Overview
The Microsoft Defender ATP integration enables ThreatAware to connect to your Microsoft Defender ATP system for data collection and monitoring.Connection Method: Credentials
Setup Time: 15-20 minutes
Access Required: Administrator account
Setup instructions
1
**Navigate to Microsoft Defender ATP in ThreatAware**
Open the ThreatAware dashboard, go to Settings → Integrations, and use the search bar to locate Microsoft Defender ATP.
2
**Connect and Authorize**
Click Connect next to Microsoft Defender ATP, and a pop-up window will appear.
In the pop-up, click Authorize to initiate the automatic application registration process.
3
**Log in with Microsoft Administrator Account**
You will be redirected to a Microsoft login page. Sign in using an account with administrative privileges for Microsoft Defender ATP.
Review and accept the permissions requested.
4
**Verify Connection**
After authorising, you will be redirected to a ThreatAware page that confirms whether the connection was successful.
If successful, close the page. If the connection fails, try authorising again.
Important Notes and Links
This setup process automatically creates an application in Microsoft Defender ATP, so no manual app registration is required. Ensure the account used for authorization has the appropriate permissions in Microsoft Defender ATP for access.Input Details
No manual input fields are required due to the automated authorization process.Verification and Troubleshooting
Verification**: Confirm that the Integration Status in ThreatAware shows as Active once authorization is complete. Troubleshooting**: Authorization Errors**: Retry the authorization process if the initial attempt fails, ensuring that you are using an account with sufficient administrative permissions.Troubleshooting
Connection Issues
Connection Issues
If you encounter connection errors:
- Verify your credentials are correct
- Check firewall rules allow outbound connections
- Ensure required ports are accessible
- Review the integration logs in ThreatAware
No Data Appearing
No Data Appearing
If data is not appearing after connecting:
- Wait 5-10 minutes for initial sync
- Verify the account has proper permissions
- Check the integration status in Settings
- Contact support if issues persist