Microsoft Defender discoveries
Cyberwatch can list and monitor all assets protected by Microsoft Defender for Endpoint by querying the Microsoft Defender API.
For each detected asset, the discovery retrieves the information available in Microsoft Defender (machine name, operating system, address, etc.) as well as the list of software installed on it.
Monitoring of Microsoft Defender assets is performed from the data exposed by the Microsoft Defender API. Cyberwatch can list the detected software and view the asset’s information, but cannot deploy patches on these assets.
Configure your API access
First, you must create a new application registration from the Azure console.
For the Cyberwatch integration with Microsoft Defender to work, your application must have the following permissions on the WindowsDefenderATP (Microsoft Defender for Endpoint) API:
- Machine.Read.All
- Software.Read.All
Note that these permissions require admin consent to be applied.
Back on the application registration page, you can create a client secret from Certificates & secrets.
Once these 3 pieces of information are gathered, you can create Microsoft Azure credentials in Cyberwatch, from the Stored credentials menu.
Create the discovery
- From Discoveries, click Add. Click Microsoft Defender in the Local infrastructure category
- Enter the name of the scan
- Select optional groups that will be assigned to the scan
- Choose the source of the scan (the Cyberwatch scanner that will run the operation)
- Using the Credentials selector, pick the Microsoft Defender account registered in previous steps
- Select Microsoft Defender agentless connection in Automatic registration if you want to automatically register discovered assets
- Choose a recurrence. The default value 0 days means the scan will be launched only once
- Click Confirm
When created, the discovery is immediately started as a background task. You may check the state of the task any time from Discoveries.
Newly monitored Microsoft Defender assets are found in the assets menu.