This article explains the purpose of the Microsoft 365 Defender integration with SMARTFENSE and how to configure it. The integration allows SMARTFENSE to read security alerts from Microsoft 365 Defender via Microsoft Graph API, using an authenticated connection with Microsoft Entra ID.
The configuration is available at Configuration > Integrations > Microsoft 365 Defender.
Initial Setup in Microsoft Entra ID
Log in to the Microsoft Entra ID portal: https://portal.azure.com/.
In the left-hand menu, select Microsoft Entra ID.
Copy the domain name and paste it into the SMARTFENSE platform, inside the Domain field.
Application Registration
Return to the Microsoft Entra ID portal.
Select the option Manage > App registrations.
Click on New registration in the top menu.
In the Name field, enter SMARTFENSE.
Select the option Accounts in this organizational directory only (SMARTFENSE only: single tenant).
Press the Register button.
Once registration is complete, copy the value from the Application (client) ID field and paste it into the SMARTFENSE platform, inside the Application ID field.
Assigning API Permissions
In the left-hand menu, select API permissions.
Press the + Add a permission button to open the Request API permissions menu.
In the Request API permissions window, select Microsoft Graph.
-
Assign the following permission to the application:
SecurityAlert.Read.All
Click the Grant admin consent button to apply the permission.
Creating the Secret Key
In the left-hand menu, select Certificates & secrets.
Press + New client secret.
In the side window Add a client secret, enter a description and define an expiration time.
Click Add.
When the expiration date is reached, the connection will stop working. You will need to generate a new secret and verify the connection again.
Copy the Generated Value. This value is shown only once and cannot be retrieved later.
Connection with SMARTFENSE
Paste the secret key value copied in the previous step into the SMARTFENSE platform, inside the Application secret key field.
Click the Check connection button within SMARTFENSE to verify that the configuration is correct.
Ad-blocking extensions such as Ad-Block Plus can interfere with the connection test. It is recommended to disable them temporarily before running this check.
💡 Best practices
Keep a secure record of the Application ID, Domain, and Application secret key.
Confirm that the SecurityAlert.Read.All permission has been granted correctly before testing the connection.
Set up internal alerts to renew the client secret before its expiration date to avoid disruptions to the integration.
Disable any content-blocking extensions temporarily before running Check connection to prevent false errors.
Verify that the Nudges and Playbooks that depend on this integration are properly configured to process alerts received from Microsoft 365 Defender.