Skip to main content

Microsoft Defender XDR Microsoft Defender XDR

Microsoft XDR (Extended Detection and Response), formerly known as 365 Defender, is a comprehensive cybersecurity solution that integrates multiple Microsoft security products for threat detection, investigation, and response across various domains like endpoints, email, and cloud to provide unified protection for an organization's digital environment.

Microsoft Defender XDR alerts are generated by many sources

Solutions that are part of Microsoft Defender XDR:

  • Microsoft Defender for Endpoint
  • Microsoft Defender for Office 365
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud Apps
  • The app governance add-on for Microsoft Defender for Cloud Apps
  • Microsoft Entra ID Protection
  • Microsoft Data Loss Prevention

Other services that have integrations with the Microsoft Defender security portal:

  • Microsoft Sentinel
  • Non-Microsoft security solutions that pass their alerts to Microsoft Sentinel
  • Microsoft Defender for Cloud

Creating a Microsoft Defender XDR connection

Using App Registration

To create the connection you need:

  • A Client ID
  • A Client Secret
  • A Tenant ID

Obtaining the credentials

  1. Go to Microsoft Azure Portal.

  2. Click on Azure Active Directory.

    Azure Active Directory

  3. Go to App Registrations.

    Azure App Registrations

  4. Create a new application registration or click on one of your existing applications.

    Azure App Registrations

  5. Copy your client ID and tenant ID.

    Client ID & Tenant ID

  6. Create a new client secret or copy your existing client secret here.

    Client Secret

  7. Navigate to API Permissions.

    API Permissions

  8. Add a new permission.

    Add New Permission

  9. Click on Microsoft Graph.

    Microsoft Graph

  10. Choose Application permissions and mark the permissions you wish to add.

    Microsoft Graph

  11. Click on Add permissions.

    Microsoft Graph

Please note:

Most of the permissions will require additional Admin Consent. Please refer to Microsoft Documentation for further information about permissions & consent.

Creating your connection

  1. In the Blink platform, navigate to the Connections page > Add connection. A New Connection dialog box opens displaying icons of external service providers available.
  2. Select the Microsoft Defender XDR icon. A dialog box with name of the connection and connection methods appear.
  3. (Optional) Edit the name of the connection. At a later stage you cannot edit the name.
  4. Select App Registration as the method to create the connection.
  5. Fill in the parameters:
    • The Client ID
    • The Client Secret
    • The Tenant ID
  6. (Optional) Click Test Connection to test it.
  7. Click Create connection. The new connection appears on the Connections page.