Skip to main content
Loading

Microsoft Defender for Cloud

This page explains how to make data from the Microsoft Defender for Cloud integration appear in the following places within Elastic Security:

In order for Microsoft Defender for Cloud data to appear in these workflows:

  • Follow the steps to set up the Microsoft Defender for Cloud integration.
  • Make sure the integration version is at least 3.0.0.
  • Ensure you have read privileges for the following indices: security_solution-*.misconfiguration_latest, security_solution-*.vulnerability_latest.