Microsoft Defender

Pull Secure Score posture findings and Defender alerts.

Source connector

Source connector — pulls identity and access data from Microsoft Defender into ComplianceScout where it is scored against your compliance frameworks and violation rules.

What ComplianceScout collects

After a successful sync, the following data is available in your ComplianceScout dashboard for violation detection and reporting.

  • Microsoft Secure Score and per-control score breakdown
  • Defender for Identity alerts and incident metadata
  • Vulnerability findings from Defender for Endpoint
  • Security recommendations and remediation status

Required credentials

These fields are collected when you add the connector in the ComplianceScout dashboard. Secrets are encrypted at rest using AES-256-GCM and are never logged.

FieldTypeRequiredNotes
Tenant IDTextRequired
Client IDTextRequired
Client secretSecretRequiredApp needs SecurityEvents.Read.All admin-consented in Entra ID.

How to set up this connector

Follow these steps to gather the credentials above and connect Microsoft Defender to ComplianceScout.

  1. In the Azure Portal, create a new App registration under Microsoft Entra ID → App registrations → New registration.

  2. Go to API permissions → Add a permission → Microsoft Graph → Application permissions and add SecurityEvents.Read.All. Click Grant admin consent.

  3. Go to Certificates & secrets → New client secret, copy the value.

  4. Copy the Application (client) ID and Directory (tenant) ID from the Overview page.

  5. In ComplianceScout, go to Data & Secrets → Integrations → Add Connector → Microsoft Defender and enter the credentials.

Ready to connect Microsoft Defender?

Start a free trial — your tenant is provisioned instantly and you can wire up this integration from the connectors page.