Overview
This guide walks through how to create a Microsoft Defender for Cloud connection and the permissions it requires to be used in Blink’s Automated Case Management, across Ingestion, Enrichment, and Response workflows.Permission requirements can vary by workflow type. See Required Permissions for the full breakdown by connection option.
Creating a Connection
You can authenticate to Microsoft Defender for Cloud in one of two ways. Both are supported across every Microsoft integration in Blink’s Automated Case Management, so the connection you choose here can be reused elsewhere.- Microsoft Graph
- Microsoft Defender for Cloud
Which stage of Alert Processing need this connection?
Which stage of Alert Processing need this connection?