Microsoft Defender Vulnerability Management
Configure Microsoft Defender Vulnerability Management with RAD Security for real-time vulnerability assessment.
This guide walks you through integrating Microsoft Defender Vulnerability Management (part of Microsoft Defender for Endpoint) with RAD Security, allowing you to import vulnerability findings and correlate them with runtime container and cloud activity.
Microsoft Defender Vulnerability Management provides continuous, agent-based discovery and assessment of software vulnerabilities, security recommendations, and exposure scores across your devices.
This is a Vulnerabilities integration that imports vulnerability findings from Defender. If you want to ingest Defender alerts and incidents for endpoint detection and response instead, see the Microsoft Defender (EDR) setup guide. You can configure both integrations side by side.
Prerequisites
Before you begin, ensure you have:
- Admin access to Azure Portal
- An Azure Active Directory (Entra ID) application created
- Microsoft Defender for Endpoint subscription with Vulnerability Management enabled
- Access to RAD Security workspace with integration permissions
Azure AD Application Required: You must have an Azure Active Directory application created before proceeding. Follow Microsoft's guide to create an app for Defender API access.
Step 1: Access App Registration
Log in to Azure Portal
Log in to the Azure Portal with administrative privileges
Navigate to App Registrations
- Go to Azure Active Directory
- Select App registrations
- Find and select the application you created for Microsoft Defender API access
Note Application Details
From the application's Overview page, copy the following values:
- Application (client) ID
- Directory (tenant) ID
Save these values securely for later configuration.
Step 2: Create Client Secret
Navigate to Certificates & Secrets
In your application, click Certificates & secrets in the left navigation
Create New Secret
- Click New client secret
- Add a description (e.g., "RAD Security Vulnerability Integration")
- Select an expiration period
- Click Add
Save Secret Value
Immediately copy the Secret value that appears
Copy this value now! You will not be able to see the secret value again. If you lose it, you'll need to create a new secret.
Step 3: Configure API Permissions
Microsoft Defender Vulnerability Management requires read access to vulnerability, software, and device data.
Navigate to API Permissions
In your application, click Manage > API permissions
Add Required Permissions
Click Add a permission, select APIs my organization uses, search for WindowsDefenderATP, and add the Application permissions listed below
Required Permissions
Grant Admin Consent
Review Permissions
After adding the permissions, review the list to ensure all required permissions are present
Grant Consent
Click Grant admin consent for [Your Organization]
Admin consent is required! The permissions will not be active until an administrator grants consent.
Verify Status
Verify all permissions show a green checkmark in the Status column
Step 4: Determine API Endpoint URL
Microsoft Defender for Endpoint uses different API endpoints based on your data center location.
Step 5: Configure in RAD Security
Navigate to your RAD Security workspace and configure the Microsoft Defender Vulnerability Management integration with the following parameters:
Required Parameters
| Parameter | Description | Example |
|---|---|---|
| Base URL | Base endpoint URL for your region (without /api/) | https://api-us3.securitycenter.microsoft.com |
| Client Id | Application (client) ID from Step 1 | 11111111-1111-1111-1111-111111111111 |
| Client Secret | Client secret value from Step 2 | your-secret-value-here |
| Tenant ID | Directory (tenant) ID from Step 1 | 00000000-0000-0000-0000-000000000000 |
Important: The URL must be the base endpoint without the /api/ path. Incorrect: https://api.securitycenter.microsoft.com/api/ - Correct: https://api.securitycenter.microsoft.com
Verify Integration
After completing the setup, verify your integration is working:
- Navigate to Data Sources > Integrations > Vulnerabilities in RAD Security
- Locate your Microsoft Defender Vulnerability Management integration
- Check the connection status shows as Connected
- Verify vulnerability data is being synced
Your Microsoft Defender Vulnerability Management integration is now configured! RAD Security can now import vulnerability findings and correlate them with runtime security events.
What Data is Synced
Once configured, RAD Security will sync the following data from Microsoft Defender Vulnerability Management:
Use Cases
Runtime Exploit Detection Detect when vulnerabilities identified by Defender are actively being exploited in your environment.
Risk-Based Prioritization Prioritize vulnerabilities based on runtime exposure, active exploitation, and criticality.
Automated Response Trigger automated responses when high-risk vulnerabilities are detected on critical assets.
Compliance Validation Verify vulnerability remediation efforts with runtime validation.
Troubleshooting
Security Best Practices
Least Privilege Access Only grant the read permissions listed above. Avoid adding write or isolation permissions to this vulnerability integration.
Rotate Secrets Regularly Set short expiration periods for client secrets and rotate before expiry to maintain security.
Secure Credential Storage Store client secrets in a secure vault. Never commit credentials to version control.
Separate Applications Create a dedicated application for this integration rather than reusing an existing app.
Additional Resources
Create Defender API App
Microsoft's guide to creating an app for Defender API access
Defender API Endpoints
Complete list of regional API endpoints