> ## Documentation Index
> Fetch the complete documentation index at: https://docs.rad.security/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft Defender Vulnerability Management

> Configure Microsoft Defender Vulnerability Management with RAD Security for real-time vulnerability assessment.

# Microsoft Defender Vulnerability Management Integration Setup

This guide walks you through integrating Microsoft Defender Vulnerability Management (part of Microsoft Defender for Endpoint) with RAD Security, allowing you to import vulnerability findings and correlate them with runtime container and cloud activity.

Microsoft Defender Vulnerability Management provides continuous, agent-based discovery and assessment of software vulnerabilities, security recommendations, and exposure scores across your devices.

<Note>
  This is a **Vulnerabilities** integration that imports vulnerability findings from Defender. If you want to ingest Defender alerts and incidents for endpoint detection and response instead, see the [Microsoft Defender (EDR) setup guide](/rad-security/integrations/edr/microsoft-defender-setup). You can configure both integrations side by side.
</Note>

## Prerequisites

Before you begin, ensure you have:

<Check>
  * Admin access to Azure Portal
  * An Azure Active Directory (Entra ID) application created
  * Microsoft Defender for Endpoint subscription with Vulnerability Management enabled
  * Access to RAD Security workspace with integration permissions
</Check>

<Info>
  **Azure AD Application Required:** You must have an Azure Active Directory application created before proceeding. Follow [Microsoft's guide to create an app for Defender API access](https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-create-app-webapp).
</Info>

***

## Step 1: Access App Registration

<Steps>
  <Step title="Log in to Azure Portal">
    Log in to the [Azure Portal](https://portal.azure.com) with administrative privileges
  </Step>

  <Step title="Navigate to App Registrations">
    1. Go to **Azure Active Directory**
    2. Select **App registrations**
    3. Find and select the application you created for Microsoft Defender API access
  </Step>

  <Step title="Note Application Details">
    From the application's **Overview** page, copy the following values:

    * **Application (client) ID**
    * **Directory (tenant) ID**

    Save these values securely for later configuration.
  </Step>
</Steps>

***

## Step 2: Create Client Secret

<Steps>
  <Step title="Navigate to Certificates & Secrets">
    In your application, click **Certificates & secrets** in the left navigation
  </Step>

  <Step title="Create New Secret">
    1. Click **New client secret**
    2. Add a description (e.g., "RAD Security Vulnerability Integration")
    3. Select an expiration period
    4. Click **Add**
  </Step>

  <Step title="Save Secret Value">
    **Immediately copy the Secret value** that appears

    <Warning>
      **Copy this value now!** You will not be able to see the secret value again. If you lose it, you'll need to create a new secret.
    </Warning>
  </Step>
</Steps>

***

## Step 3: Configure API Permissions

Microsoft Defender Vulnerability Management requires read access to vulnerability, software, and device data.

<Steps>
  <Step title="Navigate to API Permissions">
    In your application, click **Manage > API permissions**
  </Step>

  <Step title="Add Required Permissions">
    Click **Add a permission**, select **APIs my organization uses**, search for **WindowsDefenderATP**, and add the **Application** permissions listed below
  </Step>
</Steps>

### Required Permissions

<AccordionGroup>
  <Accordion title="WindowsDefenderATP" icon="windows">
    **API:** WindowsDefenderATP (Microsoft Defender for Endpoint)

    **Permissions (Application type):**

    * `Vulnerability.Read.All` - Read Threat and Vulnerability Management vulnerability information
    * `Software.Read.All` - Read software inventory
    * `Machine.Read.All` - Read all machine (device) information
    * `Score.Read.All` - Read threat and vulnerability exposure scores

    <Note>
      These are the read-only Vulnerability Management permissions needed to import findings, affected software, devices, and exposure scores. Grant **Application** permissions (not Delegated) for service-to-service access.
    </Note>
  </Accordion>
</AccordionGroup>

### Grant Admin Consent

<Steps>
  <Step title="Review Permissions">
    After adding the permissions, review the list to ensure all required permissions are present
  </Step>

  <Step title="Grant Consent">
    Click **Grant admin consent for \[Your Organization]**

    <Warning>
      **Admin consent is required!** The permissions will not be active until an administrator grants consent.
    </Warning>
  </Step>

  <Step title="Verify Status">
    Verify all permissions show a green checkmark in the **Status** column
  </Step>
</Steps>

***

## Step 4: Determine API Endpoint URL

Microsoft Defender for Endpoint uses different API endpoints based on your data center location.

<AccordionGroup>
  <Accordion title="Finding Your API Endpoint" icon="globe">
    Refer to [Microsoft's API endpoint documentation](https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-list) to find the correct endpoint for your region.

    **Common Endpoints:**

    | Region          | API Endpoint                                   |
    | --------------- | ---------------------------------------------- |
    | United States   | `https://api.securitycenter.microsoft.com`     |
    | United States 2 | `https://api-us2.securitycenter.microsoft.com` |
    | United States 3 | `https://api-us3.securitycenter.microsoft.com` |
    | Europe          | `https://api-eu.securitycenter.microsoft.com`  |
    | United Kingdom  | `https://api-uk.securitycenter.microsoft.com`  |
    | Australia       | `https://api-au.securitycenter.microsoft.com`  |
    | US GCC          | `https://api-gcc.securitycenter.microsoft.us`  |
    | US GCC High     | `https://api-gov.securitycenter.microsoft.us`  |

    <Note>
      Use the base endpoint URL **without** the `/api/` path. For example: `https://api-us3.securitycenter.microsoft.com`
    </Note>
  </Accordion>
</AccordionGroup>

***

## Step 5: Configure in RAD Security

Navigate to your RAD Security workspace and configure the Microsoft Defender Vulnerability Management integration with the following parameters:

### Required Parameters

| Parameter         | Description                                         | Example                                        |
| ----------------- | --------------------------------------------------- | ---------------------------------------------- |
| **Base URL**      | Base endpoint URL for your region (without `/api/`) | `https://api-us3.securitycenter.microsoft.com` |
| **Client Id**     | Application (client) ID from Step 1                 | `11111111-1111-1111-1111-111111111111`         |
| **Client Secret** | Client secret value from Step 2                     | `your-secret-value-here`                       |
| **Tenant ID**     | Directory (tenant) ID from Step 1                   | `00000000-0000-0000-0000-000000000000`         |

<Warning>
  **Important:** The URL must be the base endpoint without the `/api/` path. Incorrect: `https://api.securitycenter.microsoft.com/api/` - Correct: `https://api.securitycenter.microsoft.com`
</Warning>

***

## Verify Integration

After completing the setup, verify your integration is working:

1. Navigate to **Data Sources > Integrations > Vulnerabilities** in RAD Security
2. Locate your Microsoft Defender Vulnerability Management integration
3. Check the connection status shows as **Connected**
4. Verify vulnerability data is being synced

<Check>
  Your Microsoft Defender Vulnerability Management integration is now configured! RAD Security can now import vulnerability findings and correlate them with runtime security events.
</Check>

## What Data is Synced

Once configured, RAD Security will sync the following data from Microsoft Defender Vulnerability Management:

<AccordionGroup>
  <Accordion title="Vulnerability Findings" icon="bug">
    * CVE identifiers
    * Vulnerability severity scores
    * CVSS scores and vectors
    * Affected software and versions
    * Exploit availability information
  </Accordion>

  <Accordion title="Device & Asset Information" icon="server">
    * Device (machine) inventory
    * Operating system details
    * Installed software inventory
    * Asset metadata and onboarding status
  </Accordion>

  <Accordion title="Risk Context" icon="chart-line">
    * Exposure and threat scores
    * Security recommendations
    * Remediation guidance
    * Patch availability status
  </Accordion>
</AccordionGroup>

## Use Cases

<CardGroup cols={2}>
  <Card title="Runtime Exploit Detection" icon="crosshairs">
    Detect when vulnerabilities identified by Defender are actively being exploited in your environment.
  </Card>

  <Card title="Risk-Based Prioritization" icon="ranking-star">
    Prioritize vulnerabilities based on runtime exposure, active exploitation, and criticality.
  </Card>

  <Card title="Automated Response" icon="bolt">
    Trigger automated responses when high-risk vulnerabilities are detected on critical assets.
  </Card>

  <Card title="Compliance Validation" icon="clipboard-check">
    Verify vulnerability remediation efforts with runtime validation.
  </Card>
</CardGroup>

## Troubleshooting

<AccordionGroup>
  <Accordion title="Authentication Failed" icon="triangle-exclamation">
    **Possible causes:**

    * Client ID, Tenant ID, or Client Secret is incorrect
    * Client secret has expired
    * Application registration was deleted

    **Solution:**

    * Verify all credentials are copied correctly
    * Check client secret expiration date
    * Ensure the Azure AD application still exists
    * Verify Tenant ID matches your Azure directory
  </Accordion>

  <Accordion title="Insufficient Permissions" icon="shield-exclamation">
    **Possible causes:**

    * Required API permissions not granted
    * Admin consent not provided
    * Permissions added as Delegated instead of Application

    **Solution:**

    * Verify `Vulnerability.Read.All`, `Software.Read.All`, `Machine.Read.All`, and `Score.Read.All` are present
    * Ensure permissions are **Application** type, not Delegated
    * Click "Grant admin consent" if any permissions show "Not granted"
    * Wait a few minutes for permissions to propagate after granting consent
  </Accordion>

  <Accordion title="Wrong API Endpoint" icon="globe">
    **Possible causes:**

    * Using incorrect regional endpoint
    * Including `/api/` in the URL
    * Typo in the endpoint URL

    **Solution:**

    * Verify your Defender data center location
    * Check [Microsoft's endpoint documentation](https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-list)
    * Ensure URL does NOT end with `/api/`
    * Common mistake: `https://api.securitycenter.microsoft.com/api/` (wrong) vs `https://api.securitycenter.microsoft.com` (correct)
  </Accordion>

  <Accordion title="No Data Syncing" icon="database-slash">
    **Possible causes:**

    * No devices onboarded to Defender
    * Vulnerability Management not enabled
    * Initial sync still in progress
    * Regional endpoint mismatch

    **Solution:**

    * Verify devices are onboarded to Microsoft Defender for Endpoint
    * Confirm Defender Vulnerability Management is enabled for your tenant
    * Allow up to 15 minutes for initial data sync
    * Confirm you're using the correct regional API endpoint
    * Review integration logs in RAD Security for specific errors
  </Accordion>
</AccordionGroup>

## Security Best Practices

<CardGroup cols={2}>
  <Card title="Least Privilege Access" icon="shield-halved">
    Only grant the read permissions listed above. Avoid adding write or isolation permissions to this vulnerability integration.
  </Card>

  <Card title="Rotate Secrets Regularly" icon="rotate">
    Set short expiration periods for client secrets and rotate before expiry to maintain security.
  </Card>

  <Card title="Secure Credential Storage" icon="lock">
    Store client secrets in a secure vault. Never commit credentials to version control.
  </Card>

  <Card title="Separate Applications" icon="split">
    Create a dedicated application for this integration rather than reusing an existing app.
  </Card>
</CardGroup>

## Additional Resources

<CardGroup cols={2}>
  <Card title="Create Defender API App" icon="book" href="https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-create-app-webapp">
    Microsoft's guide to creating an app for Defender API access
  </Card>

  <Card title="Defender API Endpoints" icon="globe" href="https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-list">
    Complete list of regional API endpoints
  </Card>
</CardGroup>

## Next Steps

<CardGroup cols={2}>
  <Card title="Vulnerabilities Overview" icon="shield-halved" href="/rad-security/integrations/vulnerabilities/overview">
    Explore other vulnerability integration options
  </Card>

  <Card title="Runtime Security" icon="shield" href="/rad-security/integrations/runtime-security">
    Learn how RAD correlates vulnerabilities with runtime threats
  </Card>

  <Card title="Microsoft Defender (EDR)" icon="microsoft" href="/rad-security/integrations/edr/microsoft-defender-setup">
    Add Microsoft Defender for endpoint detection and response
  </Card>

  <Card title="Alerts & Incidents" icon="bell" href="/rad-security/platform/workspace">
    Configure alerts for vulnerability-related events
  </Card>
</CardGroup>
