.png)
Microsoft Defender for Endpoint Integration Guide
Integrate Microsoft Defender for Endpoint with enterprise systems through REST APIs, Advanced Hunting, selected security event streams, and Microsoft Entra ID authentication.
Microsoft Defender for Endpoint integration options at a glance
Microsoft Defender for Endpoint provides REST APIs for machines, alerts, indicators, vulnerabilities, recommendations, evidence, and machine actions. Its Advanced Hunting API supports Kusto Query Language queries over security tables such as DeviceInfo, DeviceEvents, DeviceNetworkEvents, DeviceProcessEvents, and DeviceFileEvents. Selected streaming and notification capabilities can deliver endpoint data to Azure Event Hubs or Azure Storage, although coverage is not a universal webhook model. Microsoft Entra ID supplies OAuth 2.0 bearer-token authentication with operation-specific permissions. Martini can orchestrate scheduled or event-assisted workflows, handle pagination and checkpoints, transform JSON results, apply security rules, and expose normalized APIs for downstream systems.
Common Microsoft Defender for Endpoint integration patterns
Common Microsoft Defender for Endpoint data objects used in integrations
Authentication and security considerations
Microsoft Entra ID and OAuth 2.0
Microsoft Defender for Endpoint APIs use Microsoft Entra ID OAuth 2.0 bearer tokens. Martini can use application permissions for unattended workflows or delegated permissions where an interactive context is required.
Least privilege
Permissions are operation-specific. Reading alerts does not automatically authorize machine actions or indicator management, so applications and environments should use narrowly scoped permissions and documented administrator consent.
Security controls
- Store tenant identifiers, client credentials, and tokens using Martini secrets.
- Restrict Martini API access for response operations.
- Audit requester, approver, machine, action, and outcome.
- Minimize retention of machine, process, network, and investigation data.
- Confirm tenant, regional endpoint, and national-cloud requirements before deployment.
Operational considerations for Microsoft Defender for Endpoint integrations
Throttling and pagination
Machines, alerts, vulnerabilities, recommendations, and hunting results may require continuation handling. Apply bounded concurrency, exponential backoff, Retry-After guidance, and checkpointed page processing.
Idempotency and asynchronous actions
Use stable identifiers such as Alert IDs, Machine IDs, indicator IDs, vulnerability identifiers, and action IDs. Machine isolation, scans, investigation packages, and similar operations may complete asynchronously, so store the operation identifier and track completion separately from request acceptance.
Hunting and schema management
Use bounded Kusto time windows, selective projections, retention-aware checkpoints, and overlap windows for delayed events. Tolerate unknown fields while explicitly validating required fields and recording API or table assumptions.
Testing and operations
- Test permission-denied, throttling, invalid-query, not-found, and transient-service scenarios.
- Keep alert and incident identifiers distinct when mapping to downstream systems.
- Protect binary investigation artifacts and short-lived download results.
- Monitor workflow failures, retry queues, checkpoint progression, and target acknowledgements.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration beyond scripts
Martini separates authentication, triggering, API consumption, mapping, validation, business rules, target writes, and error handling into maintainable workflows rather than embedding all behavior in one script.
Reliable synchronization
Scheduled workflows can manage pagination, time-window checkpoints, overlap windows, deduplication, throttling, and replay. Supported notifications or streams can be combined with REST retrieval when lower latency is available.
Reusable enterprise APIs
Martini can expose a controlled API façade for normalized alert data or approved response requests, allowing downstream systems to use stable enterprise contracts while Defender-specific details remain in the integration layer.
Operational control
- Centralize secrets and environment configuration.
- Apply approval and authorization rules before machine actions.
- Reuse mappings and workflow components across security integrations.
- Monitor failures and preserve audit context for sensitive operations.