Integrate Device Security with Microsoft Defender XDR
Focus
Focus
Device Security

Integrate Device Security with Microsoft Defender XDR

Table of Contents

Integrate Device Security with Microsoft Defender XDR

Integrate Device Security through Cortex XSOAR with Microsoft Defender XDR.
Where Can I Use This?What Do I Need?
  • Device Security (Managed by Strata Cloud Manager)
  • (Legacy) IoT Security (Standalone portal)
One of the following subscriptions:
  • Device Security subscription for an advanced Device Security product (Enterprise Plus, Industrial OT, or Medical)
  • Device Security X subscription
One of the following Cortex XSOAR setups:
  • A free, cohosted, limited-featured Cortex XSOAR instance
  • A full-featured Cortex XSOAR server
Device Security integrates with Microsoft Defender XDR through Cortex XSOAR to learn about devices and device attributes, as well as vulnerabilities for IoT devices. Microsoft Defender XDR, an extended detection and response solution, lets users monitor endpoints, user identities, and cloud applications, as well as manage vulnerabilities detected in their networks. By integrating with Microsoft Defender XDR, Device Security enriches the asset inventory and risk context.
Through the integration, Device Security can learn the following device attributes from Microsoft Defender XDR:
  • Device name
  • OS group
  • OS version
  • OS build
  • IP address
  • MAC address
  • EDR operational status
  • Endpoint protection status
  • AD join status
Device Security can learn the following vulnerability information from Microsoft Defender XDR:
  • CVE ID
  • CVSS score
When Device Security receives information for devices already in its inventory, it incorporates any additional information from Microsoft Defender XDR into the data it previously gathered from network traffic and behavior analysis. For devices and vulnerabilities that are not already in the Device Security inventory, Device Security creates new entries with the data that Microsoft Defender XDR provides.
Integrating with Microsoft Defender XDR requires either a full-featured Cortex XSOAR™ server or the activation of a Device Security free cohosted Cortex XSOAR instance.