Skip to main content

Microsoft Connectors

Microsoft Defender for Cloud

The Microsoft Defender for Cloud connector integrates with Microsoft Azure to synchronize cloud security posture and workload-protection data. It queries **Azure Resource Graph (ARG)** and the **Azure Resource Manager (ARM)** REST APIs to pull security alerts, security assessments (recommendations) and their metadata, vulnerability sub-assessments, and the cloud assets they apply to (resources, hosts, subscriptions, and resource groups). For identity-targeting findings it optionally enriches records with account details from **Microsoft Graph**.

Microsoft Defender for Endpoint

The Microsoft Defender for Endpoint connector integrates with the [Microsoft Defender for Endpoint (ATP) REST API](https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-list) to synchronize endpoint inventory and threat-and-vulnerability-management (TVM) data into the Brinqa platform. It retrieves onboarded machines, installed software, and software vulnerabilities, and maps them to hosts, packages, installed packages, vulnerability findings, and vulnerability definitions.