Connect Microsoft Defender Vulnerability Management
Use this guide to connect Microsoft Defender vulnerability findings to Cracken.
Prerequisites
- Microsoft Defender Vulnerability Management enabled
- A Microsoft Entra Privileged Role Administrator, Cloud Application Administrator, or Global Administrator
- Permission to grant tenant-wide consent for WindowsDefenderATP application permissions
- A Cracken realm where you can configure data integrations
Required authorization
This connector uses a Microsoft authorization flow instead of credential fields. The administrator who opens the consent page must approve the requested organization-wide Defender permissions. Those permissions allow Cracken to read vulnerability and device data; admin consent must be granted again if the application's requested permissions change.
Connect Defender Vulnerability Management
- Open Integration Center → Data Integrations.
- On the MS Defender VM card, click Install.
- Click Save & Connect and sign in with an administrator who can grant tenant-wide consent.
- Review the requested permissions and accept.
- Return to Cracken and confirm that the card reads Configured.
Cracken can list vulnerability findings and request an on-demand synchronization of the latest Defender results after authorization.
Sources
Next steps
- Data Integrations — Review how connected security data flows into Cracken.
- Cybergraph — See how Cracken uses imported vulnerability data.