Skip to main content

Overview

This guide walks through how to create a Microsoft Defender for Cloud connection and the permissions it requires to be used in Blink’s Automated Case Management, across Ingestion, Enrichment, and Response workflows.
Permission requirements can vary by workflow type. See Required Permissions for the full breakdown by connection option.

Creating a Connection

You can authenticate to Microsoft Defender for Cloud in one of two ways. Both are supported across every Microsoft integration in Blink’s Automated Case Management, so the connection you choose here can be reused elsewhere.
Recommended if this connection will be reused across other Microsoft integrations in your Automated Case Management setup.

Creating a Connection

Microsoft Graph Connection Guide

Follow this guide to create a Microsoft Graph connection

Required Permissions