6 ms·
I looked at the API calls on the CrowdStrike blog post and I have been using parts of these API's for calls in PowerShell for at least the past year for trackin
by ExploitsforFun 8y ago
I looked at the API calls on the CrowdStrike blog post and I have been using parts of these API's for calls in PowerShell for at least the past year for tracking down issues we have had in Office 365. I can understand how frustrating it can be if your competitors seem to have "secret knowledge". However that knowledge may have been gotten by calling up the very helpful people at MS support, laying out the problem and they send you a Powershell script in return.
- pweissbrod 8y agoI couldn't agree more. Why is the API not public? Is it because some sort of top secret corporate conspiracy? Or is it that management just decided to avoid the burden of publishing and maintaining an immature or lesser used API? After reading your comment that whole article seemed a little sensationalist
- derefr 8y ago> just decided to avoid the burden of publishing and maintaining an immature or lesser used API "Burden" is an understatement. Any API Microsoft documents becomes part of their ongoing commitment to eternal backward-compatibility. (Heck, even some things they never document at all still end up forced into that commitment, like the internal registry hives in Windows 95.) So Microsoft do everything they can to only document what they're absolutely sure they have in a good, stable, "won't regret later that we didn't fix it some more before setting it in stone" state.
- praseodym 8y agoWhile that may be true for the Win32 APIs, it is certainly not true for their cloud-based products. They’ve had some very poor APIs for Windows Live Mail (predecessor of Office 365 for education) which were also quickly deprecated and replaced.
- lixtra 8y agoThey could just flag it “volatile”, “unstable” or something. It’s very unlikely that Microsoft did not properly document the api internally and as you see it’s leaking out anyway.
- izacus 8y agoIf you'll ever develop a single simple API you'll find out that doesn't work at all. People will use unstable APIs and people will blame YOU and only you when they break.
- voltagex_ 8y agoExchange WS and Lync/Communicator would disagree with you re: eternal backward-compatibility.
- tallanvor 8y agoThere are a lot of reasons that it might not be public, but a conspiracy is quite low on the list. My guess is that it's due to one of the following: * The API isn't considered beta yet. * This was created as somewhat of a side project and hasn't been formalized yet. * Documenting it is on the backlog. * It's meant for internal use in that they may be building in tools in the Security and Compliance center that will be calling it.
- jonstewart 8y ago...which is fine if MS hands out the Powershell script to all who ask.
- shiftpgdn 8y agoThis is absolutely not true. I called O365 yesterday (well, they called me at my request) to investigate a potential data breach. All the guy on the phone could do was to read to me out of a technicians manual and then suggest I purchase the Azure Active Directory P2 plan at $9/user/month.
- ropman76 8y agoThere is a blog post from 2015 about an API for security and compliance motoring. https://www.microsoft.com/en-us/microsoft-365/blog/2015/04/21/announcing-the-new-office-365-management-activity-api-for-security-and-compliance-monitoring/ https://www.microsoft.com/en-us/microsoft-365/blog/2015/04/2... I respect that fact that CrowdStrike and others have spent the time with the api and made life a lot easier for others. As someone who has spent more time than he wanted with the Office 365 API I am a fan of people who make my life easier. That being said I am not buying the drama that these API's have been hidden.