Connect Microsoft Defender for Endpoint
Use this guide to import Microsoft Defender for Endpoint alerts and device data into Cracken.
Prerequisites
- A Microsoft Defender for Endpoint tenant
- Permission to create an app registration and client secret
- A tenant administrator who can grant consent for Defender application permissions
- A Cracken realm where you can configure data integrations
Prepare the application
Create a single-tenant Microsoft Entra app registration. Add these WindowsDefenderATP application permissions:
Alert.Read.AllMachine.Read.All
Grant tenant-wide admin consent. Create a client secret and record the directory tenant ID, application client ID, and client-secret value.
Connect Defender for Endpoint
- Open Integration Center → Data Integrations.
- On the Microsoft Defender for Endpoint card, click Install.
- Enter the Tenant ID, Client ID, and Client Secret.
- Click Test Connection, then Save & Connect.
Cracken can list endpoint alerts and request an on-demand synchronization of the latest Defender results. To import vulnerability findings, connect Microsoft Defender Vulnerability Management separately.
Sources
- Microsoft Defender for Endpoint API permissions
- Create a Microsoft Entra application and service principal
Next steps
- Data Integrations — Review how connected security data flows into Cracken.
- Cybergraph — See how Cracken uses imported endpoint data.