This article explains how to configure the Device Management integration for Microsoft Defender.
To enhance device intelligence, you can integrate Microsoft Defender device metadata with Cato’s device discovery for the IoT/OT Security service. Metadata from both platforms is merged, creating unified device profiles that enhance visibility and classification.
The combined view appears on the Home > Devices > Inventory tab and helps improve identification of both managed and unmanaged assets. With more accurate and complete device data, you can make better-informed security decisions across your network. For more information on Device Inventory, see What is Device Inventory?.
This integration enhances device intelligence and does not support Device Posture checks.
To configure the Device Management integration, you need to:
- Create the Microsoft 365 Parent Connector
- Create the Microsoft Defender Connector
An IoT/OT Security license is required for this feature.
To configure the Defender integration, create an API app.
- You must have an IoT/OT License
-
You must have one of the following Microsoft licenses:
- Microsoft 365 E5 license
- Microsoft 365 E3 license with E5 Compliance add-on
- Microsoft 365 E3 license with E5 eDiscovery and Audit add-on
- Office 365 E5 license
- To add a connector, you must have editor permission for Integrations (in the Resources section). For more information, see Managing Admin Roles Using RBAC.
First, configure the MS Tenant integration as the parent connector. This connector can be used for all Microsoft integrations. If you have already created the parent connector, go to step 2.
To create the MS Tenant integration:
- From the navigation menu, select Resources > Integrations and click the Integrated Apps tab.
- Click New. The New Connector panel opens.
-
In the New Connector panel, select the MS Tenant (Configure a new MS Tenant) app.
- Enter the Connector Name.
-
Click Authorize and Save.
A new browser tab opens to the Microsoft 365 app.
- In the new browser tab, authenticate to the Microsoft 365 app:
-
Select the Microsoft account for the Microsoft 365 app.
Otherwise, there may be a Microsoft authentication error.
- Enter the password for the app and approve it.
- Accept the permissions to let Cato access the Microsoft 365 app.
-
The screen shows that you have successfully applied the permissions for the app.
You can close the browser tab and return to the Cato Management Application.
-
- The Microsoft 365 SaaS application is added to the Integrated Apps tab.
After you have set up the Microsoft 365 Parent Connector, create the Defender connector.
To create the Microsoft Defender connector:
- From the navigation menu, click Resources > Integrations.
- Click the Configured Integrations tab.
-
Click New.
The New Integration panel opens.
- Select the SaaS Application you want to add.
- Select the Microsoft Primary Tenant that was created in Step 1.
- (Optional) Add a description.
-
Click Save.
The CMA connects to the vendor.
-
Click Authorize.
A Microsoft permissions screen will appear.
- Review the requested permissions and click Accept.
- The app is visible on the Integrated Apps table with a Connected status.
0 comments
Article is closed for comments.