Skip to main content
The Environments tab on a workspace’s settings page shows what ContraForce can actually see inside that customer’s tenant: which identities and licenses exist, which endpoints are onboarded, and which response actions the current connections support.
Environments is a read-only view. Nothing on this tab changes a customer’s configuration, and no user or device data is stored by ContraForce. Every list is fetched live from the provider when you open the page.

When to use it

Verify an onboarding

Confirm endpoints are onboarded and licenses are in place before declaring a workspace live

Explain a blocked action

See at a glance whether a response action is unavailable because of licensing or a missing module

Spot coverage gaps

Find devices that could be onboarded to Defender but are not

Check seat usage

See how many seats of each security license are assigned

Opening the tab

1

Open the workspace

From the Workspace Center, click a workspace card to open its settings page
2

Go to Environments

Select the Environments tab
3

Open an environment

Click any row to drill into that provider’s detail view
The landing view lists every connected environment for the workspace.
Only providers with a configured detection module appear. If a workspace shows No environments connected, no detection module has been set up for it yet.

Microsoft

The Microsoft environment is split into two cards.

Microsoft Entra ID

Three counters summarise the directory: Below the counters are two tabs. Licenses lists the tenant’s security-relevant subscriptions with seat usage, for example Microsoft 365 E5 — 7 of 7 assigned. Assigned seat counts come from Microsoft’s own tenant-wide totals, so they match what the Microsoft 365 admin center reports. The list is deliberately filtered to security-relevant SKUs; unrelated subscriptions are not shown. Users lists directory accounts with their user principal name, enabled state, and whether they hold a license. Filter by Licensed or State, or search by name or user principal name.
Search queries the complete directory, not just the rows on screen. Large tenants show a sample in the table with a note saying so, but searching still finds any matching user.
The card also reports Product Detected for Entra ID Protection, and lists the Identity gamebook capabilities available in this workspace: invalidate existing sessions, lockout user, reset MFA, reset user password, and unlock user.

Microsoft Defender

Three counters summarise endpoint coverage:
Can be onboarded is the most useful number on this tab for finding coverage gaps. These are real devices Defender already knows about that are not yet protected.
The endpoint table lists each device with its operating system, health, onboarding state, and last seen time, and is searchable by name, OS, or status. Underneath, the card shows Defender products detected, the state of Native automations (AIR, ZAP, and attack disruption), and the Defender gamebook capabilities available: isolate endpoint, release from isolation, scan endpoint, and quarantine file.

CrowdStrike and SentinelOne

Each shows total, active, and contained endpoint counts, a searchable endpoint table with platform, agent version, status, and last seen, and the response gamebook capabilities its connection supports.

Reading capability states

Every capability row carries a state.
A capability marked Not licensed cannot be enabled from ContraForce. It requires a licensing change in the customer’s Microsoft tenant.

Refreshing

Each card has a Refresh button that re-collects inventory immediately, and a Last collected timestamp beneath it. Refresh requires the Owner or Content Admin workspace role; everyone who can open the workspace settings page can read the tab.
Directory inventory reads through the Microsoft Defender XDR module’s connection, so that module must be connected before the Entra ID card shows anything. If it is not, the card explains that instead of showing counters. ContraForce reads the directory with two Microsoft Graph application permissions on the Defender XDR app registration: Both are read-only. Neither allows ContraForce to modify users, licenses, or the tenant.

Granting the directory permission

Tenants that connected Defender XDR before this permission was introduced need to reconsent the module once. Until they do, the Entra ID card shows a Microsoft Defender consent required notice in place of the counters.
1

Open the notice

Go to the workspace’s Environments tab and open the Microsoft environment
2

Grant or share

In your own tenant, click Grant consent to be taken to the Microsoft consent screen.For a managed customer’s tenant, click Copy consent link instead and send it to that tenant’s administrator. A partner administrator cannot consent inside a customer’s directory.
3

Approve in Microsoft

A Global Administrator or Privileged Role Administrator reviews and approves the permissions
4

Return to the tab

You are returned to the Environments tab and the counters populate
Consent must be granted by a Global Administrator or Privileged Role Administrator in the tenant being consented. Other roles cannot approve application permissions.
Because these are application permissions, Microsoft shows the Defender XDR app registration’s full permission set on the consent screen rather than only the new entry. Approving does not add anything beyond what the app registration declares. The same list is shown on the module’s configuration page under Microsoft Graph.

Troubleshooting

Directory inventory is read through the Defender XDR connection. Connect that module on the workspace’s Modules tab, then return to Environments.
Your account has no role on this workspace. A workspace owner needs to grant you access. Refreshing the page will not change this.
Large tenants are capped for page performance and show a note saying so. Use the search field, which queries the provider’s complete inventory.

Workspace Center

Manage workspaces, modules, and per-workspace settings

Defender capability matrix

Which capabilities each Microsoft license tier unlocks

Enterprise applications

The app registrations ContraForce uses and what each one needs

Platform permissions and consent

How consent works across the platform