Environments is a read-only view. Nothing on this tab changes a customer’s configuration, and no user or device data is stored by ContraForce. Every list is fetched live from the provider when you open the page.
When to use it
Verify an onboarding
Confirm endpoints are onboarded and licenses are in place before declaring a workspace live
Explain a blocked action
See at a glance whether a response action is unavailable because of licensing or a missing module
Spot coverage gaps
Find devices that could be onboarded to Defender but are not
Check seat usage
See how many seats of each security license are assigned
Opening the tab
1
Open the workspace
From the Workspace Center, click a workspace card to open its settings page
2
Go to Environments
Select the Environments tab
3
Open an environment
Click any row to drill into that provider’s detail view
Only providers with a configured detection module appear. If a workspace shows No environments connected, no detection module has been set up for it yet.
Microsoft
The Microsoft environment is split into two cards.Microsoft Entra ID
Three counters summarise the directory:
Below the counters are two tabs.
Licenses lists the tenant’s security-relevant subscriptions with seat usage, for example Microsoft 365 E5 — 7 of 7 assigned. Assigned seat counts come from Microsoft’s own tenant-wide totals, so they match what the Microsoft 365 admin center reports. The list is deliberately filtered to security-relevant SKUs; unrelated subscriptions are not shown.
Users lists directory accounts with their user principal name, enabled state, and whether they hold a license. Filter by Licensed or State, or search by name or user principal name.
The card also reports Product Detected for Entra ID Protection, and lists the Identity gamebook capabilities available in this workspace: invalidate existing sessions, lockout user, reset MFA, reset user password, and unlock user.
Microsoft Defender
Three counters summarise endpoint coverage:
The endpoint table lists each device with its operating system, health, onboarding state, and last seen time, and is searchable by name, OS, or status.
Underneath, the card shows Defender products detected, the state of Native automations (AIR, ZAP, and attack disruption), and the Defender gamebook capabilities available: isolate endpoint, release from isolation, scan endpoint, and quarantine file.
CrowdStrike and SentinelOne
Each shows total, active, and contained endpoint counts, a searchable endpoint table with platform, agent version, status, and last seen, and the response gamebook capabilities its connection supports.Reading capability states
Every capability row carries a state.Refreshing
Each card has a Refresh button that re-collects inventory immediately, and a Last collected timestamp beneath it. Refresh requires the Owner or Content Admin workspace role; everyone who can open the workspace settings page can read the tab.Permissions and consent
Directory inventory reads through the Microsoft Defender XDR module’s connection, so that module must be connected before the Entra ID card shows anything. If it is not, the card explains that instead of showing counters. ContraForce reads the directory with two Microsoft Graph application permissions on the Defender XDR app registration:
Both are read-only. Neither allows ContraForce to modify users, licenses, or the tenant.
Granting the directory permission
Tenants that connected Defender XDR before this permission was introduced need to reconsent the module once. Until they do, the Entra ID card shows a Microsoft Defender consent required notice in place of the counters.1
Open the notice
Go to the workspace’s Environments tab and open the Microsoft environment
2
Grant or share
In your own tenant, click Grant consent to be taken to the Microsoft consent screen.For a managed customer’s tenant, click Copy consent link instead and send it to that tenant’s administrator. A partner administrator cannot consent inside a customer’s directory.
3
Approve in Microsoft
A Global Administrator or Privileged Role Administrator reviews and approves the permissions
4
Return to the tab
You are returned to the Environments tab and the counters populate
Because these are application permissions, Microsoft shows the Defender XDR app registration’s full permission set on the consent screen rather than only the new entry. Approving does not add anything beyond what the app registration declares. The same list is shown on the module’s configuration page under Microsoft Graph.
Troubleshooting
The Entra ID card says to connect Microsoft Defender XDR
The Entra ID card says to connect Microsoft Defender XDR
Directory inventory is read through the Defender XDR connection. Connect that module on the workspace’s Modules tab, then return to Environments.
A consent notice appears even though the module is connected
A consent notice appears even though the module is connected
The module was consented before the directory permission was added. Follow the consent steps above to reconsent it once.
The consent notice is still showing right after granting consent
The consent notice is still showing right after granting consent
Click Refresh on the Entra ID card. If it persists, confirm the approval completed in Microsoft and that it was granted in the correct tenant.
You do not have access to this environment
You do not have access to this environment
Your account has no role on this workspace. A workspace owner needs to grant you access. Refreshing the page will not change this.
The endpoint table shows a sample rather than every device
The endpoint table shows a sample rather than every device
Large tenants are capped for page performance and show a note saying so. Use the search field, which queries the provider’s complete inventory.
Related
Workspace Center
Manage workspaces, modules, and per-workspace settings
Defender capability matrix
Which capabilities each Microsoft license tier unlocks
Enterprise applications
The app registrations ContraForce uses and what each one needs
Platform permissions and consent
How consent works across the platform