Skip to main content

Microsoft Connectors

Microsoft Azure Compute

The Azure Compute connector integrates with Microsoft Azure and synchronizes virtual machine and managed disk inventory using the Azure Resource Manager APIs (via the Azure SDK for Java). For each configured subscription it lists all virtual machines, enriches each VM with instance-view status, agent details, network-interface IP configuration, and resource metadata, and maps the result to a Host connector object. It also lists all managed disks and maps them to Cloud Resource connector objects.

Microsoft Azure Network

The Azure Network connector integrates with Microsoft Azure and synchronizes the network resources that determine a workload's internet exposure and blast radius, using the Azure Resource Manager APIs (via the Azure SDK for Java). For each configured subscription it lists network interfaces, public IP addresses, network security groups, virtual networks, virtual network peerings, route tables, load balancers, and application gateways, and maps each to a Cloud Resource connector object.

Microsoft Defender for Cloud

The Microsoft Defender for Cloud connector integrates with Microsoft Azure to synchronize cloud security posture and workload-protection data. It queries **Azure Resource Graph (ARG)** and the **Azure Resource Manager (ARM)** REST APIs to pull security alerts, security assessments (recommendations) and their metadata, vulnerability findings, and the cloud assets they apply to (resources, hosts, subscriptions, and resource groups). For identity-targeting findings it optionally enriches records with account details from **Microsoft Graph**.

Microsoft Defender for Endpoint

The Microsoft Defender for Endpoint connector integrates with the [Microsoft Defender for Endpoint (ATP) REST API](https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-list) to synchronize endpoint inventory and threat-and-vulnerability-management (TVM) data into the Brinqa platform. It retrieves onboarded machines, installed software, and software vulnerabilities, and maps them to hosts, packages, installed packages, vulnerability findings, and vulnerability definitions.