> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Defender for Endpoint

## Overview

This guide walks through how to create a Microsoft Defender for Endpoints connection and the permissions it requires to be used in Blink's Automated Case Management, across **Ingestion**, **Enrichment**, and **Response** workflows.

<Note>
  Permission requirements can vary by workflow type. See [Required Permissions](#required-permissions) for the full breakdown by connection option.
</Note>

***

## Creating a Connection

You can authenticate to Microsoft Defender for Endpoints in one of two ways. Both are supported across every Microsoft integration in Blink's Automated Case Management, so the connection you choose here can be reused elsewhere.

<Tabs>
  <Tab title="Microsoft Graph">
    Recommended if this connection will be reused across other Microsoft integrations in your Automated Case Management setup.

    ### Creating a Connection

    <Card title="Microsoft Graph Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-graph">
      Follow this guide to create a Microsoft Graph connection
    </Card>

    ### Required Permissions

    <Accordion title="Required Permissions for Microsoft Graph">
      | Permissions |
      | - |
      | AuditLog.Read.All |
      | Calendars.ReadBasic |
      | Calendars.ReadWrite |
      | Calendars.ReadWrite.Shared |
      | Channel.Create |
      | ChannelMember.ReadWrite.All |
      | ChannelMessage.ReadWrite |
      | ChannelMessage.Send |
      | ChannelSettings.ReadWrite.All |
      | Chat.Create |
      | Chat.ReadWrite |
      | Chat.ReadWrite.All |
      | ChatMember.ReadWrite |
      | Device.Command |
      | Device.Read.All |
      | DeviceManagementApps.ReadWrite.All |
      | DeviceManagementManagedDevices.PrivilegedOperations.All |
      | DeviceManagementManagedDevices.ReadWrite.All |
      | Directory.AccessAsUser.All |
      | Directory.ReadWrite.All |
      | eDiscovery.ReadWrite.All |
      | Files.ReadWrite |
      | Files.ReadWrite.All |
      | Group.ReadWrite.All |
      | GroupMember.ReadWrite.All |
      | IdentityRiskyUser.Read.All |
      | IdentityRiskyUser.ReadWrite.All |
      | Mail.Read |
      | Mail.ReadBasic |
      | Mail.ReadWrite |
      | Mail.ReadWrite.Shared |
      | Mail.Send |
      | MailboxSettings.ReadWrite |
      | Notes.ReadWrite.All |
      | offline\_access |
      | OnlineMeetings.ReadWrite |
      | SecurityAlert.Read.All |
      | SecurityAlert.ReadWrite.All |
      | SecurityIncident.ReadWrite.All |
      | Sites.Manage.All |
      | Sites.ReadWrite.All |
      | TeamMember.ReadWrite.All |
      | ThreatHunting.Read.All |
      | User.EnableDisableAccount.All |
      | User.ManageIdentities.All |
      | User.Read |
      | User.ReadWrite.All |
      | User.RevokeSessions.All |
      | DeviceLocalCredential.ReadBasic.All |
      | SecurityCopilotWorkspaces.ReadWrite.All |
    </Accordion>
  </Tab>

  <Tab title="Microsoft Defender for Endpoint">
    Recommended if this connection will be used for Defender for Endpoint only.

    ### Creating a Connection

    <Card title="Microsoft Defender for Endpoint Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-defender-for-endpoints">
      Follow this guide to create a Microsoft Defender for Endpoint connection
    </Card>

    ### Required Permissions

    | Permission |
    | - |
    | `Alert.Read.All` |
    | `Alert.ReadWrite.All` |
    | `Machine.LiveResponse` |
    | `Machine.Read.All` |
    | `Machine.ReadWrite.All` |
    | `Machine.Isolate` |
    | `Machine.StopAndQuarantine` |
    | `Machine.Scan` |
    | `AdvancedQuery.Read.All` |
    | `Ti.ReadWrite` |
    | `Library.Manage` |

    #### Per-action requirements

    Individual response actions require specific scopes, roles, and licensing:

    | Response action | Scopes | Role / permissions | License |
    | - | - | - | - |
    | Isolate Device / Release Device | `Machine.Read.All`, `Machine.Isolate` | Security Administrator, or a custom role with the *Active remediation actions* permission | Defender for Endpoint **Plan 2** |
    | Scan an Endpoint | `Machine.Scan`, `Machine.Read.All` | Security Administrator (or equivalent) | Defender for Endpoint Plan 1 or Plan 2 |
    | Stop Process + Quarantine File | `Machine.StopAndQuarantine` | Security Administrator (or equivalent) | Defender for Endpoint Plan 1 or Plan 2 |
    | Block IOC / Allow IOC | `Ti.ReadWrite` | Security Administrator, or equivalent role with indicator management rights | Defender for Endpoint Plan 1 or Plan 2 |
    | Run Script (Live Response) | `Machine.Read.All`, `Machine.LiveResponse`, `Library.Manage` | Security Center administrator, or appropriate API application permissions | Defender for Endpoint Plan 1 or Plan 2 |
  </Tab>
</Tabs>

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✓ Yes | Pulls alerts/incidents into Blink |
    | Enrichment | ✓ Yes | Adds Defender for Endpoints context to cases |
    | Response | ✓ Yes | Executes containment actions (e.g. isolate device, stop and quarantine) |
  </Accordion>
</AccordionGroup>

***


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.