Microsoft Defender for Endpoint
Copy link

You can start virus scans, stop execution of malicious code, manage isolation of network resources, get security recommendations in your Microsoft Defender for Endpoint  tenant, and trigger workflows on new security alerts with the Microsoft Defender for Endpoint plugin for Automation (InsightConnect) .

ℹ️

Name Change Notice

Microsoft Defender for Endpoint was previously known as Windows Defender ATP. You may still see the former name in Azure configurations, logs, or documentation. Both names refer to the same service.

To use the Microsoft Defender for Endpoint plugin, you must create an application in your Azure Active Directory and then configure the connection in Automation (InsightConnect). For more information on the functionality of the Microsoft Defender for Endpoint plugin, see the Extension Library listing .

Prerequisites
Copy link

When you create an application in Azure Active Directory, you must assign specific API permissions. The required permissions depend on the actions your application will perform.

Make sure your application has the following minimum permissions:

  1. From Command Home, go to Automation > Plugins.

  2. From the Plugins & Tools page, go to the Connections tab and click Add Connection.

  3. Configure the connection for the Microsoft Defender ATP plugin. Give the connection a unique and identifiable name, select where the plugin should run, and choose the Microsoft Windows Defender ATP plugin from the list. If it’s not available, then import the plugin from the Installed Plugins tab.

  4. Configure your Microsoft Defender ATP credentials. In the Secret Key field, create a credential and paste in the Microsoft Defender ATP Application Secret that you copied earlier. In addition, add the Application ID and Directory ID you copied earlier.

Success!

The Microsoft Defender for Endpoint plugin is ready to use.

Test in Progress
Copy link

Save the connection, and the connection test will attempt to authenticate to your Azure Active Directory Microsoft Defender for Endpoint application. A blue circle on the Connection tile indicates that the Connection test is in progress.

Success
Copy link

If there is no circle, the connection succeeded and you’re ready to begin orchestrating your processes with Microsoft Defender for Endpoint.

Failed
Copy link

A red circle indicates that the connection test failed. If this occurs, check your connection details (including the Application Secret, Application ID and Directory ID) before trying again.

The log may contain useful troubleshooting information. Click the ellipsis at the right side of the plugin and click View to see a list of your recent connection tests.

Under the Test Status tab, expand the dropdown for the test that encountered an error to view its log.