What this connection does

Microsoft Defender provides the XDR signals used by EmDash for Security Detections, including alerts, incidents, analyzed-email evidence, and user-reported messages. It is a separate consent and health boundary from Microsoft 365 mailbox analysis.

Prerequisites

  • The XDR module must be entitled for the tenant.
  • A user with integrations:manage to configure or test the connection. integrations:read can view status and capabilities.
  • A Microsoft Defender or Microsoft 365 Global Administrator who can approve application consent in the correct directory.
  • The Defender tenant ID (GUID) or verified domain.
  • Review the requested permissions with your security team. Depending on enabled capabilities, the application may request SecurityAlert.Read.All, SecurityIncident.Read.All, SecurityAnalyzedMessage.Read.All, and optional read/write permissions for analyzed-message remediation or threat submission.

Configure Microsoft Defender

  1. Open Settings → Integrations and choose Microsoft Defender.
  2. Enter the Tenant ID or domain for the Defender organization. This can be the same directory as Microsoft 365, but consent is still separate.
  3. Select Generate consent link. Have an authorized Microsoft administrator review and approve the requested Defender permissions.
  4. Return to EmDash and wait for the callback. Select Test connection to run the provider health check.
  5. Review the Capabilities shown by the page. A connected integration can still report an individual capability as unavailable when a permission, licensing feature, or provider API is not enabled.
  6. Open Security Detections and confirm that the page loads the connected state before relying on alert or incident data.

Using Defender data safely

Defender alerts and incidents are presented inside the tenant boundary. Remediation controls appear only when the server reports the required capability and the signed-in user has the necessary manage permission. If Defender is disconnected, EmDash shows a safe not-connected state and does not request Graph tokens or provider data.

Permissions and data boundaries

The final permission set depends on the capabilities your tenant enables. Read permissions support signal visibility; write permissions are reserved for specific remediation or submission workflows. EmDash does not expose provider tokens, unrelated tenants, or raw provider responses in the portal.

Troubleshooting

  • Microsoft Defender is not connected: use the link to this integration page, generate consent, and test again.
  • Connected but a capability is unavailable: inspect the capability reason and confirm the corresponding Defender permission/licensing feature.
  • No alerts or incidents: confirm the tenant ID, check the last successful test, and allow time for provider synchronization.
  • Remediation is disabled: read access, XDR entitlement, or provider write permission may be missing; this is an intentional fail-closed boundary.
  • Consent or authorization failure: have the correct directory administrator repeat consent; do not paste an access token into EmDash.

See Modules and access and Roles and permissions for entitlement and role boundaries. If the provider remains unavailable, contact support with the sanitized status only.