Skip to main content

Overview

TheΒ Microsoft Teams integration uses an application registration in Microsoft Entra ID and authenticates with Tenant ID, Client ID, and Client Secret. Microsoft documents this as the standard application-based method for accessing Microsoft Defender APIs without a user session.

Supported Versions

Microsoft provides separate but similar app-registration guidance forΒ Microsoft Defender XDRΒ andΒ Microsoft Defender for Endpoint, both using Microsoft Entra application authentication.Β 

Authentication

AirMDR usesΒ application-based OAuth authenticationΒ through Microsoft Entra ID.

Pre-requisites

Active tenant inΒ Microsoft Entra IDAccess toΒ Microsoft Defender for EndpointΒ (or relevant Defender service with API data)

Set Up Steps

1

Register a Microsoft Entra Application

  1. Log in to your Azure Portal.
  2. Go to Microsoft Entra ID (formerly Azure AD).
  3. In the left menu, click Manage β†’ App registrations.
2

Register a New Application

  1. Click + New registration.
  2. Provide the mandatory details:
    • (ApplicationΒ Name: Enter a name for your app (e.g., airmdr-defender).
    • Supported Account Types: Select β€œAccounts in any organizational directory (Any Microsoft Entra ID tenant - Multitenant)” option).
  3. Click Register.
Redirect URI (Optional): If your app uses authentication, enter a URL (e.g., https://myapp.com/auth).
3

Retrieve the Application (Client) ID and Tenant ID

  1. After successful registration, you will see the App Overview page.
Copy Application (Client) ID – Identifies your app.
Copy Directory (Tenant) ID – Identifies your Azure AD tenant.
4

Configure API Permissions

  1. In the application Overview page left navigation pane, select Manage dropdown.
  2. Click API Permissions.
  3. Click + Add a permission
  4. Select APIs my organization uses tab.
  5. Search and select the API β€œMicrosoft Threat Protection”.
  6. Click on Application permissions.
  7. Select the required permissions:
    • To Fetch List of Incidents - Incident.Read.All
  8. Click Add permissions at the bottom of the page.
  9. Click API permissions, select Yes for Grant admin consent confirmation to allow access.
5

Create a Client Secret (For Authentication)

  1. In the application Overview page left navigation pane, select Manage dropdown.
  2. Click Certificates & secrets.
  3. Click + New client secret. MDE6 Pn
  4. Enter a description (e.g., MySecretKey) and set expiration.
  5. Click Add.
Copy and secure the Value (Client Secret) immediately – (It won’t be shown again!)
Email the Tenant ID, Client ID and the Client Secret Value to AirMDR or self Configure Microsoft Defender in AirMDR Integrations Dashboard.

Evaluate Microsoft Defender

Pre-requisites

Azure App Registration with API permissions for Microsoft Defender.
Client ID, Tenant ID, and Client Secret.
1

Obtain an Access Token

Open cURL and run the following command to check if your API Access is working:MDE uses OAuth 2.0 authentication. First, request an access token from Microsoft Entra ID (Azure AD):
Replace:
  • <tenant_id> – Your Azure Directory (Tenant) ID.
  • <client_id> – Your App Registration Client ID.
  • <client_secret> – Your App Registration Client Secret.
Expected Response (Success):
  • This verifies if the user can retrieve device information based on the assigned scope.
2

Test API Access with MDE

Once you have the access_token, use it in API calls.
  • To Get Device List
Expected Response: A JSON list of devices onboarded to Microsoft Defender.
  • To Get Alerts
Expected Response:A list of security alerts detected by Microsoft Defender.

Configure Microsoft Teams in AirMDR Integrations Dashboard

  1. Navigate to AirMDR, provide the credentials and click Login
  2. Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select Integrations.
  3. Use the search option, enter the keyword β€œMicrosoft Defender”, select the Connections tab, and click + Create button.
  4. Enter an unique name to the Instance (e.g., your org name-Microsoft Defender) to easily identify the user connection by AirMDR.
  5. Enter the generated Tenant ID, Client ID and the Client Secret in the Authentication Details field params, and click Save.

Skills provided by this Integration

To view the details of Input Parameters and Output for the respective skills

Additional Information

  • Secure service account credentials
  • Use built-in RBAC fromΒ Microsoft Defender for EndpointΒ and related Defender services.
  • Assign only the minimum required permissions usingΒ Microsoft Entra IDΒ roles.
  • Enforce:
    • Multi-Factor Authentication (MFA)
    • Device compliance checks
    • Location-based access restrictions
  • Ensure all endpoints:
    • Are onboarded toΒ Microsoft Defender for Endpoint
    • Meet compliance policies
  • Enable:
    • Attack Surface Reduction (ASR) rules
    • Endpoint Detection and Response (EDR)
  • Disable:
    • Unnecessary services and ports
  • Ensure encryption:
    • In transit β†’ TLS 1.2+
    • At rest β†’ Microsoft-managed or customer-managed keys
  • πŸ“§ Contact AirMDR Support through your designated support channel.
  • πŸ” Rotate:
    • Client secrets (recommended every 30–90 days)
    • Certificates before expiration
  • Implement automated rotation where possible
  • πŸ”„ Reconnect in AirMDR when secrets are changed.