Skip to main content

Connect Microsoft Defender for Endpoint

Use this guide to import Microsoft Defender for Endpoint alerts and device data into Cracken.

Prerequisites

  • A Microsoft Defender for Endpoint tenant
  • Permission to create an app registration and client secret
  • A tenant administrator who can grant consent for Defender application permissions
  • A Cracken realm where you can configure data integrations

Prepare the application

Create a single-tenant Microsoft Entra app registration. Add these WindowsDefenderATP application permissions:

  • Alert.Read.All
  • Machine.Read.All

Grant tenant-wide admin consent. Create a client secret and record the directory tenant ID, application client ID, and client-secret value.

Connect Defender for Endpoint

  1. Open Integration Center → Data Integrations.
  2. On the Microsoft Defender for Endpoint card, click Install.
  3. Enter the Tenant ID, Client ID, and Client Secret.
  4. Click Test Connection, then Save & Connect.

Cracken can list endpoint alerts and request an on-demand synchronization of the latest Defender results. To import vulnerability findings, connect Microsoft Defender Vulnerability Management separately.

Sources

Next steps

  • Data Integrations — Review how connected security data flows into Cracken.
  • Cybergraph — See how Cracken uses imported endpoint data.