The Defender module is designed for environments using Microsoft Defender for Endpoint (Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps). If you also use Microsoft Sentinel, consider the XDR + SIEM module instead.
Before You Begin
Prerequisites
Ensure you have the following before starting deployment:Microsoft Defender for Endpoint
An active Microsoft Defender for Endpoint deployment in the target tenant
Admin Credentials
Global Administrator access to the Microsoft tenant being onboarded — required to grant admin consent for ContraForce enterprise applications. Cloud Application Administrator and Application Administrator cannot grant consent for Microsoft Graph application permissions.
Portal Access
Access to portal.contraforce.com, plus your workspace invite link if you are a customer admin onboarding an invited workspace
Supported Licenses
The Defender module works with the following Microsoft 365 licenses:| License | Supported | Notes |
|---|---|---|
| Microsoft 365 Business Premium | ✓ | Full XDR capabilities |
| Microsoft 365 E3 | ✓ | Full XDR capabilities |
| Microsoft 365 E5 | ✓ | Full XDR capabilities + advanced features |
| Standalone Defender for Endpoint | ✓ | Endpoint features only |
Capability Matrix
View detailed feature availability by license tier
Module Options
ContraForce offers two deployment modules. Choose based on your security stack:Defender Module
Microsoft Defender for Endpoint only
- Defender for Endpoint incidents
- Endpoint management
- Identity and email response
- Gamebook actions
XDR + SIEM Module
Defender for Endpoint + Microsoft Sentinel
- Everything in Defender module
- Sentinel incidents
- Advanced threat hunting
- Data connectors
- Custom notifications by severity
Feature Comparison
| Feature | Defender Module | XDR + SIEM Module |
|---|---|---|
| Defender for Endpoint Incidents | ✓ | ✓ |
| Endpoint Management | ✓ | ✓ |
| Gamebook Response Actions | ✓ | ✓ |
| Entity Insights | ✓ | ✓ |
| Sentinel Incidents | — | ✓ |
| Advanced Threat Hunting | — | ✓ |
| Data Connectors | — | ✓ |
| Custom Severity Notifications | — | ✓ |
Deployment Process
You deploy the Defender module directly in the ContraForce portal — there is no separate setup tool to launch. Sign in, grant the core ContraForce app consents, then enable and consent the Defender module from your workspace’s Modules tab.Step 1: Sign In and Grant Core App Consents
Open the portal
Open portal.contraforce.com. If you were invited to a workspace, open your invite link instead — it routes you to the portal sign-in.
Consent ContraForce API
The first time anyone from your tenant signs in, a Microsoft consent prompt appears for ContraForce API. Review the requested permissions and click Accept.
ContraForce API and ContraForce Portal are consented as two separate Microsoft prompts. Both are required for all ContraForce deployments, regardless of module selection.
Step 2: Open the Modules Tab
After the core app consents complete, open the workspace you are onboarding and go to its Modules tab. This is where you enable and consent each module for the workspace.Step 3: Consent the Microsoft Defender for Endpoint Module
On the Modules tab, enable and consent the Microsoft Defender for Endpoint module.Consent is granted per module on the Modules tab with a single Consent action. The single Consent authorizes ContraForce to operate the module for the workspace.
Step 4: Consent Response (Gamebook) Modules
To enable Gamebook response actions, consent the response modules you need — each with a single Consent on the Modules tab.Gamebooks for Microsoft Defender for Endpoint
Consent this module to enable endpoint response actions (isolate, scan, offboard).
| Module | Purpose | When to Consent |
|---|---|---|
| Gamebooks for Identity | User response actions (disable, reset password) | If managing Microsoft Entra ID identities |
| Microsoft 365 Response | Email response actions (delete email) | If using Defender for Office 365 |
| Azure Response | Azure resource response actions | If responding to Azure-based threats |
Step 5: Confirm the Workspace Is Live
There is no completion screen. Your workspace is onboarded when its status light turns green on its card in the Workspace Center.Check the status light
Open the Workspace Center and find your workspace card. A green status light means the workspace is live. A blue light means it is pre-onboarded and still awaiting consent; amber means a module or agent is still missing.
Verify incidents
Defender for Endpoint incidents begin syncing to ContraForce (this may take 15-30 minutes). Open the Command page to confirm incidents are appearing.
Adding Users
Adding users is not part of module deployment. Once your workspace is live, invite your team from the organization settings.Invite people
Go to Settings → User Management and open the Invite people to the organization dialog to add users and assign roles.
| Role | Best For |
|---|---|
| Admin | Team leads, workspace owners |
| Incident Responder | SOC analysts who need response capabilities |
| Incident Analyst | Junior analysts, read-only access |
| Data Source Admin | Integration specialists |
User Roles Reference
View detailed permissions for each role
Defender Module Limitations
When using the Defender module (without SIEM), the following features are not available:| Feature | Status | Alternative |
|---|---|---|
| SIEM Incidents | Not available | Upgrade to XDR + SIEM |
| Sentinel Advanced Threat Hunting | Not available | Upgrade to XDR + SIEM |
| Data Connectors page | Empty | Upgrade to XDR + SIEM |
| Custom severity notifications | Not available | Upgrade to XDR + SIEM |
Notifications
Defender Module Notification Behavior:
- Email notifications are not generated by ContraForce for new Defender for Endpoint incidents
- Email notifications are sent for Gamebook runs
- ContraForce does not interrupt existing Defender notification configurations
Notifications Guide
Learn more about ContraForce notification options
Troubleshooting
Common Issues
| Issue | Possible Cause | Solution |
|---|---|---|
| Consent fails | Insufficient permissions | Verify you’re using a Global Administrator account. Cloud Application Administrator and Application Administrator cannot grant consent for Microsoft Graph application permissions |
| Consent window doesn’t open | Pop-up blocker | Disable the pop-up blocker for portal.contraforce.com and click Consent again |
| No incidents appearing | Sync in progress | Wait 15-30 minutes for initial sync |
| No incidents appearing | No incidents in Defender | Verify incidents exist in the Microsoft Defender for Endpoint portal |
| No MDE device data | MDE consent incomplete | Re-consent the Microsoft Defender for Endpoint module on the Modules tab |
| Gamebooks unavailable | Module not consented | Consent Gamebooks for Microsoft Defender for Endpoint on the Modules tab |
| Status light not green | Module or agent still missing | Confirm every required module shows consented on the Modules tab |
Getting Help
If you encounter issues during deployment:- Check consent status on the workspace Modules tab
- Verify admin permissions in the target tenant
- Review error messages for specific guidance
- Contact support at support@contraforce.com
Related Documentation
Enterprise Applications
Enterprise Applications Overview
Overview of all ContraForce service principals
Microsoft Defender for Endpoint Application
Detailed permissions reference
Gamebooks for Defender for Endpoint
Endpoint response permissions
Portal Application
Core portal permissions
Next Steps
Incident Management Guide
Learn the incident workflow
Gamebooks
Start using response actions
User Management
Add and manage users
Command Dashboard
Navigate your dashboard
Questions about Defender module deployment? Contact us at support@contraforce.com.