Refresh Microsoft 365 credentials

When your Microsoft 365 client secret expires, create a new one and resubmit it to Arctic Wolf®.

These resources are required:

  • A user account with Global Administrator permissions

Create a Microsoft client secret

  1. Sign in to the Microsoft Entra admin center.
  2. Click Entra ID > App registrations.
  3. Click on the relevant application.
    Tip: If needed, click the All applications tab to view all applications for your organization.
  4. In the navigation menu, in the Manage section, click Certificates & secrets.
  5. In the Client secrets section, click + New client secret, and then configure these settings:
    • Description — Enter a description for the client secret.
    • Expires — Select an expiration date for the client secret.
  6. Click Add.
  7. On the Client secrets tab, verify that your new client secret appears.

    Screenshot of the Certificates and Secrets page on the Microsoft Azure Portal. The Value field and text is highlighted by an orange box.

  8. Copy the Value value to a safe, encrypted location.
    You will provide it to Arctic Wolf later.
    Note:
    • The Value value is only available immediately after creation. Do not exit the Certificates & Secrets page until the value is saved in a safe, encrypted location.
    • The Value value is the Client Secret Value that you must provide to Arctic Wolf later. It is not necessary to copy the Secret ID field.
    • You must provide the updated client secret credentials to Arctic Wolf before the credentials expire.

Retrieve the client and tenant IDs

  1. Sign in to the Microsoft Entra admin center.
  2. Click Entra ID > App registrations.
  3. Click on the relevant application.
    Tip: If needed, click the All applications tab to view all applications for your organization.
  4. In the Essentials section, copy the Application (client) ID and the Directory (tenant) ID to a safe, encrypted location.
    You will provide these values to Arctic Wolf later.

Update Active Response credentials

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Organization Profile > Integrations.
  3. Make sure that you are on the Active Response tab.
  4. Optional: Filter the list of integrations.

    For more information, see Active Response integration filters.

  5. For the account that you want to update, click Actions > View Integration.
  6. On the Integration page, click Edit Settings.
  7. In the appropriate field, enter the token and secret.
  8. Click Save Changes.