Free on Microsoft Marketplace

Stop Threats Faster with Free Security Dashboards for Microsoft Defender

7 pre-built Power BI dashboards connecting live to your Defender for Endpoint tenant vulnerability priorities, patch gaps, device risk, and board-ready Secure Score reporting. Live in minutes. No data storage.

Get It Free on Marketplace
  • Free up to 100 devices
  • Live in under 15 min
  • Built on Power BI
  • Enterprise at $2,999/year
head img 1
SOC Teams
Real-time incident and vulnerability triage
IT Security
Device health, patch gaps & compliance
CISOs and Security Leaders+
Secure Score and board-ready reporting
Enterprises
Running Microsoft Defender for Endpoint
7 Specialist Dashboards

Every Security Blind Spot. Covered.

Microsoft Defender generates powerful telemetry but its native reporting buries the signals that drive fast remediation. Each dashboard closes a specific gap. Click Watch Demo on any card to see it in action.

DASHBOARD 01

icon
Summary · All Personas

Protection Insights

Reduce post-launch rework by validating assumptions early. User interviews, competitive analysis, and journey mapping that ground your app in real user needs.

  • Incidents and alerts by severity, category, and risk level
  • Vulnerability Risk Matrix across devices, software and configs
  • Real-time Exposure and Secure Configuration Scores
  • Patch and configuration gaps ranked by exploitability

DASHBOARD 02

icon
SOC Teams

Incidents and Alerts

Real-time security command center. Every alert ranked by severity and status drill into affected devices and attack origins before threats escalate.

  • Live incident and alert monitoring by severity and status
  • Risk-based prioritization focus on what matters most
  • Device & threat correlation: pinpoint affected assets
  • Trend analysis for long-term cyber resilience

DASHBOARD 03

icon
IT Ops · SOC

Device Health

Complete endpoint visibility: active, inactive, unmanaged, and shadow IT assets all mapped with exposure levels, OS compliance, and risk rankings.

  • Active, inactive & unmanaged device mapping
  • Risk & exposure levels ranked by threat intelligence
  • OS version, patch status & onboarding completeness
  • Shadow IT detection & corporate vs. unauthorized devices

DASHBOARD 04

icon
Compliance · IT Ops

Software and Compliance

Full software inventory with unpatched and End of Support applications flagged automatically. Public exploit tracking so you know which gaps attackers are actively targeting.

  • Full inventory: vendor, version & category detail
  • Unpatched & EOS software automatically flagged
  • Public exploit tracking: know what attackers target
  • Device-level impact analysis per software gap

DASHBOARD 05

icon
SOC Teams

Vulnerability Risk

Exploitable vs. non-exploitable CVE classification with device-level impact mapping and time-to-remediation tracking. Fix what matters, backed by threat intelligence.

  • Exploitable vs. non-exploitable CVE classification
  • Vulnerability trend analysis over time
  • Severity & business impact prioritization
  • Days-since-first/last-detection tracking

DASHBOARD 06

icon
IT Ops · SOC

Patch Gaps

Always-current view of missing security updates ranked by severity and exploitability. Vendor-backed recommendations with device-level impact close gaps before attackers find them.

  • Missing updates: exploited vs. non- exploited classification
  • Vendor-backed remediation recommendations
  • Device-level impact: exactly which endpoints at risk
  • Patch urgency: severity + business impact in one view

DASHBOARD 07

icon
CISOs · Security Directors · Board Reporting

Secure Score Control

Stop reporting a number. Show the board exactly what you’re doing about it and what each action costs. Purpose-built for CISO briefings and board security presentations.

  • Prioritized control actions ranked by score impact
  • Implementation cost per control: Low / Moderate / High / Unknown
  • User impact evaluation deploy with minimal disruption
  • Score tracking: Max Score, Rank, Tier & Score %
  • Service-based control breakdown by security domain

Ideal for monthly CISO briefings, board security updates, and cyber insurance evidence packages.

  • Prioritized control actions ranked by score impact
  • Implementation cost per control: Low / Moderate / High / Unknown
  • User impact evaluation deploy with minimal disruption
  • Score tracking: Max Score, Rank, Tier & Score %
  • Service-based control breakdown by security domain
Trusted By Security Teams

Proving Value in Real Environments

Security and IT teams use Defender Analytics to close the gap between raw Defender telemetry and actionable intelligence at zero cost.

2000+

Active Installations

7

Dashboard Modules

100+

Security Data Fields

FREE

No Licensing Cost

Using Defender Analytics? Help others find it leave a rating on Microsoft AppSource →

Setup Process

Up and Running in Three Steps

No data warehouse. No custom ETL pipeline. No weeks of configuration. Connect your Microsoft Defender for Endpoint tenant and your first dashboard is live in minutes.

View Full Setup Guide →
01

Install from Marketplace

Click “Get it now” on Microsoft Marketplace. Defender Analytics installs directly into your Power BI tenant no on-premises infrastructure required.

02

Architecture and Wireframing

Create an Azure App Registration, enter your Client ID, Secret, and Tenant ID in Power BI parameters. Grant admin consent for API permissions. Takes under 15 minutes.

03

Explore and Act

All 7 dashboards populate immediately from your live Defender data. Drill into CVEs, patch gaps, and device risk share Secure Score reports with leadership.

Always-current, live-connected data no intermediate storage

Defender Analytics reads directly from Microsoft’s Defender for Endpoint APIs. Every dashboard refresh reflects the live state of your environment as of that moment. Your security data never passes through or is stored by Brickclay it stays exclusively within your Microsoft Azure tenancy, exactly as your security policy requires.

Why Defender Analytics

Built for Microsoft Defender. Designed for Security Teams.

Everything native Defender reporting doesn’t show you in a free Power BI layer that connects in minutes.

Completely Free

No licensing cost beyond your existing Power BI subscription. Available on Microsoft Marketplace with a single click no procurement conversation required.

Live in Under 15 Minutes

7 pre-built dashboards appear immediately after connecting your Defender tenant. No blank-canvas setup, no engineering sprint, no IT project.

100+ Security Fields

A richer data model than any native Defender report 100+ fields from the Defender for Endpoint API, surfacing signals the built-in portal leaves buried.

Built for Two Buyers

Drill-through CVE & device-level analysis for SOC teams. Board-ready Secure Score Control reporting for CISOs. One product for your entire security hierarchy.

Real-Time Auto-Updates

No licensing cost beyond your existing Power BI subscription. Available on Microsoft Marketplace with a single click no procurement conversation required.

Fully Customizable

Built on standard Power BI extend, filter, or combine dashboards with other data sources using tools your team already knows. No proprietary lock-in.

Zero Data Exposure

Your security data never leaves your Microsoft environment. Defender Analytics reads from your Azure tenant Brickclay does not collect, store, or transmit your data.

Dedicated Support Team

Our team responds within 2 business days for setup assistance, customization guidance, and technical questions a real person who knows the product.

Capability Comparison

What Native Defender Reporting Doesn’t Show You

Defender for Endpoint’s built-in reporting covers the fundamentals. Defender Analytics surfaces everything else for free.

Capability Defender Analytics Native Defender Reporting
Exploitable Vs. Non-exploitable Cve Classification
Device-level Vulnerability Mapping with Drill-through
Time-to-remediation Tracking Per Vulnerability
Secure Score Control Actions with Cost & User Impact
Shadow It and Unmanaged Device Detection Limited
Software Eos and Public Exploit Tracking Limited
Patch Gaps Ranked by Severity + Exploitability
Board-ready Consolidated Security Reporting
Customizable Dashboards & Branded Reports
100+ Security Data Fields in One Model
Cost to Add Free Already included
Enterprise Unlimited Devices + Dedicated Account Manager $2,999/year Not available
Simple, Transparent Pricing

Two Tiers. No Surprises.

Start free for up to 100 devices — all 7 dashboards, no credit card required. When you’re ready for unlimited scale, a dedicated account manager, and full enterprise reporting, upgrade to Enterprise at $2,999/year.

Community free up to 100 devices. Enterprise at $2,999/year.
No hidden tiers, no per-device fees, no surprise cliffs. Community gives your team all 7 dashboards free. Enterprise adds unlimited devices, a dedicated account manager, and full enterprise reporting all in one flat annual subscription.
✓ Flat annual price
Community

Free

Up to 100 devices

No credit card · No time limit

Contact Sales
  • All 7 security dashboards
  • Up to 100 devices
  • Unlimited internal users
  • 100+ Defender security fields
  • Real-time data refresh (up to 8×/day)
  • CISO & board reporting dashboard
  • Fully customisable in Power BI
  • Community email support (2-day response)
  • Unlimited devices
  • Dedicated account manager
  • White-label & branded report exports
Enterprise

$2,999

Billed annually · All devices included

Dedicated account manager included

Contact Sales
  • Everything in Community
  • Unlimited devices — no cap
  • Dedicated account manager
  • Priority email support — 1-business-day SLA
  • Scheduled report delivery to stakeholders
  • White-label & branded report exports
  • Executive Summary Pack
  • Single-tenant dedicated deployment
  • Custom data source integrations
  • Co-branded deployment
  • Advanced Power BI refresh scheduling
  • Priority feature requests

One plan. Every device. One flat price.

Enterprise at $2,999/year covers your entire tenant — no per-device fees, no tiered device bands, no surprise invoices as your fleet grows. You get a dedicated account manager, white-label exports, the Executive Summary Pack, custom integrations, and priority support. Your security reporting scales with you, not against you.

FAQ

The Community tier is genuinely free — all 7 dashboards, up to 100 devices, no time limit, no credit card. The only requirements are a Microsoft Defender for Endpoint subscription and Power BI Pro or Premium. Brickclay earns revenue through the Enterprise plan ($2,999/year) — not by charging for Community or imposing surprise fees.

It is a flat annual subscription — $2,999/year regardless of how many devices you manage. Whether you have 101 devices or 10,000, the price does not change. There are no per-device fees, no usage bands, and no overage charges. Your security coverage scales freely within a single tenant as your fleet grows.

Enterprise includes everything in Community plus: unlimited devices (no cap), a dedicated account manager assigned to your organisation, priority 1-business-day support SLA, scheduled report delivery to stakeholders, white-label and branded report exports, the Executive Summary Pack, single-tenant dedicated deployment, custom data source integrations, and co-branded deployment. Contact subscriptions@brickclay.com to get started.

No. Defender Analytics connects directly to your Microsoft Defender for Endpoint tenant via an Azure App Registration using read-only API permissions. All data stays within your Microsoft Azure environment — it flows from Microsoft’s APIs directly into your Power BI workspace. Brickclay does not collect, store, or access your security data at any point.

Typically under 15 minutes for someone with Azure Global Administrator access. The steps are: install from Marketplace, create an Azure App Registration, grant the 11 read-only API permissions, and enter your credentials in Power BI parameters. Our setup guide walks through every step with screenshots.

Creating the Azure App Registration requires a Global Administrator in your Azure Active Directory — but this is a one-time, 8-minute step. Once done, any Power BI workspace admin can install and configure the dashboards. We recommend forwarding our Setup Guide to your IT or Azure AD admin with the specific steps highlighted.

Power BI Pro, Power BI Premium Per User (PPU), or a Power BI Premium tenant license. Microsoft offers free 60-day trials of Power BI Pro. If you’re already using Power BI for other reporting, you likely have the required license already.

Defender Analytics displays as-of-date, live-connected security intelligence — each dashboard reflects your environment as of the most recent refresh. Because data flows directly from Microsoft’s APIs to your Power BI workspace with no intermediate storage, dashboards always show an authoritative current-state snapshot. For security operations, this is a feature: every refresh gives your SOC team and CISO accurate real-time data, not a stale export.

You control the refresh schedule — up to 8 times per day with Power BI Pro. Each refresh pulls the latest data directly from your Microsoft Defender for Endpoint tenant and updates all 7 dashboards simultaneously. The Incidents & Alerts and Device Health boards benefit most from frequent syncs. Enterprise customers can configure advanced refresh scheduling beyond the standard 8×/day limit.

Yes — all dashboards are built on standard Power BI and are fully editable. Your team can add visualizations, filter by device groups or business units, create custom summary views, and combine Defender Analytics data with other Power BI sources. Enterprise customers additionally get white-label branded report exports and the Executive Summary Pack.

Email our support team at subscriptions@brickclay.com. Community customers receive a response within 2 business days; Enterprise customers within 1 business day from their dedicated account manager. We also have a detailed Setup Guide covering every step of the Azure App Registration and Power BI configuration process.

Protection Insights is your daily security command center and executive briefing board in one. It consolidates the signals from all other dashboards — incident severity distribution, top CVEs, device exposure score, and Secure Score gaps — into one overview that tells you immediately whether your security posture improved or worsened since the last refresh. Most teams open it at the start of each day and before any leadership update. When something flags here, you drill into the relevant specialist dashboard (Incidents, Devices, Vulnerabilities, etc.) to investigate.

No — it gives you the picture, not the depth. When Protection Insights flags a cluster of high-severity incidents or a spike in exposed devices, you move to Incidents & Alerts or Device Health to investigate. Think of it as the command center and the other six as the specialist workrooms behind it. Its value is speed: one glance confirms whether your environment needs immediate attention or is operating normally.

The Defender portal shows a list. The Incidents & Alerts dashboard shows a pattern. You get severity distribution over time, device and threat correlation mapped visually, MITRE ATT&CK tactic breakdowns, and trend charts that let you spot whether your incident rate is climbing or falling week over week — context the native portal’s list view doesn’t give you. For SOC leads and security managers, this pattern view is what enables proactive decisions rather than reactive triage.

Yes — all dashboards are built on Power BI, so you can slice by any dimension in the data model: severity level, alert status, device group, assigned analyst, or date range. The Incidents & Alerts dashboard supports cross-filtering, meaning selecting a specific tactic on the MITRE ATT&CK chart automatically filters the device list and timeline to show only the affected assets and time windows. Enterprise customers can layer in custom filters tied to business unit or department structure.

Yes. The Device Health dashboard surfaces unmanaged and potentially unauthorised devices that appear in your Defender for Endpoint telemetry, categorised separately from your corporate-managed fleet. This gives your IT and security teams a clear shadow IT signal — devices connecting to your network that haven’t been through onboarding — without requiring a separate endpoint discovery tool. Each unmanaged device is shown with its risk exposure level and last seen date.

Each device is scored using Microsoft Defender for Endpoint’s own exposure and threat intelligence signals — the dashboard surfaces and organises data Defender already generates, rather than inventing its own scoring model. High-risk devices appear with their associated open vulnerabilities and patch gaps linked, so you can move from “this device is high-risk” to “here’s what to fix” in one click. OS compliance, sensor version, and onboarding status are surfaced alongside the risk ranking to give a complete endpoint health picture.

Yes. Any software in your environment that has reached its vendor End of Support date is automatically tagged in the Software & Compliance dashboard — no manual list maintenance required. You’ll see which devices it’s installed on, whether known public exploits exist for that version, and the vendor’s recommended remediation action. For organisations running legacy software, this view alone often surfaces risk that was previously invisible.

For frameworks like ISO 27001, Cyber Essentials, SOC 2, or cyber insurance audits, having a live, exportable record of your software estate — including unpatched versions, EOS software, and public exploit status — reduces audit preparation time significantly. The dashboard exports directly from Power BI, so you can generate a current-state snapshot for an auditor on demand. Enterprise customers additionally get white-label branded exports and the Executive Summary Pack, which packages this data into a board-ready format.

The dashboard classifies every CVE in your environment as exploitable or non-exploitable based on Defender for Endpoint’s threat intelligence — not just CVSS score. Within exploitable CVEs, you see severity, number of affected devices, and how long the CVE has been present in the environment. The combination of actively exploited + high severity + many devices affected + long dwell time naturally surfaces itself as the top of your remediation queue. This prevents the common mistake of patching high-CVSS theoretical risks while ignoring lower-scored CVEs that are actively being weaponised.

Yes — the dashboard tracks days since first detection and days since last detection for each CVE. Across successive refreshes, this lets you observe whether your remediation velocity is improving, and identify CVEs with unusually long dwell times that may have been overlooked. Enterprise customers use this data to build mean-time-to-remediate evidence for cyber insurance requirements and to demonstrate programme maturity in audit and board reporting contexts.

Native Defender reporting tells you updates are missing. The Patch Gaps dashboard tells you which ones matter most and why. Missing updates are ranked by severity, by exploitability (whether the vulnerability has a known active exploit in the wild), by vendor remediation recommendation, and by device-level impact. This means your team can prioritise the patches that carry the highest actual risk to your organisation — not just the most recently released ones. The vendor-backed recommendation column removes the guesswork from prioritisation.

Yes — every patch gap in the dashboard has device-level drill-through. Click on a missing update and you see the complete list of affected devices, their individual exposure levels, and the vendor’s remediation recommendation for that specific gap. This makes it practical to assign remediation to the right team members — your patch operations lead, IT admin, or specific device owner — with the right context attached, rather than sending a generic “patch these” alert.

The dashboard is designed for exactly this. Instead of reporting a score number and hoping the board understands it, you can show them the prioritised list of improvement actions, the implementation cost of each (Low / Moderate / High), the expected user impact, and your current rank and tier. This frames security investment as a business decision — “these three actions move our score by X points at low cost and minimal disruption” — rather than a technical metric that the board has no reference point to evaluate. Export directly from Power BI for a clean, shareable briefing document.

Yes — each control action shows its maximum score contribution alongside its implementation cost category and user impact assessment. This lets your security team model which actions deliver the highest score improvement for the lowest disruption or cost, and present that prioritised roadmap to leadership with confidence. It also enables you to sequence the roadmap strategically: quick wins first to demonstrate momentum, then higher-cost controls aligned to budget cycles. Enterprise customers use this view to build quarterly security improvement plans tied directly to their Secure Score trajectory.

Get Started Today

Free up to 100 Devices. Enterprise at $2,999/year.

Community is free — all 7 dashboards, up to 100 devices, no credit card. When you need unlimited scale and a dedicated account manager, Enterprise is $2,999/year — one flat price, every device in your tenant included.

  • Free up to 100 devices
  • Live in under 15 min
  • Built on Power BI
  • Enterprise at $2,999/year
Get Started Today CTA Illustration
cross black cross white