For Microsoft-stack organizations, Defender for Endpoint is the malware protection layer your frameworks ask about. This integration verifies it continuously: onboarding coverage, sensor health, and AV configuration checked against your fleet, gaps routed as findings, and high-severity alerts optionally wired into the incident flow. CrowdStrike shops: see the CrowdStrike integration.
Prerequisites
- An OptiTech workspace with the Admin role.
- Global Administrator or Security Administrator in your Microsoft tenant for consent.
- Intune connected, so coverage reconciles against the managed fleet.
Connect the integration
- In the OptiTech Console, go to Integrations and select Microsoft Defender.
- Click Connect and grant admin consent for the read-only permissions (
Machine.Read.All,Alert.Read.All,SecurityConfiguration.Read.Allon the Defender API). - Choose whether to enable Incident wiring for high-severity alerts.
- Run the first sync.
Checks the integration activates
- Onboarding coverage: devices in your Intune fleet without Defender onboarding surface as coverage gaps.
- Sensor health: inactive or misconfigured sensors flag per device.
- AV configuration: real-time protection, cloud-delivered protection, and tamper protection verified against your baseline.
- Exposure visibility: Defender's exposure and secure score for endpoints recorded per sync, a useful trend line for the board report.
Alerts to incidents
With incident wiring enabled, alerts at or above your chosen severity open an incident record automatically: alert details in the timeline, severity assessment queued, and reporting clocks started if warranted. Tune the threshold so the flow receives incidents, not noise; informational alerts belong in Defender's own console.
Verify the connection
- Confirm Status: Connected and a machine count in line with the Defender portal.
- Filter Controls by Source: Defender and review the coverage reconciliation first.
- Trigger a test detection (EICAR file on a test machine) and confirm the alert appears, and, if wired, opens an incident at the configured severity.
Troubleshooting
- Machines missing: devices must be onboarded to Defender for Endpoint, not merely enrolled in Intune; the coverage check exists precisely for this gap.
- Consent errors: Defender API permissions are separate from Graph; the consent screen should list Machine and Alert scopes.
- Duplicate incidents: if you also wire CrowdStrike or a SIEM, set one source as incident-authoritative to avoid doubles.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.