Skip to content
English
  • There are no suggestions because the search field is empty.

Microsoft Defender XDR

In this guide we go over how to integrate Defender XDR with Aftra and cover any issues you might face.

Step 1: Select the Security Provider

Navigate to the Security section within your Aftra Integrations.

  • Locate the Microsoft Defender XDR card.

  • Click the card to begin the integration process. It will show a purple checkmark once selected.

    Screenshot 2026-02-12 at 10.23.14

Step 2: Authenticate with Microsoft

You will be redirected to the Microsoft Pick an account page.

  • Select Account: Click on the corporate Microsoft account you wish to use for the integration (e.g., you@yourcompany...).

  • Log in: If you are not already signed in, enter your credentials to proceed.

    MSFT_ACCOUNT_SELECT

Step 3: Authorize Permissions

You will be presented with a Permissions requested page for the Aftra Security Scanner application.

  • Review Access: Ensure the application is requesting the necessary read access, including:

    • Read organization information

    • Read all security alerts

    • Read your organization's security events

    • Read all security incidents

    • Read all threat indicators

    • Read all Threat Intelligence Information

  • Accept: Click the blue Accept button to authorize the connection.

    Screenshot 2026-02-09 at 13.44.53

Step 4: Confirmation

Once authorized, you will be redirected back to the Aftra platform.

  • A popup window will appear confirming Integration complete.

  • The message will state: "You have successfully integrated with Microsoft Defender XDR."

  • Click Close window.

    Screenshot 2026-02-09 at 13.45.00

Step 5: Verification & Troubleshooting

After closing the window, check the status of the integration card.

  • Success: The integration should display as active.

    Screenshot 2026-02-12 at 11.02.04

  • Error State: If you see an Error tag, hover over it for details.

    A common error is "Insufficient user permissions," which indicates that the auth token does not contain valid permissions or the user does not have valid roles. Ensure your user account has the appropriate administrative privileges in Microsoft Defender before retrying.

    Screenshot 2026-02-09 at 13.45.35