Skip to main content
This matrix shows which ContraForce features are available for each supported security integration. Use it to understand what your team can do based on the tools deployed in your customer environments.
Looking for Microsoft Defender for Endpoint-specific capability details by license tier (Business Premium, E3, E5)? See the Microsoft Defender Capability Matrix.

Legend


Supported Integrations


Incident Management

Unified incident queue with cross-workspace handling, bidirectional sync, and analyst assignment.

Entity Enrichment & Triage

Contextual intelligence for users, devices, IPs, files, emails, and URLs during investigations.

User Insights

Device Insights

IP Address Insights

Email, File & URL Insights

(1) Requires Microsoft Entra ID connection.(2) Requires Defender for Endpoint — included with E5 or available as an add-on for Business Premium and E3.

Direct query access to log data for deep investigation and threat hunting.

Gamebook Response Actions

Automated response playbooks for endpoint, file, identity, and email threats.

Endpoint Actions

File Actions

User Actions

Email Actions

(1) Requires Microsoft Entra ID connection and the Gamebooks for Identity enterprise application.(2) Requires Defender for Endpoint — Sentinel gamebook actions execute through Defender for Endpoint.(3) Requires Microsoft 365 Exchange license and the Microsoft 365 Response enterprise application.

Endpoint Management

View and manage devices across your customer environments.

Content Management System (CMS)

Deploy and manage detection rules across workspaces.
CMS requires the XDR + SIEM module. Microsoft Sentinel must be connected to use CMS.

Incident Notifications

Email notifications when new incidents arrive.
Incident email notifications require the XDR + SIEM module. Email notifications for Gamebook activity are available across all modules.

Microsoft Defender Capability Matrix

XDR capabilities by Microsoft 365 license tier

Defender Module Deployment

Deploy the Defender for Endpoint module

Sentinel Module Deployment

Deploy the XDR + SIEM module

Enterprise Applications

Service principal permissions reference

Questions about capabilities or integrations? Contact us at support@contraforce.com.