Troubleshooting the Office 365 Message Trace REST API protocol
To resolve issues with the Office 365 Message Trace REST API protocol, use the troubleshooting and support information. Find the errors by using the protocol testing tools in the QRadar Log Source Management app.
General troubleshooting
The following troubleshooting steps apply to common configuration errors when using the Microsoft Message Trace API with IBM® Security QRadar®. Follow these steps if the log source fails to retrieve Message Trace data.
- If you use QRadar 7.3.2, software Update 3 or later, run the testing tool before you enable the log source. If the testing tool does not pass all tests, the log source might fail when enabled. If a test fails, an error message with additional information is displayed.
- Verify that the selected Event Collector can access Microsoft Graph endpoints over HTTPS (port 443).
- Verify that the application credentials are valid. Ensure that the Client ID, Client Secret, and Tenant ID configured in the log source match the values from the application registered in Microsoft Entra ID.
- Ensure that the application has the required Microsoft Graph application permissions to access Message Trace data and that administrator consent is granted
- Ensure that a service principal is provisioned for Exchange Online for the registered application.
- Ensure that Conditional Access policies do not prevent the application from obtaining an OAuth access token for Microsoft Graph.
- Reenter the configuration values and rerun the testing tool, if available.
For more information, see: