How It Works
ContraForce continuously polls the Microsoft Defender for Endpoint security API for new incidents across all eligible customer accounts. When a new incident is detected:- The platform identifies the incident and checks it against previously processed incidents to prevent duplicates.
- A notification is queued for processing.
- ContraForce validates that the account has a deployed agent with the appropriate severity capability for the incident.
- The agent is automatically triggered on-queue to investigate and respond — just as it would for Sentinel-ingested incidents.
Prerequisites
Before Agent On-Queue for Defender for Endpoint can activate for a workspace, all of the following must be true:1
Active Subscription
The account must have an Active or Trial ContraForce subscription.
2
Defender for Endpoint Module Enabled
The Defender for Endpoint security provider must be enabled for the workspace. See Defender for Endpoint Module Deployment for setup instructions.
3
Module Consent Granted
Microsoft consent must be granted for the Defender for Endpoint module. This is the same single Consent action completed on the Modules tab when deploying the Defender module, granted by a Global Administrator.
4
Sentinel Forwarding Disabled
The workspace must not be configured to forward Defender for Endpoint incidents to Sentinel. If
FetchToSentinel is enabled, incidents are ingested through the existing Sentinel pipeline instead.5
Agent Deployed with ProcessIncident Capability
A Security Delivery Agent must be deployed via Agent Center with the ProcessIncident capability enabled for the target incident severity levels (High, Medium, Low, Informational).
What Changes for You
If you use Defender for Endpoint without Sentinel
This is the feature for you. Once the prerequisites are met, your agent will begin automatically processing Defender for Endpoint incidents within approximately 2 minutes of their creation. No configuration changes are needed on your end — the platform handles everything.If you already forward to Sentinel
Nothing changes. Your incidents continue to flow through the Sentinel ingestion pipeline as before. The Defender for Endpoint polling pipeline automatically excludes accounts with Sentinel forwarding enabled.If you use both
Accounts are evaluated individually. Workspaces with Sentinel forwarding enabled use the Sentinel pipeline. Workspaces without Sentinel forwarding use the new Defender for Endpoint polling pipeline. There is no overlap or duplicate processing.Configuring Your Agent for Defender for Endpoint Incidents
If you already have a Security Delivery Agent deployed and configured, no additional setup is required. The platform automatically detects eligible workspaces and begins polling. To deploy or configure an agent:- Select Agents in the left navigation to open the Agent Center.
- Deploy your agent following the Agent Center Deployment guide.
- Open the agent’s configuration and set Mode to On Queue for each severity the agent should handle automatically.
- Set the agent mode to On Queue.
Verifying It’s Working
After setup, confirm that the pipeline is active:- Check Agent Center — Verify your agent status shows On Queue and the mode is set to your preferred level (Manual, Automatic, or Autonomous).
- Monitor the Command Dashboard — New Defender for Endpoint incidents should appear on the Command Dashboard within approximately 2 minutes of creation in Defender.
- Review Gamebook Activity — When the agent processes an incident, you’ll see corresponding Gamebook activity in the Gamebook Activity widgets and the incident’s Workbench.
- Check Agent Execution History — Navigate to Agent Center to review the agent’s execution history and confirm incidents are being processed.
Incident Detection Timing
ContraForce polls Defender for Endpoint approximately every 2 minutes. This means:- New incidents are typically detected within 2 minutes of appearing in Defender for Endpoint.
- The agent is triggered immediately after detection and validation.
- End-to-end time from incident creation to agent response initiation is typically under 5 minutes.
Troubleshooting
If the issue persists after reviewing the above, contact support@contraforce.com or submit a support ticket with:
- Workspace name
- Agent status screenshot from Agent Center
- Approximate timestamp of the incident that was not processed
- Any error messages visible in the portal
Frequently Asked Questions
Do I need to change anything if I’m already using Sentinel? No. If your workspace forwards Defender for Endpoint incidents to Sentinel, your existing pipeline continues to work. The Defender for Endpoint polling pipeline automatically skips your account. Can I use both Sentinel and direct Defender for Endpoint ingestion for the same workspace? No. Each workspace uses one ingestion path. If Sentinel forwarding is enabled, incidents come through Sentinel. If it’s disabled, incidents come through the Defender for Endpoint polling pipeline. This prevents duplicate processing. What response actions are available for Defender for Endpoint incidents? The same Gamebook response actions available for any incident — device isolation, account disabling, password resets, IP/URL blocking, file quarantine, email deletion, and more. See the Microsoft Defender Capability Matrix for the full list based on your license. Is there any additional cost for this feature? No. Agent On-Queue for Defender for Endpoint is included with your existing ContraForce subscription and agent deployment. No additional modules or licenses are required beyond the standard Defender module and Agent Center. What happens if the polling service restarts? Polling state is persisted per account. If the service restarts, it resumes from the last known position with a configurable overlap window to ensure no incidents are missed.Related Guides
Configuring Security Delivery Agents
Set each agent’s Mode per severity and when it can run Gamebooks
Defender Native Automations
How Security Delivery Agents defer to Defender AIR, ZAP, and attack disruption
Agent Shifts
Schedule the hours when an agent picks up incidents on its own
Defender for Endpoint Module
Deploy the Defender for Endpoint module and confirm incidents sync
Questions? Contact us at support@contraforce.com.