← Connector Catalog

Microsoft Defender

Native

Security · Microsoft · Website ↗

Query security alerts and incidents from Microsoft Defender for Endpoint and Microsoft Sentinel via the Graph Security API using your Azure AD credentials.

2 tools your agents can use

defender_list_alerts

List security alerts from Microsoft Defender / Sentinel via the Graph Security API. Returns alert title, severity, status, category, affected host, and created time. Always use thi...

defender_get_alert

Retrieve full details of a specific Microsoft Defender / Sentinel security alert by its ID, including description, recommended actions, affected hosts, and user states.

Governed by default

Like every connector, Microsoft Defender runs inside the ApiSpi governance layer: admins can set it to full, read-only, or approval-required access, every call is audit-logged and firewall-screened, and spend caps apply.

Put Microsoft Defender to Work

Connect it in minutes and let your agents act — inside guardrails you control.