Skip to main content

Connect Microsoft Defender for Cloud

Use this guide to import Defender for Cloud security assessments and recommendations into Cracken.

Prerequisites

  • Microsoft Defender for Cloud enabled on the target subscriptions
  • Permission to create an app registration and client secret
  • Permission to assign Azure roles on the target subscriptions
  • A Cracken realm where you can configure data integrations

Prepare Azure access

Create a single-tenant Microsoft Entra app registration and a client secret. Record the directory tenant ID, application client ID, and client-secret value.

Assign the app's service principal the Azure Security Reader role on each subscription that Cracken should read. Assign it at a management-group scope only if every child subscription should be included. Security Reader can view security state without changing security settings.

Connect Defender for Cloud

  1. Open Integration Center → Data Integrations.
  2. On the Microsoft Defender for Cloud card, click Install.
  3. Enter the Tenant ID, Client ID, and Client Secret.
  4. Click Test Connection, then Save & Connect.

Cracken can list cloud-security findings visible to the service principal.

Sources

Next steps

  • Data Integrations — Review how connected security data flows into Cracken.
  • Cybergraph — See how Cracken uses imported cloud data.