Connect Microsoft Defender for Cloud
Use this guide to import Defender for Cloud security assessments and recommendations into Cracken.
Prerequisites
- Microsoft Defender for Cloud enabled on the target subscriptions
- Permission to create an app registration and client secret
- Permission to assign Azure roles on the target subscriptions
- A Cracken realm where you can configure data integrations
Prepare Azure access
Create a single-tenant Microsoft Entra app registration and a client secret. Record the directory tenant ID, application client ID, and client-secret value.
Assign the app's service principal the Azure Security Reader role on each subscription that Cracken should read. Assign it at a management-group scope only if every child subscription should be included. Security Reader can view security state without changing security settings.
Connect Defender for Cloud
- Open Integration Center → Data Integrations.
- On the Microsoft Defender for Cloud card, click Install.
- Enter the Tenant ID, Client ID, and Client Secret.
- Click Test Connection, then Save & Connect.
Cracken can list cloud-security findings visible to the service principal.
Sources
Next steps
- Data Integrations — Review how connected security data flows into Cracken.
- Cybergraph — See how Cracken uses imported cloud data.