Clariti Docs
Credentials5 minutes· easy

Microsoft Defender for Endpoint

Endpoint Protection

The Microsoft Defender for Endpoint adapter pulls machine inventory, active security alerts, and aggregated CVE vulnerability findings into Clariti for centralized endpoint protection visibility across your Microsoft-managed fleet.

What Clariti Collects

What You'll Need

  • Global Administrator or Application Administrator role in Microsoft Entra ID
  • A Microsoft 365 E5, E5 Security, or Defender for Endpoint P1/P2 license
  • ~5 minutes to complete setup
  • Your Clariti account with adapter management permissions

Get Your Credentials

If you have already set up the Microsoft Entra ID adapter, you can reuse the same app registration — just add the additional API permissions listed below and re-grant admin consent. See the Microsoft Entra ID guide for the full app registration walkthrough.

In the Azure portal, go to App registrations and select your Clariti app (or create a new one). Under API permissions > Add a permission > APIs my organization uses, search for and select WindowsDefenderATP (this is Defender for Endpoint's own API — a separate entry from Microsoft Graph). Add the following Application permissions:

  • Machine.Read.All
  • Alert.Read.All
  • Vulnerability.Read.All
  • Software.Read.All
  • Score.Read.All

Click Grant admin consent for your tenant. Then go to Certificates & secrets, create a new client secret, and copy its value. You will also need the Application (client) ID from the Overview page and the Directory (tenant) ID.

Enter Credentials in Clariti

Value from vendor consolePaste into Clariti field
Directory (tenant) IDTenant / Directory ID
Application (client) IDClient ID
Client secret valueClient Secret

Verify Connection

Click Test Connection in Clariti. A successful connection returns a green checkmark. The first data sync typically completes within a few minutes.

Troubleshooting

  • 401 Unauthorized — The client secret may have expired. Generate a new secret in Azure and update it in Clariti.
  • 403 Forbidden — Verify that admin consent was granted for all five permissions. Check in Enterprise applications > Clariti > Permissions. A tenant connected before Software.Read.All or Score.Read.All existed on this list will see software-inventory or exposure/configuration-score data skipped (with everything else unaffected) until an admin adds the missing permission and re-grants consent.
  • Timeout — Large tenants with many machines may take longer for the initial sync. Clariti retries automatically.
  • Partial vulnerability coverage on very large fleets (100+ machines) — Per-device CVE data is fetched at a throughput-bounded rate. On fleets beyond the coverage limit, Clariti prioritizes your highest-risk machines and does not fetch CVE data for the remaining, lower-risk machines that cycle — this is a standing limitation on very large fleets, not a temporary gap that resolves on a later sync.