Data, AI & Analytics
Design
Development
This manual offers detailed steps for configuring Microsoft Defender Analytics, assisting security teams in effortlessly setting up insights, automating the data gathering process, and maintaining a secure and efficient analytics environment.
Setting up Azure Defender Analytics is straightforward. There is no need for on-premises infrastructure, as the app can be installed directly from Microsoft AppSource into your Power BI tenant. After installation, you have the option to explore the application with the provided sample data or request a fully functional trial license that lasts 30 days.
To carry out this step, the user must possess a Power BI Pro license, a Power BI Premium Per User license, or the Power BI tenant must have a Power BI Premium license. For individuals interested in testing Azure Defender Analytics without immediately purchasing Microsoft licenses, Microsoft provides a free trial for the Power BI Pro license through self-service sign-up. Authorization to create an App Registration in Azure AD is necessary to set up the trial.
To get started select the “Install Now” button to be directed to Microsoft App Source
Schedule a CallPlease complete the following form to receive a trial license key by email. You should receive the key within 10 min of submitting the form. If you do not see the email, please check your junk folder. Note that only one key per email domain will be generated, if you or someone else from your organization has previously requested a key contact us at yasir@brickclay.com for assistance.
Now that your Azure App Registration is ready, let’s plug those values into your Power BI workspace so it can securely pull data from Microsoft Defender for Endpoint using the Azure Microsoft Defender Analytics product.
| Field Label | What to Enter |
|---|---|
| API Key | This is provided by Brickclay. |
| Azure AD Client ID | Paste your Application (client) ID from Azure. |
| Azure AD Client Secret |
Paste the Value from the client secret you created.
|
| Azure AD Tenant ID | Paste your Directory (tenant) ID from Azure. |
Click Edit credentials
Select Authentication method as Anonymous
Set Privacy level to Organizational
Check Check Skip test connection
Click Sign In
This simple guide helps you set up a secure connection between Microsoft Defender for Endpoint and Azure Microsoft Defender Analytics using an Azure App Registration. Even if you have never done this before, just follow each step carefully.
We need to tell Azure what data this app can access.
This is like a password your app will use to connect to Microsoft services.
| API | Permission Name | Description |
|---|---|---|
| Microsoft Graph | Application.Read.All | Read all applications |
| Microsoft Graph | SecurityAlert.Read.All | Read all security alerts |
| Microsoft Graph | SecurityEvents.Read.All | Read organization’s security events |
| Microsoft Graph | SecurityIncident.Read.All | Read all security incidents |
| Microsoft Graph | User.Read.All | Read full user profiles |
| WindowsDefenderATP | Alert.Read.All | Read Defender alerts |
| WindowsDefenderATP | Machine.Read.All | Read Defender machine profiles |
| WindowsDefenderATP | Score.Read.All | Read risk/vulnerability scores |
| WindowsDefenderATP | SecurityRecommendation.Read.All | Read security recommendations |
| WindowsDefenderATP | Software.Read.All | Read installed software |
| WindowsDefenderATP | User.Read.All | Read Defender user profiles |
| WindowsDefenderATP | Vulnerability.Read.All | Read vulnerability data |
Data is synchronized from the data sources to Power BI on a schedule as described here. Most customers sync approximately 3 times per day.