API Permissions
Map the permission resource names shown in Microsoft Entra app registrations to the API families in this reference.
Permission Resource Map
| Portal/API permission resource | API record | Lifecycle | Use this for |
|---|---|---|---|
| WindowsDefenderATP | Microsoft Defender for Endpoint APIs | current | Microsoft Defender for Endpoint APIs expose endpoint alerts, devices, machine actions, indicators, vulnerability management, software inventory, recommendations, scores, remediation tasks, files, users, and advanced query operations. |
| WindowsDefenderATP | Microsoft Defender for Endpoint Indicators API | current | The Microsoft Defender for Endpoint indicators API manages custom indicators of compromise for endpoint enforcement and alerting, including batch import for custom threat intelligence ingestion into Defender for Endpoint. |
| Microsoft Graph | Microsoft Graph Security API | current | The Microsoft Graph Security API is the unified Microsoft Graph surface for security alerts, incidents, actions, threat submissions, identity security data, and related security operations workflows across supported Microsoft security providers. |
| Microsoft Threat Protection | Legacy Microsoft Defender XDR APIs | retiring | The legacy Microsoft Defender XDR API surface covers Defender XDR incidents and advanced hunting endpoints under api.security.microsoft.com. Microsoft Graph Security API is the forward-looking replacement for advanced hunting integrations, and Microsoft says the older advanced hunting endpoints stop returning data on February 1, 2027. |
| Azure Service Management / Azure Resource Manager RBAC | Microsoft Sentinel REST API | current | The Microsoft Sentinel REST API manages Sentinel resources such as incidents, analytics rules, data connectors, bookmarks, and entity information. |
| Azure Monitor | Azure Monitor Logs Ingestion API | current | The Azure Monitor Logs Ingestion API sends custom JSON log records through a Data Collection Rule stream into a Log Analytics workspace used by Microsoft Sentinel. |
| Azure RBAC for Microsoft Sentinel workspace | Microsoft Sentinel Threat Intelligence Upload API | current | The Microsoft Sentinel threat intelligence upload API imports custom threat intelligence STIX objects, including indicators, attack patterns, threat actors, identities, and relationships, into a Sentinel workspace without requiring a data connector. |
Selection Notes
WindowsDefenderATP
Use for Defender for Endpoint device, alert, machine action, indicator, vulnerability, software, recommendation, score, file, URL, IP, user, and older advanced query permissions.
Use for Defender for Endpoint device, alert, machine action, indicator, vulnerability, software, recommendation, score, file, URL, IP, user, and older advanced query permissions.
Microsoft Threat Protection
Use only for legacy Defender XDR API integrations that still depend on api.security.microsoft.com incident or advanced hunting paths.
Use only for legacy Defender XDR API integrations that still depend on api.security.microsoft.com incident or advanced hunting paths.
Microsoft Graph
Use for Graph Security alerts, incidents, threat submissions, identity security resources, threat intelligence, security actions, and current Graph-based hunting workflows.
Use for Graph Security alerts, incidents, threat submissions, identity security resources, threat intelligence, security actions, and current Graph-based hunting workflows.
Azure RBAC / ARM
Use Azure Resource Manager authorization and workspace/resource roles for Microsoft Sentinel REST API access, not a product-specific API permission tile.
Use Azure Resource Manager authorization and workspace/resource roles for Microsoft Sentinel REST API access, not a product-specific API permission tile.