Skip to main content

Microsoft Defender for Cloud

Microsoft Azure

The Microsoft Defender for Cloud connector integrates with Microsoft Azure to synchronize cloud security posture and workload-protection data. It queries Azure Resource Graph (ARG) and the Azure Resource Manager (ARM) REST APIs to pull security alerts, security assessments (recommendations) and their metadata, vulnerability sub-assessments, and the cloud assets they apply to (resources, hosts, subscriptions, and resource groups). For identity-targeting findings it optionally enriches records with account details from Microsoft Graph.

The connector maps this data into Brinqa's UDM as Alerts, Violations, Vulnerabilities, their corresponding definitions, and CloudResource/Host assets.


Data retrieved from Microsoft Defender for Cloud

Connector ObjectRequiredMaps to Data Model
Alert / Alert DefinitionYesAlert
Violation (Assessment)YesViolation
Violation Definition (AssessmentMetadata)YesViolation Definition
Vulnerability / Vulnerability Definition (SubAssessment)YesVulnerability
Cloud Resource (Asset)YesCloud Resource
HostYesHost
SubscriptionYesCloud Resource
Resource GroupYes

Model relationships

note

For detailed steps on how to view the data retrieved from Microsoft Defender for Cloud in the Brinqa Platform, see How to view your data.