The new Microsoft 365 Defender alerts API, currently in public preview, enables customers to work with alerts across all products within Microsoft 365 Defender using a single integration.
The API provides alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Azure Active Directory Identity Protection, and Microsoft Purview Data Loss Prevention and we will continue to expand it in the future.
We want customers to have the best possible experience across Microsoft Defender products, which is enabled through the new, central API. Therefore we will be deprecating the Microsoft Defender for Endpoint SIEM API over time, but we want to ensure organizations have ample time to plan and prepare their migration to the new Microsoft 365 Defender APIs.
You can find more information on the timeline here and additional details about the new API in this blog post.
If you are currently using the SIEM API, we recommend starting to plan for the migration. Below you will find details on the different options that are available and how to get started today.
Pulling Defender for Endpoint alerts into an external system
If you are pulling Defender for Endpoint alerts into an external system, there are various supported options to give organizations the flexibility to work with the solution of their choice.
Additional integrations are listed in Technological partners of Microsoft 365 Defender | Microsoft Learn, or reach out to your SIEM / SOAR provider to learn about integrations they may provide.
Calling the Microsoft 365 Defender alerts API directly
The below table provides a mapping between the SIEM API to the Microsoft 365 Defender alerts API:
Thanks for reading!
More information
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.