> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Defender XDR

## Overview

This guide walks through how to create a Microsoft Defender XDR connection and the permissions it requires to be used in Blink's Automated Case Management, across **Ingestion**, **Enrichment**, and **Response** workflows.

<Note>
  Permission requirements can vary by workflow type. See [Required Permissions](#required-permissions) for the full breakdown by connection option.
</Note>

***

## Creating a Connection

You can authenticate to Microsoft Defender XDR in one of two ways. Both are supported across every Microsoft integration in Blink's Automated Case Management, so the connection you choose here can be reused elsewhere.

<Tabs>
  <Tab title="Microsoft Graph">
    Recommended if this connection will be reused across other Microsoft integrations in your Automated Case Management setup.

    ### Creating a Connection

    <Card title="Microsoft Graph Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-graph">
      Follow this guide to create a Microsoft Graph connection
    </Card>

    ### Required Permissions

    <Accordion title="Required Permissions for Microsoft Graph">
      | Permissions |
      | - |
      | AuditLog.Read.All |
      | Calendars.ReadBasic |
      | Calendars.ReadWrite |
      | Calendars.ReadWrite.Shared |
      | Channel.Create |
      | ChannelMember.ReadWrite.All |
      | ChannelMessage.ReadWrite |
      | ChannelMessage.Send |
      | ChannelSettings.ReadWrite.All |
      | Chat.Create |
      | Chat.ReadWrite |
      | Chat.ReadWrite.All |
      | ChatMember.ReadWrite |
      | Device.Command |
      | Device.Read.All |
      | DeviceManagementApps.ReadWrite.All |
      | DeviceManagementManagedDevices.PrivilegedOperations.All |
      | DeviceManagementManagedDevices.ReadWrite.All |
      | Directory.AccessAsUser.All |
      | Directory.ReadWrite.All |
      | eDiscovery.ReadWrite.All |
      | Files.ReadWrite |
      | Files.ReadWrite.All |
      | Group.ReadWrite.All |
      | GroupMember.ReadWrite.All |
      | IdentityRiskyUser.Read.All |
      | IdentityRiskyUser.ReadWrite.All |
      | Mail.Read |
      | Mail.ReadBasic |
      | Mail.ReadWrite |
      | Mail.ReadWrite.Shared |
      | Mail.Send |
      | MailboxSettings.ReadWrite |
      | Notes.ReadWrite.All |
      | offline\_access |
      | OnlineMeetings.ReadWrite |
      | SecurityAlert.Read.All |
      | SecurityAlert.ReadWrite.All |
      | SecurityIncident.ReadWrite.All |
      | Sites.Manage.All |
      | Sites.ReadWrite.All |
      | TeamMember.ReadWrite.All |
      | ThreatHunting.Read.All |
      | User.EnableDisableAccount.All |
      | User.ManageIdentities.All |
      | User.Read |
      | User.ReadWrite.All |
      | User.RevokeSessions.All |
      | DeviceLocalCredential.ReadBasic.All |
      | SecurityCopilotWorkspaces.ReadWrite.All |
    </Accordion>
  </Tab>

  <Tab title="Microsoft Defender XDR">
    Recommended if this connection will be used for Defender XDR only.

    ### Creating a Connection

    <Card title="Microsoft Defender XDR Connection Guide" icon="arrow-up-right-from-square" href="https://docs.blinkops.com/docs/integrations/microsoft-xdr">
      Follow this guide to create a Microsoft Defender XDR connection
    </Card>

    ### Required Permissions

    To support all Blink actions, these are the required application permissions:

    <Note>
      As a best practice, request the least privileged permissions that your app needs in order to access data and function correctly. Requesting permissions with more than the necessary privileges is poor security practice, which may cause users to refrain from consenting and affect your app's usage. For additional information, refer to Microsoft Graph permissions.
    </Note>

    **Least privileged permissions**

    | Permission |
    | - |
    | `SecurityAlert.Read.All` |
    | `SecurityAlert.ReadWrite.All` |
    | `SecurityIncident.Read.All` |
    | `SecurityIncident.ReadWrite.All` |

    **Higher privileged permissions**

    | Permission |
    | - |
    | `SecurityAlert.ReadWrite.All` |
    | `SecurityIncident.ReadWrite.All` |

    #### Response Action Permissions

    The permissions above cover alert and incident ingestion/enrichment. Response actions run against **Microsoft Defender for Endpoint** and require additional scopes, roles, and licensing per action:

    | Response action | Scopes | Role / permissions | License |
    | - | - | - | - |
    | Isolate Device / Release Device | `Machine.Read.All`, `Machine.Isolate` | Security Administrator, or a custom role with the *Active remediation actions* permission | Defender for Endpoint **Plan 2** |
    | Stop Process + Quarantine File | `Machine.StopAndQuarantine` | Security Administrator (or equivalent) | Defender for Endpoint Plan 1 or Plan 2 |
    | Block IOC / Allow IOC | `Ti.ReadWrite` | Security Administrator, or equivalent role with indicator management rights | Defender for Endpoint Plan 1 or Plan 2 |
    | Run Script (Live Response) | `Machine.Read.All`, `Machine.LiveResponse`, `Library.Manage` | Security Center administrator, or appropriate API application permissions | Defender for Endpoint Plan 1 or Plan 2 |

    <Info>
      These response actions use the Defender for Endpoint API rather than the Graph security endpoints. See the [Microsoft Defender for Endpoints](/docs/case-management/blinks-automated-case-management/sources/microsoft/microsoft-defender-for-endpoint) page for the full endpoint permission set.
    </Info>
  </Tab>
</Tabs>

<AccordionGroup>
  <Accordion title="Which stage of Alert Processing need this connection?" icon="table">
    | Source | Requires this connection? | Notes |
    | - | - | - |
    | Ingestion | ✓ Yes | Pulls alerts/incidents into Blink |
    | Enrichment | ✓ Yes | Adds Defender XDR context to cases (e.g. KQL user enrichment activity) |
    | Response | ✓ Yes | Executes containment actions (e.g. isolate device, block/allow IOC, quarantine file) |
  </Accordion>
</AccordionGroup>

***


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.