added the documented permissions. I am getting a message that indicates I do not have the required rolls on the API, specifically Incident.Read.All,Incident.ReadWrite.All. I have double checked my API permissions and these are listed. I have searched the entire internet for answers and have found nothing to help.

Any suggestions will be welcome.

On Prem Elastic/Kibana/Filebeat cluster v 8.13.3

---

<div class="post-metadata">

### Author: ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)
#### Post date: [May 23, 2024, 7:30am UTC](https://discuss.elastic.co/t/missing-application-roles-api-required-roles-incident-read-all-incident-readwrite-all-application-roles/360019/2 "2024-05-23T07:30:30Z")

</div>

> [@Van\_Howell](#):
>
> I am using the Filebeat Microsoft module to ingest Defender Endpoint logs. I have setup an App on the Azure AD site and added the documented permissions. I am getting a message that indicates I do not have the required rolls on the API, specifically Incident.Read.All,Incident.ReadWrite.All. I have double checked my API permissions and these are listed. I have searched the entire internet for answers and have found nothing to help.
> 
> Any suggestions will be welcome.
> 
> On Prem Elastic/Kibana/Filebeat cluster v 8.13.3

Hi,

Ensure that the permissions `Incident.Read.All` and `Incident.ReadWrite.All` are not only listed but also granted. In Azure AD, adding a permission and granting it are two separate steps.

Regards

---

<div class="post-metadata">

### Author: ![Van\_Howell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/van_howell/32/126765_2.png) [@Van\_Howell](https://discuss.elastic.co/u/Van_Howell)
#### Post date: [May 23, 2024, 1:14pm UTC](https://discuss.elastic.co/t/missing-application-roles-api-required-roles-incident-read-all-incident-readwrite-all-application-roles/360019/3 "2024-05-23T13:14:55Z")

</div>

They are granted...

 ![Screenshot 2024-05-23 080722](https://us1.discourse-cdn.com/elastic/original/3X/2/4/242f6409385709f9556ad5f26fe10eb83ae45061.png)

I also noticed that if I create a App Context Token and run it through a JWT Decoder It only shows the Incident.Read.All role assigned. Could I have done something wrong creating the App?
