Skip to main content

Overview

The Microsoft Defender ATP integration enables ThreatAware to connect to your Microsoft Defender ATP system for data collection and monitoring.
Connection Method: Credentials Setup Time: 15-20 minutes Access Required: Administrator account

Setup instructions

1

**Navigate to Microsoft Defender ATP in ThreatAware**

Open the ThreatAware dashboard, go to Settings → Integrations, and use the search bar to locate Microsoft Defender ATP.
2

**Connect and Authorize**

Click Connect next to Microsoft Defender ATP, and a pop-up window will appear. In the pop-up, click Authorize to initiate the automatic application registration process.
3

**Log in with Microsoft Administrator Account**

You will be redirected to a Microsoft login page. Sign in using an account with administrative privileges for Microsoft Defender ATP. Review and accept the permissions requested.
4

**Verify Connection**

After authorising, you will be redirected to a ThreatAware page that confirms whether the connection was successful. If successful, close the page. If the connection fails, try authorising again.This setup process automatically creates an application in Microsoft Defender ATP, so no manual app registration is required. Ensure the account used for authorization has the appropriate permissions in Microsoft Defender ATP for access.

Input Details

No manual input fields are required due to the automated authorization process.

Verification and Troubleshooting

Verification**: Confirm that the Integration Status in ThreatAware shows as Active once authorization is complete. Troubleshooting**: Authorization Errors**: Retry the authorization process if the initial attempt fails, ensuring that you are using an account with sufficient administrative permissions.

Troubleshooting

If you encounter connection errors:
  • Verify your credentials are correct
  • Check firewall rules allow outbound connections
  • Ensure required ports are accessible
  • Review the integration logs in ThreatAware
If data is not appearing after connecting:
  • Wait 5-10 minutes for initial sync
  • Verify the account has proper permissions
  • Check the integration status in Settings
  • Contact support if issues persist

Additional resources

For more information, contact ThreatAware support.