Microsoft Defender for Endpoint
Enrich Harmony asset records with endpoint security posture, vulnerability findings, and threat alerts from Microsoft Defender
Microsoft Defender for Endpoint (MDE) is Microsoft's enterprise endpoint security platform providing threat protection, vulnerability management, and security analytics across Windows, macOS, Linux, iOS, and Android devices. Connecting MDE to Harmony enriches asset records with real-time security posture data - device health, vulnerabilities, and active threat alerts - directly within the Harmony platform.
What the Microsoft Defender for Endpoint Integration Enables
Device Security Posture
View endpoint health and protection status alongside asset records in Harmony
Vulnerability Findings
Surface vulnerability data per device to prioritize remediation workflows
Threat Alert Enrichment
Pull active alerts into Harmony to drive automated or agent-led incident response
Multi-Tenant Support
Connect multiple MDE instances for multi-tenant environments
Agent Status Monitoring
Track agent states including inactive, outdated, active threats, and scan age
MITRE-Linked Threats
View MITRE ATT&CK-mapped threats surfaced directly from MDE alerts
EDR Provider Visibility
Devices are labeled "Microsoft Defender for Endpoint" as their EDR provider in Harmony
Prerequisites
Microsoft 365 Defender Access: Account with Security Reader role or higher
MDE Subscription: Active Microsoft Defender for Endpoint Plan 1 or Plan 2
Harmony Account: Active Harmony workspace
Connect Microsoft Defender for Endpoint to Harmony
Step 1: Navigate to Integrations
Log in to your Harmony dashboard
Go to Settings > Integrations
Find Microsoft Defender for Endpoint under EDR and click Connect
Step 2: Sign in with Microsoft
You will be redirected to Microsoft to authorize the connection
Sign in with a Microsoft account that has Security Reader or higher permissions in Microsoft 365 Defender
Review the requested permissions and click Accept
Step 3: Authorize and Save
Harmony will connect to your Defender tenant
Click Save
What Harmony Syncs
From Microsoft Defender for Endpoint:
Device inventory (name, OS, platform, onboarding status)
Device health and sensor health state
Risk level and exposure level per device
Active alerts (severity, category, status, affected device)
Vulnerability findings per device
Last seen and first seen timestamps
Agent status - inactive, outdated, active threats, and scan age
MITRE ATT&CK-linked threat details surfaced from MDE alerts
EDR provider label ("Microsoft Defender for Endpoint") displayed on each connected device
Use Cases
Last updated
Was this helpful?
