Skip to main content
This guide walks you through the complete onboarding process for the ContraForce XDR module, enabling you to manage Microsoft Defender XDR incidents, run Gamebook response actions, and monitor endpoints across your managed tenants.
The XDR module is designed for environments using Microsoft Defender XDR (Defender for Endpoint, Defender for Identity, Defender for Office 365, and Defender for Cloud Apps). If you also use Microsoft Sentinel, consider the XDR + SIEM module instead.

Before You Begin

Prerequisites

Ensure you have the following before starting the onboarding process:
1

Microsoft Defender XDR

An active Microsoft Defender XDR deployment in the target tenant
2

Admin Credentials

Global Administrator access to the Microsoft tenant being onboarded
3

Onboarding Link

The ContraForce Onboarding Wizard URL (provided by the ContraForce team)
4

User List

Email addresses of users who need access to ContraForce (optional, can be added later)

Supported Licenses

The XDR module works with the following Microsoft 365 licenses:
LicenseSupportedNotes
Microsoft 365 Business PremiumFull XDR capabilities
Microsoft 365 E3Full XDR capabilities
Microsoft 365 E5Full XDR capabilities + advanced features
Standalone Defender for EndpointEndpoint features only

Capability Matrix

View detailed feature availability by license tier

Module Options

ContraForce offers two deployment modules. Choose based on your security stack:

XDR Module

Microsoft Defender XDR only
  • Defender XDR incidents
  • Endpoint management
  • Identity and email response
  • Gamebook actions
Choose this if you don’t use Microsoft Sentinel

XDR + SIEM Module

Defender XDR + Microsoft Sentinel
  • Everything in XDR module
  • Sentinel incidents
  • Advanced threat hunting
  • Data connectors
  • Custom notifications by severity
Choose this if you use Sentinel alongside Defender

Feature Comparison

FeatureXDR ModuleXDR + SIEM Module
Defender XDR Incidents
Endpoint Management
Gamebook Response Actions
Entity Insights
Sentinel Incidents
Advanced Threat Hunting
Data Connectors
Custom Severity Notifications
Not sure which module to choose? Start with XDR if you only use Defender products. You can upgrade to XDR + SIEM later if you add Sentinel.

Onboarding Process

Follow these seven steps to complete the XDR module deployment.

Step 1: Sign into the Onboarding Wizard

ContraForce Onboarding Wizard sign-in
  1. Open the Onboarding Wizard link provided by the ContraForce team
  2. Click Sign In
  3. Authenticate with a Global Administrator account from the target tenant
The account you sign in with must have Global Administrator permissions and the ability to consent enterprise applications for the organization.

The first consent step authorizes the foundational ContraForce applications.
ContraForce API consent
  1. Click Consent for the ContraForce API
  2. Review the requested permissions
  3. Click Accept to grant consent
ContraForce Portal consent
  1. Click Consent for the ContraForce Portal
  2. Review the requested permissions
  3. Click Accept to grant consent
These two applications (API and Portal) are required for all ContraForce deployments, regardless of module selection.

Step 3: Select the XDR Module

Module selection screen
  1. In the Onboarding Wizard menu, select XDR module
  2. Review the module description
  3. Click Consent Microsoft Defender XDR to proceed
If you also use Microsoft Sentinel and want SIEM capabilities, select XDR + SIEM instead.

A series of consent windows will appear for the Defender XDR integration.
Microsoft Defender XDR consent flow
1

First Consent Window

Grants read access to Defender for Endpoint data
2

Second Consent Window

Grants access to security events and incidents
3

Third Consent Window

Completes the Defender XDR integration
For each window:
  1. Review the requested permissions
  2. Click Accept to proceed
  3. Wait for the redirect to the next step
Complete all consent windows. If you close the browser or cancel mid-flow, you’ll need to restart the consent process.

Step 5: Add Users (Optional)

Add users during onboarding
During deployment, you can add users who need access to ContraForce:
  1. Search by email — Enter the user’s email address
  2. Select user — Choose from the search results (pulled from Entra ID)
  3. Assign role — Select the appropriate permission level
RoleBest For
AdminTeam leads, workspace owners
Incident ResponderSOC analysts who need response capabilities
Incident AnalystJunior analysts, read-only access
Data Source AdminIntegration specialists

User Roles Reference

View detailed permissions for each role
Adding users is optional during onboarding. You can always add more users later through Settings > User Management.

Step 6: Authorize Gamebook Service Principals

To enable Gamebook response actions, you need to consent additional service principals after the wizard completes.
Workspaces page with gear icon
  1. Go to the Workspaces page
  2. Find your newly onboarded workspace
  3. Click the gear icon to open settings
Gamebooks for Defender XDR consent
  1. Scroll to find Gamebooks for Microsoft Defender XDR
  2. Click Consent
  3. Complete the Microsoft authentication flow
  4. Click Accept on the permissions prompt
For workspaces you manage directly, click Consent only.

Additional Service Principals (Optional)

Depending on your needs, consent these additional applications:
ApplicationPurposeWhen to Consent
Gamebooks for IdentityUser response actions (disable, reset password)If managing Entra ID identities
Microsoft 365 ResponseEmail response actions (delete email)If using Defender for Office 365
Azure ResponseAzure resource response actionsIf responding to Azure-based threats

Step 7: Onboarding Complete

Onboarding complete confirmation
Congratulations! Your XDR module deployment is complete. What happens next:
  • Defender XDR incidents begin syncing to ContraForce (may take 15-30 minutes)
  • Endpoints appear on the Endpoints page
  • Gamebook actions become available for incident response
If you don’t see incidents immediately, verify that incidents exist in Microsoft Defender XDR. ContraForce only displays incidents that exist in the source system.

Post-Onboarding Checklist

After completing the wizard, verify your deployment:
1

Check Incidents

Navigate to the Command Page and verify Defender XDR incidents are appearing
2

Verify Endpoints

Go to the Endpoints page and confirm devices are listed
3

Test Gamebooks

Open an incident and verify Gamebook actions are available
4

Add Team Members

Go to Settings > User Management and add remaining users
5

Configure Notifications

Set up notification preferences for incident alerts

XDR Module Limitations

When using the XDR module (without SIEM), the following features are not available:
FeatureStatusAlternative
SIEM IncidentsNot availableUpgrade to XDR + SIEM
Sentinel Advanced Threat HuntingNot availableUpgrade to XDR + SIEM
Data Connectors pageEmptyUpgrade to XDR + SIEM
Custom severity notificationsNot availableUpgrade to XDR + SIEM

Notifications

XDR Module Notification Behavior:
  • Email notifications are not generated by ContraForce for new Defender XDR incidents
  • Email notifications are sent for Gamebook runs
  • ContraForce does not interrupt existing Defender notification configurations

Notifications Guide

Learn more about ContraForce notification options

Troubleshooting

Common Issues

IssuePossible CauseSolution
Consent failsInsufficient permissionsVerify you’re using a Global Administrator account
No incidents appearingSync in progressWait 15-30 minutes for initial sync
No incidents appearingNo incidents in DefenderVerify incidents exist in Microsoft Defender XDR portal
Endpoints page emptyMDE consent incompleteRe-consent the Microsoft Defender XDR application
Gamebooks unavailableService principal not consentedConsent Gamebooks for Microsoft Defender XDR in workspace settings
Partner consent button missingNot a partner relationshipOnly appears for partner/child workspace configurations

Getting Help

If you encounter issues during onboarding:
  1. Check consent status in workspace settings
  2. Verify admin permissions in the target tenant
  3. Review error messages for specific guidance
  4. Contact support at [email protected]

Enterprise Applications

Next Steps


Questions about XDR module onboarding? Contact us at [email protected].