Issue
Running a response action on a non-human identity results in a 403 error.
Cause
With the addition of Identity Threat Detection and Response (ITDR) monitoring non-human identities, Additional Microsoft Graph API and O365 permissions are required to perform response actions on non-human identities. These new permissions have not yet been approved for your tenant, so requests that use them are rejected.
Resolution
- In OneView, go to Investigate > Identity Threat Detection & Response > Configurations > Integrations.
- Next to Entra ID, click Connected.
- Next to MS Graph API and O365 API, click the drop-down and select Disconnect.
- Reconfigure your Entra ID connector. For detailed steps, see Configure ITDR in OneView.