Ellipse Gradient for Header

Microsoft Defender for Endpoint Integration Guide

Integrate Microsoft Defender for Endpoint with enterprise systems through REST APIs, Advanced Hunting, selected security event streams, and Microsoft Entra ID authentication.

Microsoft Defender for Endpoint integration options at a glance

Microsoft Defender for Endpoint provides REST APIs for machines, alerts, indicators, vulnerabilities, recommendations, evidence, and machine actions. Its Advanced Hunting API supports Kusto Query Language queries over security tables such as DeviceInfo, DeviceEvents, DeviceNetworkEvents, DeviceProcessEvents, and DeviceFileEvents. Selected streaming and notification capabilities can deliver endpoint data to Azure Event Hubs or Azure Storage, although coverage is not a universal webhook model. Microsoft Entra ID supplies OAuth 2.0 bearer-token authentication with operation-specific permissions. Martini can orchestrate scheduled or event-assisted workflows, handle pagination and checkpoints, transform JSON results, apply security rules, and expose normalized APIs for downstream systems.

Integration pointSupported by Microsoft Defender for Endpoint?Common use casesHow Martini supports it
REST APIsYesRetrieve machines, alerts, vulnerabilities, recommendations, indicators, evidence, and action status; initiate supported machine response operations.Martini can consume the Defender for Endpoint REST APIs from workflows, map JSON payloads, apply business rules, and expose normalized APIs.
Advanced Hunting APIYesSubmit Kusto Query Language queries against tables such as DeviceInfo, DeviceEvents, DeviceNetworkEvents, DeviceProcessEvents, and DeviceFileEvents.Martini can run bounded scheduled queries, process continuation or large-result behavior, transform results, and persist checkpoints.
Webhooks / outbound callbacksLimitedSelected security products and resource surfaces provide notification or change-notification options; coverage is not universal for Defender objects.Martini can receive supported webhook-style notifications, then retrieve authoritative resources and use polling when the required event is unavailable.
Streaming APILimitedSelected endpoint security event data can be sent to Azure Event Hubs or Azure Storage for downstream processing.Martini can orchestrate processing around supported event destinations and route, validate, transform, and checkpoint event data.
Bulk / async / batch APIsLimitedAdvanced Hunting and selected security data operations support large-result or asynchronous patterns; no universal bulk CRUD API is confirmed.Martini can implement batching, continuation handling, bounded concurrency, and checkpointed retries in workflows.
File / investigation dataLimitedSelected investigation package, evidence, and response operations retrieve endpoint artifacts, including potentially large or binary downloads.Martini can retrieve supported artifacts, process short-lived results, and apply retention and sensitive-data controls.
AuthenticationYesMicrosoft Entra ID OAuth 2.0 provides bearer tokens with application or delegated permissions and administrator consent where required.Martini can store credentials securely, call token-protected endpoints, and separate environments and permission scopes.
Database / analytics accessYesAdvanced Hunting provides Kusto-based analytics access to Defender security data, rather than direct database connectivity.Martini can consume the documented hunting API and map query results into databases, files, APIs, or downstream security systems.

How Microsoft Defender for Endpoint exposes data and business events

Defender REST APIs

Microsoft Defender for Endpoint REST APIs provide the primary programmatic interface for machines, alerts, indicators, vulnerabilities, recommendations, evidence, and machine response actions. Responses commonly use JSON and larger collections may require continuation or pagination.

Martini implementation pattern

Martini implementation pattern: a workflow authenticates with Microsoft Entra ID, calls the required REST operation, follows continuation information, maps the response into a canonical model, and writes or exposes the result for downstream systems.

Implementation sequence

Obtain an OAuth 2.0 bearer token
Call the required Defender REST endpoint
Process continuation links or tokens
Map the JSON response to the target model
Persist identifiers and processing state
Retry transient failures with bounded backoff

Advanced Hunting API

The Advanced Hunting API accepts Kusto Query Language queries and returns analytics results from Defender security tables. It is query access rather than a general transactional database interface, and query permissions, retention, limits, and execution constraints apply.

Martini implementation pattern

Martini implementation pattern: a scheduled workflow submits a bounded query, uses a time-window watermark, processes returned rows, and stores the checkpoint and stable identifiers for replay-safe synchronization.

Implementation sequence

Build a bounded Kusto query
Submit the query with the required permission
Read result pages or continuation data
Normalize hunting table rows
Deduplicate by event identifiers and timestamps
Store the completed time-window checkpoint

Selected notifications and streaming

Microsoft provides selected streaming and notification capabilities through product-specific surfaces, including streaming to Azure Event Hubs or Azure Storage and selected security change notifications. These mechanisms do not cover every Defender object or event.

Martini implementation pattern

Martini implementation pattern: Martini receives or processes a supported notification, validates the event, retrieves the authoritative Defender resource when necessary, and falls back to scheduled polling for uncovered changes.

Implementation sequence

Confirm that the required event surface is supported
Receive the notification or stream payload
Validate the event and correlation identifiers
Retrieve authoritative resource details when needed
Map and route the event to downstream systems
Record acknowledgements and replay state

Investigation packages and evidence

Selected Defender operations can retrieve investigation packages and evidence associated with endpoint response. These payloads may be binary, large, short-lived, and sensitive, and do not represent a general-purpose file repository.

Martini implementation pattern

Martini implementation pattern: a controlled workflow requests or retrieves the artifact, stores it only where permitted, records the operation status, and routes metadata or content to an approved target.

Implementation sequence

Validate the request and machine permissions
Initiate or retrieve the investigation operation
Poll asynchronous status where required
Download the supported artifact securely
Apply retention and sensitive-data rules
Record the artifact outcome and audit details

Common Microsoft Defender for Endpoint integration patterns

Pattern 1: Sync Defender alerts to ServiceNow

When to use this pattern

Use this pattern when security detections must become governed ITSM incidents with ownership, priority, remediation tracking, and closure synchronization.

Integration direction
Microsoft Defender for Endpoint
Martini
ServiceNow
Example Mapping
Microsoft Defender for Endpoint FieldCanonical FieldTarget Field
Alert.idsecurityAlertIdServiceNow correlation identifier
Alert.severityseverityincident priority
Alert.statuslifecycleStatusincident state
Alert.machineIdaffectedMachineIdconfiguration item reference
Martini implementation pattern

A scheduled workflow or supported notification flow retrieves new and changed Alerts, fetches related machine or evidence context, maps severity and state, and creates or updates ServiceNow incidents. Martini uses Alert ID for deduplication, validates required fields, and retries only transient failures.

Martini capabilities used
  • workflows
  • API consumption
  • scheduling
  • data mapping
  • business rules
  • error handling

Pattern 2: Publish vulnerability remediation work items

When to use this pattern

Use this pattern when Vulnerabilities and Recommendations must be converted into actionable remediation tasks or periodic risk reports for engineering teams.

Integration direction
Microsoft Defender for Endpoint
Martini
Jira
Example Mapping
Microsoft Defender for Endpoint FieldCanonical FieldTarget Field
Vulnerability.idvulnerabilityIdentifierJira vulnerability reference
Vulnerability.severityriskSeverityissue priority
Vulnerability.affectedSoftwareaffectedComponentcomponent
Recommendation.remediationremediationGuidanceissue description
Martini implementation pattern

A scheduled workflow queries vulnerabilities and recommendations, enriches affected software and device context, applies severity thresholds, and creates or updates Jira issues. Checkpoints, stable identifiers, and replay-safe writes prevent duplicate work items.

Martini capabilities used
  • workflows
  • API consumption
  • mapping
  • transformations
  • conditional routing
  • retry handling

Pattern 3: Orchestrate approved machine response

When to use this pattern

Use this pattern when an approved security process must isolate a machine, start a scan, collect an investigation package, or initiate another supported Machine action.

Integration direction
ServiceNow
Martini
Microsoft Defender for Endpoint
Example Mapping
Microsoft Defender for Endpoint FieldCanonical FieldTarget Field
request.machineIdtargetMachineIdMachine ID
request.actionapprovedResponseActionDefender action operation
request.approverauthorizationContextaudit metadata
action.idresponseOperationIdServiceNow work note
Martini implementation pattern

A Martini API or workflow receives the approved request, validates authorization and machine state, invokes the permitted Defender operation, and tracks asynchronous status. The workflow records requester, approver, target, action, result, and failure reason, while preventing repeated execution with an idempotency key.

Martini capabilities used
  • APIs
  • workflows
  • authentication
  • validation
  • business rules
  • asynchronous orchestration
  • audit logging

Pattern 4: Synchronize Advanced Hunting data

When to use this pattern

Use this pattern when DeviceEvents, DeviceNetworkEvents, DeviceProcessEvents, DeviceFileEvents, or DeviceInfo data must feed a SIEM, warehouse, dashboard, or operational database.

Integration direction
Microsoft Defender for Endpoint
Martini
Splunk
Example Mapping
Microsoft Defender for Endpoint FieldCanonical FieldTarget Field
TimestampeventTimestampevent_time
DeviceIddeviceIdentifierdest_device_id
ActionTypeeventTypeevent_type
RemoteIPremoteAddressremote_ip
Martini implementation pattern

A scheduled Martini workflow submits a bounded Kusto query, handles result limits and continuation behavior, maps table-specific fields, and writes batches to Splunk or another target. It stores a time-window checkpoint with overlap and deduplicates late-arriving rows.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • data mapping
  • JSON handling
  • checkpointing
  • batch processing
  • error handling

Applications commonly integrated with Microsoft Defender for Endpoint

Microsoft Defender for Endpoint can participate in security operations, endpoint management, analytics, and remediation workflows. Martini can connect its confirmed APIs and event surfaces with the following named applications and services.

Application Scenario Direction Martini Pattern
Microsoft Sentinel Centralize Defender alerts, incidents, hunting results, and investigation context in a SIEM and automation platform. Microsoft Defender for Endpoint → Martini → Microsoft Sentinel A Martini workflow retrieves or receives supported security data, maps alerts and related machine context to Sentinel-compatible payloads, applies deduplication, and retries transient API failures.
Microsoft Intune Correlate endpoint security posture with device management, compliance, onboarding, and remediation policies. Microsoft Defender for Endpoint → Martini → Microsoft Intune Martini can orchestrate approved exchanges of device and risk information, validate identifiers and policy rules, and preserve audit details for downstream management actions.
ServiceNow Create and update ITSM incidents, vulnerability remediation tasks, and security response records. Microsoft Defender for Endpoint → Martini → ServiceNow A scheduled or notification-driven workflow maps Alert severity, status, machine context, and identifiers into ServiceNow incidents, using the Defender Alert ID as an idempotency key.
Splunk Ingest endpoint alerts, events, and Advanced Hunting results for security analytics and correlation. Microsoft Defender for Endpoint → Martini → Splunk Martini runs bounded hunting queries or retrieves API data, normalizes the JSON response, enriches records, and forwards batches while checkpointing successful time windows.
Microsoft Teams Notify security and operations teams about high-severity alerts, response actions, and remediation status. Microsoft Defender for Endpoint → Martini → Microsoft Teams Martini filters and enriches qualifying alerts, formats concise notifications, and records delivery outcomes without treating notifications as the system of record.
Azure Event Hubs Receive selected Defender endpoint event data for downstream processing, storage, or analytics. Microsoft Defender for Endpoint → Azure Event Hubs → Martini Where the required event surface is supported, Martini consumes or processes the resulting event flow, validates payloads, maps event data, and routes failures for replay.
Jira Convert Defender alerts or vulnerability findings into engineering and remediation work items. Microsoft Defender for Endpoint → Martini → Jira A Martini workflow maps severity, vulnerability identifiers, affected software, and remediation guidance into Jira issues and prevents duplicates with stable Defender identifiers.

How to build a Microsoft Defender for Endpoint integration in Martini

Objective

Establish Microsoft Entra ID OAuth 2.0 authentication with permissions appropriate to the Defender operations being called.

Instructions in Martini

  • Register or select an application in Microsoft Entra ID
  • Grant only the required Defender API permissions
  • Store client credentials and tenant configuration as Martini secrets
  • Use application permissions for unattended workflows where appropriate

Objective

Select a schedule, supported notification, streaming path, or Martini API request based on the required latency and event coverage.

Instructions in Martini

  • Use a Scheduler Trigger for incremental polling
  • Use supported notifications or streaming only for covered event types
  • Define a Martini API for approved response requests
  • Set a watermark or checkpoint strategy

Objective

Call the relevant Defender REST or Advanced Hunting interface and obtain complete results without assuming one response contains all data.

Instructions in Martini

  • Retrieve Machines, Alerts, Vulnerabilities, Recommendations, Indicators, or action status
  • Submit bounded Kusto queries for hunting data
  • Process continuation tokens or pagination
  • Retrieve authoritative resources after notifications when necessary

Objective

Coordinate enrichment, routing, approvals, asynchronous operations, and target writes in a maintainable Martini workflow.

Instructions in Martini

  • Correlate alerts with machines and evidence
  • Route high-severity or approved actions through explicit rules
  • Track asynchronous Machine action identifiers
  • Persist processing state for safe replay

Objective

Transform Defender JSON and hunting rows into canonical and target-specific models while validating sensitive security fields.

Instructions in Martini

  • Map severity, status, identifiers, and timestamps
  • Use validation rules for required machine and alert fields
  • Normalize table-specific hunting results
  • Preserve source identifiers and API-version assumptions

Objective

Create or update incidents, work items, reports, event streams, databases, or normalized APIs without producing duplicates.

Instructions in Martini

  • Use stable IDs as idempotency keys
  • Apply target-specific upsert or update logic
  • Batch large writes where supported
  • Store audit metadata for response operations

Common Microsoft Defender for Endpoint data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
MachinesRepresent onboarded endpoint devices, health, operating system, exposure, and last-seen information.Microsoft Intune, ServiceNow, Microsoft Sentinel, security dashboardsMartini retrieves Machines through REST APIs, normalizes identifiers and health fields, and uses machine IDs for correlation and idempotency.
AlertsRepresent endpoint security detections with severity, status, investigation state, evidence, and related machines.Microsoft Sentinel, ServiceNow, Jira, Microsoft TeamsMartini maps Alert severity and lifecycle state, enriches related machine context, and deduplicates by Alert ID.
Advanced hunting recordsReturn Kusto query results from DeviceInfo, DeviceEvents, DeviceNetworkEvents, DeviceProcessEvents, and DeviceFileEvents.Splunk, data warehouses, operational databases, reporting filesMartini submits bounded queries, handles result limits and checkpoints, validates schemas, and transforms rows into target-specific models.
IndicatorsRepresent file hashes, IP addresses, domains, and URLs used for detection, blocking, or alerting.Security operations platforms, approval systems, audit storesMartini validates indicator type and permission context, maps values and actions, and tracks stable indicator identifiers.
VulnerabilitiesDescribe software vulnerabilities, severity, affected software, and remediation information associated with devices.ServiceNow, Jira, risk reporting, data warehousesMartini enriches affected-device information, maps remediation fields, and creates idempotent work items or reports.
Machine actionsTrack isolation, investigation package collection, antivirus scans, application restriction, and related response operations.ServiceNow, Microsoft Sentinel, audit databases, notification systemsMartini validates approval and permissions, invokes the action, stores the action identifier, and polls asynchronous status where required.

Authentication and security considerations

Microsoft Entra ID and OAuth 2.0

Microsoft Defender for Endpoint APIs use Microsoft Entra ID OAuth 2.0 bearer tokens. Martini can use application permissions for unattended workflows or delegated permissions where an interactive context is required.

Least privilege

Permissions are operation-specific. Reading alerts does not automatically authorize machine actions or indicator management, so applications and environments should use narrowly scoped permissions and documented administrator consent.

Security controls

  • Store tenant identifiers, client credentials, and tokens using Martini secrets.
  • Restrict Martini API access for response operations.
  • Audit requester, approver, machine, action, and outcome.
  • Minimize retention of machine, process, network, and investigation data.
  • Confirm tenant, regional endpoint, and national-cloud requirements before deployment.

Operational considerations for Microsoft Defender for Endpoint integrations

Throttling and pagination

Machines, alerts, vulnerabilities, recommendations, and hunting results may require continuation handling. Apply bounded concurrency, exponential backoff, Retry-After guidance, and checkpointed page processing.

Idempotency and asynchronous actions

Use stable identifiers such as Alert IDs, Machine IDs, indicator IDs, vulnerability identifiers, and action IDs. Machine isolation, scans, investigation packages, and similar operations may complete asynchronously, so store the operation identifier and track completion separately from request acceptance.

Hunting and schema management

Use bounded Kusto time windows, selective projections, retention-aware checkpoints, and overlap windows for delayed events. Tolerate unknown fields while explicitly validating required fields and recording API or table assumptions.

Testing and operations

  • Test permission-denied, throttling, invalid-query, not-found, and transient-service scenarios.
  • Keep alert and incident identifiers distinct when mapping to downstream systems.
  • Protect binary investigation artifacts and short-lived download results.
  • Monitor workflow failures, retry queues, checkpoint progression, and target acknowledgements.

Why use Martini instead of scripts or point-to-point integrations?

Orchestration beyond scripts

Martini separates authentication, triggering, API consumption, mapping, validation, business rules, target writes, and error handling into maintainable workflows rather than embedding all behavior in one script.

Reliable synchronization

Scheduled workflows can manage pagination, time-window checkpoints, overlap windows, deduplication, throttling, and replay. Supported notifications or streams can be combined with REST retrieval when lower latency is available.

Reusable enterprise APIs

Martini can expose a controlled API façade for normalized alert data or approved response requests, allowing downstream systems to use stable enterprise contracts while Defender-specific details remain in the integration layer.

Operational control

  • Centralize secrets and environment configuration.
  • Apply approval and authorization rules before machine actions.
  • Reuse mappings and workflow components across security integrations.
  • Monitor failures and preserve audit context for sensitive operations.

Frequently asked questions

How can Microsoft Defender for Endpoint be integrated with enterprise systems?

Microsoft Defender for Endpoint can be integrated through its REST APIs, Advanced Hunting API, Microsoft Entra ID OAuth 2.0 authentication, and selected security notification or streaming surfaces. REST APIs expose machines, alerts, indicators, vulnerabilities, recommendations, evidence, and machine actions, while Advanced Hunting provides Kusto-based analytics access.

Can Martini integrate with Microsoft Defender for Endpoint?

Yes. Martini can consume Microsoft Defender for Endpoint REST APIs, authenticate with Microsoft Entra ID OAuth 2.0, run Advanced Hunting queries, implement scheduled synchronization, process supported event or streaming interfaces, transform security data, and expose normalized APIs.

Do I need a connector to integrate Microsoft Defender for Endpoint with Martini?

No. A dedicated Microsoft Defender for Endpoint connector is not required. Martini can use the product's confirmed REST APIs, Advanced Hunting API, Microsoft Entra ID authentication, and supported notification or streaming mechanisms.

Is there any extra Lonti cost to integrate Microsoft Defender for Endpoint with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate Microsoft Defender for Endpoint. The integration is subject to the provisioned capacity of the Martini environment. Separate costs may apply from Microsoft, Azure, cloud infrastructure, or other third-party services based on subscription, usage, and deployment model.

Which Microsoft Defender for Endpoint integration methods should be used?

Use the REST APIs for operational resources and response actions, and use the Advanced Hunting API for Kusto-based analytics and event-data queries. Selected streaming or notification surfaces can support lower-latency flows, but coverage must be verified for the specific resource and event. Microsoft Defender for Endpoint GraphQL and SOAP APIs were not confirmed.

Are webhooks or events available for Microsoft Defender for Endpoint?

Selected event, streaming, and change-notification mechanisms are available through Microsoft security product surfaces, including streaming to Azure Event Hubs or Azure Storage. They are not universal webhooks for every Defender object, so scheduled polling with a watermark may be required for machines, vulnerabilities, recommendations, or uncovered hunting changes.

How should Microsoft Defender for Endpoint synchronization work?

Use supported filters, timestamps, continuation tokens, Kusto time windows, or modification fields where available. Martini can persist checkpoints, replay a small overlap window for delayed data, and deduplicate using stable identifiers such as Alert IDs, Machine IDs, indicator IDs, action IDs, and available hunting event identifiers.

How are errors, retries, and duplicate records handled?

Martini workflows can classify authentication, permission, validation, query, throttling, not-found, transient service, and asynchronous action errors. Transient failures can use bounded exponential backoff and Retry-After guidance, while stable identifiers and idempotent target writes prevent duplicates. Authorization and malformed-query errors should not be blindly retried.