Skip to main content
The Microsoft Defender for Endpoint enterprise application enables ContraForce to access Microsoft Defender for Endpoint (MDE) data. Once consented, you gain visibility into endpoints across your managed tenants and can perform response actions directly from ContraForce.
This enterprise application is required for device insights and endpoint-related Gamebook actions in ContraForce.

What This Application Enables

Endpoint Visibility

View all devices managed by Defender for Endpoint across your workspaces

Device Details

Access device information including OS, health state, and exposure level

Incident Correlation

See device-related incidents and timeline data during investigations

Response Actions

Execute endpoint Gamebooks (with additional consent)

Features Enabled

Once consented, the Microsoft Defender for Endpoint enterprise application enables the following capabilities:

Entity Insights

During incident investigation, access device-related insights:

Incident Data

The application also enables:
  • Bi-directional incident streaming from Defender for Endpoint
  • Fetching incident entities and evidence
  • Alert timelines and investigation audit trails
For full endpoint response capabilities (isolate, scan, quarantine), you’ll also need to consent the Gamebooks for Defender for Endpoint enterprise application.

Permissions

The Microsoft Defender for Endpoint enterprise application requests the following Microsoft Graph and Defender API permissions:

Required Permissions

These permissions grant read access to endpoint data across the tenant. Ensure you have proper authorization before consenting on behalf of customers.

Permission Types Explained


Prerequisites

Before consenting this enterprise application:
1

Microsoft Defender for Endpoint

MDE must be deployed and active in the target tenant
2

Appropriate Licensing

Microsoft 365 Business Premium, E3, or E5 (or standalone MDE license)
3

Admin Permissions

Cloud App Admin, Application Admin, or Global Admin role in the target tenant
4

ContraForce Workspace

The workspace must be created and the tenant onboarded

Step 1: Navigate to Workspace Modules

1

Open Workspaces

Go to the Workspaces page in ContraForce
2

Select Workspace

Find the workspace you want to configure
3

Open Modules

Click the gear icon or Modules to access workspace settings

Step 2: Add the Module

1

Click Add Module

Click the Add Module button
2

Select Microsoft Defender for Endpoint

Choose Microsoft Defender for Endpoint from the list
3

Confirm

Click Confirm to add the module to the workspace
1

Open the Module

Click on the Microsoft Defender for Endpoint module you just added
2

Review Permissions

Scroll down to see the list of permissions required
3

Click Consent

Click the Consent button to start the consent flow
4

Authenticate

Sign in with a Cloud App Admin, Application Admin, or Global Admin account from the target tenant
5

Accept Permissions

Review and accept the requested permissions
Microsoft Defender for Endpoint permission consent
The consent flow is a 3-step process. Ensure you complete all steps for the application to function correctly.

After consenting, verify the application is working:

In ContraForce

  1. Navigate to the Endpoints page
  2. Select the workspace you just configured
  3. Confirm devices are populating in the list

In Microsoft Entra ID

  1. Go to Azure Portal > Microsoft Entra ID > Enterprise Applications
  2. Search for “ContraForce” or the application name
  3. Verify the application appears with Enabled status
  4. Check Permissions to confirm grants are in place

Capability Matrix

The Microsoft Defender for Endpoint integration capabilities vary by license: *Requires Microsoft Defender for Endpoint Plan 2 add-on

Full Capabilities Matrix

View the complete Defender capability matrix including Gamebook actions

The Microsoft Defender for Endpoint application works alongside other ContraForce enterprise applications:
For a complete MXDR setup, consent all relevant enterprise applications based on the response capabilities you need.

Troubleshooting

Common Issues

In the workspace modules view, consented applications show a green checkmark or “Consented” status. If you see “Not Consented” or a warning icon, re-run the consent process. If you need to revoke consent:
  1. Go to Azure Portal > Microsoft Entra ID > Enterprise Applications
  2. Find the ContraForce Defender for Endpoint application
  3. Go to Properties and set Enabled for users to sign-in to No
  4. Or delete the application entirely
Revoking consent will disable MDE data access in ContraForce for that workspace.

Best Practices

Create a dedicated service account with Cloud App Admin or Application Admin permissions for consenting enterprise applications across customer tenants.

Enterprise Applications Overview

Overview of all ContraForce enterprise applications

Gamebooks for Defender for Endpoint

Enable endpoint response actions

Defender Capability Matrix

Full Defender feature capabilities

Questions about the Microsoft Defender for Endpoint enterprise application? Contact us at support@contraforce.com.