Skip to main content

Connect Microsoft Defender Vulnerability Management

Use this guide to connect Microsoft Defender vulnerability findings to Cracken.

Prerequisites

  • Microsoft Defender Vulnerability Management enabled
  • A Microsoft Entra Privileged Role Administrator, Cloud Application Administrator, or Global Administrator
  • Permission to grant tenant-wide consent for WindowsDefenderATP application permissions
  • A Cracken realm where you can configure data integrations

Required authorization

This connector uses a Microsoft authorization flow instead of credential fields. The administrator who opens the consent page must approve the requested organization-wide Defender permissions. Those permissions allow Cracken to read vulnerability and device data; admin consent must be granted again if the application's requested permissions change.

Connect Defender Vulnerability Management

  1. Open Integration Center → Data Integrations.
  2. On the MS Defender VM card, click Install.
  3. Click Save & Connect and sign in with an administrator who can grant tenant-wide consent.
  4. Review the requested permissions and accept.
  5. Return to Cracken and confirm that the card reads Configured.

Cracken can list vulnerability findings and request an on-demand synchronization of the latest Defender results after authorization.

Sources

Next steps

  • Data Integrations — Review how connected security data flows into Cracken.
  • Cybergraph — See how Cracken uses imported vulnerability data.