Microsoft Defender Integration
Bring your own EDR: connect a read-only Entra app registration and get a daily agent-health report for every device onboarded to Microsoft Defender for Endpoint.
This is the Defender counterpart of the CrowdStrike Falcon integration and produces the same vendor-agnostic device checks, so Defender and Falcon hosts sit side by side with your Blue Lantern agent scans in the Monitoring Hub and the Security Attestation Report. Software inventory, vulnerability data, risk scores, and alert contents are never read.
Licensing
Requires Microsoft Defender for Endpoint P2 or Microsoft Defender for Business. Defender for Business supports this integration with some Microsoft-documented API limitations (reduced alert detail and API rate caps); device health and alert-presence checks work on both. Only the commercial cloud is supported in this version; GCC, GCC High, and DoD tenants use a separate authentication and API host and are not yet supported.
What you get
Once a day, one Device run per onboarded machine with these checks:
| Check | Passes when | Severity |
|---|---|---|
| EDR sensor online | The machine has been seen within the last 7 days | High |
| EDR sensor healthy | Defender reports the sensor health as Active (not Inactive, Impaired Communication, or No Sensor Data) | Medium |
| EDR AV protection healthy | Defender antivirus is enabled, reporting, and running current signatures | Medium |
| EDR no active alerts | No Defender alerts for the machine are still New or In Progress | High |
A few details worth knowing: the AV check is omitted for devices whose platform does not report an antivirus status, and the alert check is omitted entirely if Alert.Read.All was not granted, so a report may contain three or four checks. Only machines whose onboarding status is Onboarded produce runs; machines unseen for more than 30 days stop producing runs and age out of the fleet count. Runs appear with the target <hostname> (EDR) and the submitter system:defender, scored Healthy or At Risk.
Setup
- Register an app in your Entra admin center. Go to App registrations → New registration (any name, single tenant).
- Grant application permissions. Under API permissions → Add a permission → APIs my organization uses, search for WindowsDefenderATP, choose Application permissions, and add Machine.Read.All, Alert.Read.All, and User.Read.All. Then click Grant admin consent. All three are read-only.
- Create a client secret under Certificates & secrets → New client secret, and copy the value while it is shown. Your tenant ID and application (client) ID are on the app's Overview page.
- Connect. Open Integrations → Add Integration → Microsoft Defender for Endpoint, and enter the tenant ID, application (client) ID, and client secret. The credential is validated against Microsoft before anything is stored; failures distinguish an unknown tenant, a rejected secret, and missing admin consent.
- Wait for the first scan. The scanner runs daily; the first health runs appear in the Monitoring Hub after the next sweep.
What each permission is for
- Machine.Read.All is required and powers the sensor and antivirus checks.
- Alert.Read.All enables the no active alerts check. Reads are presence-only: alert ids are counted per machine and no alert content is stored. Without it the check is omitted.
- User.Read.All (the WindowsDefenderATP permission, not the Graph one) improves device-owner attribution. Without it a device's last logged-on username is recorded but not matched to an email.
Device ownership
Attribution follows the same strict ladder as Falcon: a machine tag of the form email:[email protected] is an exact override; otherwise the last logged-on user is matched to a directory email only by an unambiguous local-part match, and ambiguity attributes nobody. Username-only attribution is shown flagged as unverified.
Managing the integration
- Client secrets expire. Entra caps secrets at 24 months and many tenants enforce less. An expired secret is the most likely reason a connected integration flips to error; the row's message says so. Create a new secret in Entra, click Reconnect on the Defender row, and enter it. Reconnecting re-runs the connection against the same integration.
- Errors. A revoked consent or invalid secret at scan time sets the integration to error with a plain-language reason; non-fatal scan issues are shown on the row even while connected.
- Removal. Remove stops the daily scans and erases our copy of the client secret. The app registration stays in your Entra tenant until you delete it there.
- Limits. One Defender tenant per account; fleets are capped at 500 devices per scan.
Billing and privacy
Defender monitoring is covered by an active Seat License. We read machine records (name, platform, last seen, sensor health, antivirus status, onboarding status, agent version, tags), logged-on users for attribution, and alert ids and machine ids for counting. Risk scores and exposure levels are ignored, and software inventory, vulnerabilities, advanced hunting, live response, and alert details are never accessed. The client secret is stored in AWS Secrets Manager and is never returned by any API.