AQUILA - Microsoft Defender for Endpoint

Overview

This guide walks through the full process of integrating Microsoft Defender for Endpoint (MDE) to centralize security telemetry, enrich alerts, and enable unified threat hunting across your environment.

This integration is for Microsoft Defender for Endpoint logs.

Microsoft Defender for Endpoint integration collects data for Alert, Machine, Machine Action, and Vulnerability logs using REST API.

This integration collects the following logs:

Prerequisites

Before you begin, ensure the following are in place:

Azure App Registration

This integration authenticates to the MDE API using OAuth 2.0 client credentials. You need to register an application in Microsoft Entra ID and grant it the appropriate API permissions.

Step 1: Register a New Application

Step 2: Create a Client Secret

Step 3: 

Permission

Purpose

Alert.Read.All

Read all MDE alerts and incidents

Machine.Read.All

Read device inventory and health state

Vulnerability.Read.All

Read vulnerability and software inventory

AdvancedQuery.Read.All

Execute advanced hunting queries (optional)

Step 4: 

Please saved and provide this values:

  1. Directory (tenant) ID
  2. Application (client) ID
  3. Client Secret Value

If you need further assistance, kindly contact our support at support@cytechint.com for prompt assistance and guidance.


Revision #3
Created 5 March 2026 07:22:27
Updated 13 May 2026 18:46:47 by Richmond Abella