Data, AI & Analytics
Design
Development
Lorem ipsum dolor sit amet consectetur adipiscing elit. Quisque faucibus ex sapien vitae pellentesque sem placerat. In id cursus mi pretium tellus duis convallis. Tempus leo eu aenean sed diam urna tempor. Pulvinar vivamus fringilla lacus nec metus bibendum egestas. Iaculis massa nisl malesuada lacinia intege.
Installing BI for Defender is quite simple. BI for Defender requires no on-premises infrastructure, the app installs from Microsoft AppSource directly into your Power BI tenant. Once installed you can try the application using the supplied sample data or you can choose to request a fully functional 30-day trial license.
To get started select the “Install Now” button to be directed to Microsoft App Source
Schedule a CallPlease complete the following form to receive a trial license key by email. You should receive the key within 10 min of submitting the form. If you do not see the email, please check your junk folder. Note that only one key per email domain will be generated, if you or someone else from your organization has previously requested a key contact us at yasir@brickclay.com for assistance.
Now that your Azure App Registration is ready, let’s plug those values into your Power BI workspace so it can securely pull data from Microsoft Defender for Endpoint using the Azure Microsoft Defender Analytics product.
Field Label | What to Enter |
---|---|
API Key | This is provided by Brickclay. |
Azure AD Client ID | Paste your Application (client) ID from Azure. |
Azure AD Client Secret |
Paste the Value from the client secret you created.
|
Azure AD Tenant ID | Paste your Directory (tenant) ID from Azure. |
Click Edit credentials
Select Authentication method as Anonymous
Set Privacy leveltoOrganizational
Check Check Skip test connection
Click Sign In
This simple guide helps you set up a secure connection between Microsoft Defender for Endpoint and Azure Microsoft Defender Analytics using an Azure App Registration. Even if you have never done this before, just follow each step carefully.
You’ve now:
This is like a password your app will use to connect to Microsoft services.
API | Permission Name | Description |
---|---|---|
Microsoft Graph | Application.Read.All | Read all applications |
Microsoft Graph | SecurityAlert.Read.All | Read all security alerts |
Microsoft Graph | SecurityEvents.Read.All | Read organization’s security events |
Microsoft Graph | SecurityIncident.Read.All | Read all security incidents |
Microsoft Graph | User.Read.All | Read full user profiles |
WindowsDefenderATP | Alert.Read.All | Read Defender alerts |
WindowsDefenderATP | Machine.Read.All | Read Defender machine profiles |
WindowsDefenderATP | Score.Read.All | Read risk/vulnerability scores |
WindowsDefenderATP | SecurityRecommendation.Read.All | Read security recommendations |
WindowsDefenderATP | Software.Read.All | Read installed software |
WindowsDefenderATP | User.Read.All | Read Defender user profiles |
WindowsDefenderATP | Vulnerability.Read.All | Read vulnerability data |
The BI for Defender dataset contains some parameters that must be configured in order to synchronize data from Defender for Endpoint to Power BI. Following the steps below to configure the dataset parameters and sync your data.
Data is synchronized from the data sources to Power BI on a schedule as described here. Most customers sync approximately 3 times per day.