# AQUILA - Microsoft Defender for Endpoint

### <span style="color: rgb(53, 152, 219);">**Overview**</span>

This guide walks through the full process of integrating Microsoft Defender for Endpoint (MDE) to centralize security telemetry, enrich alerts, and enable unified threat hunting across your environment.

This integration is for <span style="color: rgb(185, 106, 217);">[Microsoft Defender for Endpoint](https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/microsoft-defender-endpoint?view=o365-worldwide)</span> logs.

Microsoft Defender for Endpoint integration collects data for Alert, Machine, Machine Action, and Vulnerability logs using REST API.

This integration collects the following logs:

- <span style="color: rgb(185, 106, 217);">[Alert](https://learn.microsoft.com/en-us/defender-endpoint/api/get-alerts?view=o365-worldwide) </span>- Retrieves alerts generated by Microsoft Defender for Endpoint.
- <span style="color: rgb(185, 106, 217);">[Machine](https://learn.microsoft.com/en-us/defender-endpoint/api/get-machines?view=o365-worldwide)</span> - Retrieves machines that have communicated with Microsoft Defender for Endpoint.
- <span style="color: rgb(185, 106, 217);">[Machine Action](https://learn.microsoft.com/en-us/defender-endpoint/api/get-machineactions-collection?view=o365-worldwide)</span> - Retrieves logs of actions carried out on machines.
- <span style="color: rgb(185, 106, 217);">[Vulnerability](https://learn.microsoft.com/en-us/defender-endpoint/api/get-assessment-software-vulnerabilities#2-export-software-vulnerabilities-assessment-via-files)</span> - Retrieves logs of Vulnerability.

### <span style="color: rgb(53, 152, 219);">**Prerequisites**</span>

Before you begin, ensure the following are in place:

- An active Microsoft Defender for Endpoint license (Plan 1 or Plan 2, or Microsoft 365 Defender)
- Access to the Microsoft Entra ID (formerly Azure AD) portal to register an application
- Permissions to grant API permissions within your tenant (typically a Global Administrator or Security Administrator role)

### <span style="color: rgb(53, 152, 219);">**Azure App Registration**</span>

This integration authenticates to the MDE API using OAuth 2.0 client credentials. You need to register an application in Microsoft Entra ID and grant it the appropriate API permissions.

**Step 1:** Register a New Application

- Navigate to **portal.azure.com** and sign in with an account that has sufficient privileges.
- Go to **Microsoft Entra ID** &gt; **App registrations** &gt; **New registration**.
- Provide a descriptive name.
- Under Supported account types, select Accounts in this organizational directory only (Single tenant).
- Leave the Redirect URI blank. Click Register.
- Copy and save the **Application (client) ID** and **Directory (tenant) ID** from the overview page. You will need these later.

**Step 2**: Create a Client Secret

- In your newly created app registration, navigate to **Certificates &amp; secrets** &gt; **Client secrets** &gt; **New client secret**.
- Add a description and choose an expiry period appropriate for your organization.
- Click Add, then immediately copy the **secret Value**. This is the only time it is shown in full.

**Step 3:**

- In the app registration, go to **API permissions** &gt; **Add a permission**.
- Select APIs my organization uses, then search for and select WindowsDefenderATP.
- Choose Application permissions and grant the following minimum required scopes:

<div align="left" dir="ltr" id="bkmrk-permission-purpose-a"><table><colgroup><col width="200"></col><col width="424"></col></colgroup><thead><tr><th scope="col">Permission

</th><th scope="col">Purpose

</th></tr></thead><tbody><tr><td>Alert.Read.All

</td><td>Read all MDE alerts and incidents

</td></tr><tr><td>Machine.Read.All

</td><td>Read device inventory and health state

</td></tr><tr><td>Vulnerability.Read.All

</td><td>Read vulnerability and software inventory

</td></tr><tr><td>AdvancedQuery.Read.All

</td><td>Execute advanced hunting queries (optional)

</td></tr></tbody></table>

</div>**Step 4:**

- Click Add permissions, then click Grant admin consent for \[Your Tenant\]. Confirm when prompted.
- Verify the Status column shows Granted for \[tenant\] for all added permissions.

<div class="euiFlexGroup css-weekwv-euiFlexGroup-responsive-none-spaceBetween-flexStart-row" id="bkmrk-"><div class="euiFlexItem css-kpsrin-euiFlexItem-growZero"></div></div><p class="callout warning"><span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" style="color: rgb(224, 62, 45);" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Please saved and provide this values:</span></span></p>

1. **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Directory (tenant) ID</span></span>**
2. **<span class="TextRun SCXW264382529 BCX0" data-contrast="none" lang="EN-US" xml:lang="EN-US"><span class="NormalTextRun SCXW264382529 BCX0" data-ccp-parastyle="heading 3">Application (client) ID</span></span>**
3. <div aria-label="Client Secret" class="euiFlexItem css-kpsrin-euiFlexItem-growZero">**Client Secret Value**</div>

<span class="euiSwitch__label css-cxzz3-euiSwitch__label" id="bkmrk-microsoft-defender-f-1"></span>

*If you need further assistance, kindly contact our support at<span style="color: rgb(53, 152, 219);"> </span>*<span style="color: rgb(53, 152, 219);">***support@cytechint.com***</span> *for prompt assistance and guidance.*