> ## Documentation Index
> Fetch the complete documentation index at: https://docs.threataware.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Defender ATP

> Connect ThreatAware to Microsoft Defender ATP

## Overview

The Microsoft Defender ATP integration enables ThreatAware to connect to your Microsoft Defender ATP system for data collection and monitoring.

<Info>
  **Connection Method**: Credentials
  **Setup Time**: 15-20 minutes
  **Access Required**: Administrator account
</Info>

## Setup instructions

<Steps>
  <Step title="**Navigate to Microsoft Defender ATP in ThreatAware**">
    Open the ThreatAware dashboard, go to **Settings → Integrations**, and use the search bar to locate **Microsoft Defender ATP**.
  </Step>

  <Step title="**Connect and Authorize**">
    Click **Connect** next to Microsoft Defender ATP, and a pop-up window will appear.
    In the pop-up, click **Authorize** to initiate the automatic application registration process.
  </Step>

  <Step title="**Log in with Microsoft Administrator Account**">
    You will be redirected to a Microsoft login page. Sign in using an account with administrative privileges for Microsoft Defender ATP.
    Review and accept the permissions requested.
  </Step>

  <Step title="**Verify Connection**">
    After authorising, you will be redirected to a ThreatAware page that confirms whether the connection was successful.
    If successful, close the page. If the connection fails, try authorising again.

    ### Important Notes and Links

    This setup process automatically creates an application in Microsoft Defender ATP, so no manual app registration is required.
    Ensure the account used for authorization has the appropriate permissions in Microsoft Defender ATP for access.

    ### Input Details

    No manual input fields are required due to the automated authorization process.

    ### Verification and Troubleshooting

    Verification\*\*: Confirm that the **Integration Status** in ThreatAware shows as **Active** once authorization is complete.
    Troubleshooting\*\*:
    Authorization Errors\*\*: Retry the authorization process if the initial attempt fails, ensuring that you are using an account with sufficient administrative permissions.
  </Step>
</Steps>

## Troubleshooting

<AccordionGroup>
  <Accordion title="Connection Issues" icon="triangle-exclamation">
    If you encounter connection errors:

    * Verify your credentials are correct
    * Check firewall rules allow outbound connections
    * Ensure required ports are accessible
    * Review the integration logs in ThreatAware
  </Accordion>

  <Accordion title="No Data Appearing" icon="database">
    If data is not appearing after connecting:

    * Wait 5-10 minutes for initial sync
    * Verify the account has proper permissions
    * Check the integration status in Settings
    * Contact support if issues persist
  </Accordion>
</AccordionGroup>

## Additional resources

For more information, contact ThreatAware support.
