App registrations

API Permissions

Map the permission resource names shown in Microsoft Entra app registrations to the API families in this reference.

Permission Resource Map

Portal/API permission resourceAPI recordLifecycleUse this for
WindowsDefenderATPMicrosoft Defender for Endpoint APIscurrentMicrosoft Defender for Endpoint APIs expose endpoint alerts, devices, machine actions, indicators, vulnerability management, software inventory, recommendations, scores, remediation tasks, files, users, and advanced query operations.
WindowsDefenderATPMicrosoft Defender for Endpoint Indicators APIcurrentThe Microsoft Defender for Endpoint indicators API manages custom indicators of compromise for endpoint enforcement and alerting, including batch import for custom threat intelligence ingestion into Defender for Endpoint.
Microsoft GraphMicrosoft Graph Security APIcurrentThe Microsoft Graph Security API is the unified Microsoft Graph surface for security alerts, incidents, actions, threat submissions, identity security data, and related security operations workflows across supported Microsoft security providers.
Microsoft Threat ProtectionLegacy Microsoft Defender XDR APIsretiringThe legacy Microsoft Defender XDR API surface covers Defender XDR incidents and advanced hunting endpoints under api.security.microsoft.com. Microsoft Graph Security API is the forward-looking replacement for advanced hunting integrations, and Microsoft says the older advanced hunting endpoints stop returning data on February 1, 2027.
Azure Service Management / Azure Resource Manager RBACMicrosoft Sentinel REST APIcurrentThe Microsoft Sentinel REST API manages Sentinel resources such as incidents, analytics rules, data connectors, bookmarks, and entity information.
Azure MonitorAzure Monitor Logs Ingestion APIcurrentThe Azure Monitor Logs Ingestion API sends custom JSON log records through a Data Collection Rule stream into a Log Analytics workspace used by Microsoft Sentinel.
Azure RBAC for Microsoft Sentinel workspaceMicrosoft Sentinel Threat Intelligence Upload APIcurrentThe Microsoft Sentinel threat intelligence upload API imports custom threat intelligence STIX objects, including indicators, attack patterns, threat actors, identities, and relationships, into a Sentinel workspace without requiring a data connector.

Selection Notes