For the complete documentation index, see llms.txt. This page is also available as Markdown.

Microsoft Defender for Endpoint

This guide walks you through enabling Microsoft Defender API access in CybrHawk SIEM.

Requirements:

  • Access to Microsoft 365 services (Microsoft 365 Compliance Center, Azure Active Directory)

  • Premium P1/P2 Licensing (CybrHawk will automatically extract available security events based on your license tier)


Step 1: Grant API Permissions in Azure

1. Register an Application

Create Application

2. Assign Windows Defender ATP Permissions

  • In your application page for CybrHawk, go to API Permissions > Add permission > APIs my organization uses.

  • Search for WindowsDefenderATP and select it.

Windows Defender ATP Permissions
  • Select Application Permissions and add the following:

Standard Permissions

Host Isolation Permissions (Optional, for host isolation via MS Defender endpoint agents)

To enable Host Isolation features, also add:

  • Click Add Permissions.

  • Click Grant admin consent for [Your Organization] to grant the permissions you just added.

Grant Admin Consent

Step 2: Configure CybrHawk SIEM

  1. Log in to your CybrHawk SIEM Portal.

  2. Navigate to Deployments > Integrations.

  3. Click Add and select Microsoft Defender API.


Need Help?

If you have any questions or need further assistance, please contact CybrHawk Support.


Last updated