Connecting Microsoft Defender for Endpoints to Strobes
Overview
The Microsoft Defender for Endpoint connector enables you to sync endpoint assets and associated security findings into Strobes, providing centralized visibility into endpoint risks.
Why Integrate Microsoft Defender for Endpoint into Strobes?
Integrating Microsoft Defender for Endpoint with Strobes helps security teams centralize endpoint security data, prioritize vulnerabilities, track remediation, and manage endpoint risks alongside the broader attack surface.
Microsoft Defender for Endpoint Connector Details
Field | Details |
|---|---|
Supported products | https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint |
Category | Vulnerability Assessment (also functions as EDR) |
Ingested asset type(s) | Endpoint |
Integration type | UNI directional (data is transferred from the Connector to the Strobes Platform in one direction) |
Supported version and type | Cloud-based (SaaS) — pulls via Microsoft Graph Security API using an Azure AD app credential (client ID/secret/tenant) |
What Data Is Imported into Strobes?
The Microsoft Defender for Endpoint connector imports the following data into Strobes:
Endpoint Assets
Devices from Microsoft Defender for Endpoint are imported into Strobes as Endpoint type assets. These represent the same machines listed in the customer's Microsoft Defender device inventory.
If the same device is also discovered through other integrations, such as the Microsoft Defender for Cloud connector or Tenable Cloud Security, Strobes identifies and deduplicates the asset to avoid creating duplicate entries.
Security Findings
When enabled during connector configuration, vulnerabilities associated with the imported endpoint devices are also brought into Strobes as security findings. These findings are linked to their respective endpoint assets for centralized tracking and remediation.
How Vulnerability Status Is Synchronized
Strobes keeps the status of vulnerabilities synchronized with Microsoft Defender for Endpoint.
- When a vulnerability is marked as fixed in Microsoft Defender, the corresponding finding in Strobes is automatically marked as Resolved.
- If the vulnerability remains active in Microsoft Defender, the finding stays New in Strobes.
- If a previously resolved vulnerability becomes active again, Strobes reopens the corresponding finding.
This ensures that vulnerability statuses in Strobes remain aligned with the latest information from Microsoft Defender for Endpoint.
Required Permissions
To configure the Microsoft Defender for Endpoint connector, the customer must provide the following details from their Microsoft Azure account:
- Tenant ID
- Client ID
- Client Secret
The following permission is mandatory for the Microsoft Defender for Endpoint connector:
- Machine.Read.All – Allows Strobes to read machine and device information from Microsoft Defender for Endpoint.
This permission must be granted to the registered application before configuring the connector.
These credentials are generated through an App Registration created in the customer's Microsoft Azure portal. The registered application enables Strobes to securely connect to and retrieve the required Microsoft Defender for Endpoint data.
Note: The Azure App Registration must have the necessary API permissions to access Microsoft Defender for Endpoint data. Ensure the required permissions are granted and admin consent is provided before configuring the connector.
Step 1: Navigate to the Connectors
In the left navigation pane, expand Connectors and click Overview. The Connectors Overview page opens, displaying all installed and available connectors organized by category.
Step 2: Search for the Connector
In the Search bar, type MS Defender for Endpoints. The MS Defender for Endpoints connector is displayed under Available Connectors.
Step 3: Open the Connector
Click Add Configuration on the MS Defender for Endpoints card. The Add Workflow panel opens with three steps listed in the left sidebar.
Step 4: Enter a Configuration Name
In the Configuration Name field, enter a unique name for the configuration. A green "Config name is available!" message confirms that the name is not already taken.
Step 5: Select MS Defender Credentials
Click the Select MS Defender Credential dropdown. If you have an existing saved credential, select it from the list. If not, click Create Credential to add one now.
Step 6: Add a New Credential (if needed)
The Add a Credential modal opens. Select Azure as the provider and fill in the following fields:
- Name (required) — Enter a label for this credential set, used for internal reference only.
- Client ID (required) — Enter the Azure application Client ID.
- Client Secret (required) — Enter the Azure application Client Secret.
- Tenant ID (required) — Enter your Microsoft Entra ID Tenant ID.
Step 7: Save the Credential
Click Add. The modal closes, and the newly created credential is automatically selected in the Configuration Details form.
Step 8: Choose a Baseline
Under Baseline, select which findings to import from CrowdStrike:
Option | What it imports |
Strict | Findings of all severity levels |
High | Critical and High severity findings only |
Step 9: Proceed to Step Two
Click Next to proceed to the next configuration step.
Step 10: Select an Agent
Click the Agents field and select the Strobes agent that will handle the connector's data. By default, Strobes Default Agent is selected.
Step 11: Add Tags (Optional)
Click the Tags field and enter any tags you want to apply to the assets and findings imported by this connector. Tags help with filtering and scoping data within Strobes. Leave this field empty if no tags are needed.
Step 12: Set Sync Frequency
Under How frequently do you want to run a sync?, select the desired recurring sync schedule for importing findings from Tenable CS into Strobes.
Option | Description |
Don't Schedule | Run syncs manually only |
Daily | Sync once every day |
Weekly | Sync once every week |
Monthly | Sync once every month |
Step 13: Set Merge with Strobes Assets
Under Merge with Strobes Assets, select Yes to import new assets from Microsoft Defender for Endpoints and merge duplicates with existing Strobes asset records, or select No to create separate records for all incoming assets.
Step 14: Set Merge Assets Based On
Select the fields Strobes should use to identify and match duplicate assets. The available options are Mac Address, Hostname, and IP. All three options are selected by default.
Step 15: Select the Device Type (Optional)
Under Device Type, select the device types to import from Microsoft Defender for Endpoint.
The available options include:
- Server
- Desktop
- Other
Select one or multiple device types based on the requirements. If left blank, the connector imports all available device types
Step 16: Fetch Findings(Optional)
Under Fetch Findings, select whether vulnerabilities associated with the selected endpoint assets should be imported into Strobes.
- No (Default): Imports only the selected endpoint devices as assets. No vulnerability findings are created.
- Yes: Imports the vulnerabilities identified on those devices as findings along with the endpoint assets.
Step 17: Proceed to Step Three
Click Next to proceed to the third and final configuration step.
Step 18: Configure a Notification or Tracking Channel (Optional)
This step allows you to connect notification and tracking channels to the Tenable CS connector.
Notification Channels
You can configure a notification channel to receive updates when the connector syncs data or imports new findings. The available notification channels are:
- MS Teams
- Microsoft 365 Email
- Flock Messenger
- Slack
Tracking Tools
You can also connect tracking tools to receive imported findings as tickets for further tracking and remediation. The available tracking tools are:
- ServiceNow ITSM
- JIRA
- GitHub Issues
- Azure Boards
- Bugzilla – Strobes Sync Add-on
If a notification or tracking configuration is already available in Strobes, it will appear in the respective list and can be linked to this connector. If no configuration is available, you can skip this optional step and configure it later.
Step 19: Submit the Configuration
Click Submit to save and activate the connector. Strobes will begin syncing cloud security findings from Tenable CS according to the schedule you configured.