Microsoft Defender XDR Integration
Defender for Office 365 Plan 2 integrates email and collaboration protection signals into Microsoft Defender XDR for cross-domain incidents, investigation, hunting, and response.
capabilitiesCurrent
Relationships
Microsoft Defender for Office 365
Source productproductMicrosoft Defender for Office 365 Plan 2
Required licenselicenseEmailEvents
Related tabletableUrlClickEvents
Related tabletableMessageEvents
Related tabletableMessagePostDeliveryEvents
Related tabletableMicrosoft Graph Security API
API accessapiLegacy Microsoft Defender XDR APIs
API accessapi
Source productproductMicrosoft Defender for Office 365 Plan 2
Required licenselicenseEmailEvents
Related tabletableUrlClickEvents
Related tabletableMessageEvents
Related tabletableMessagePostDeliveryEvents
Related tabletableMicrosoft Graph Security API
API accessapiLegacy Microsoft Defender XDR APIs
API accessapi
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Supported | Reference |
| REST API | Supported | Reference |
| Graph | Supported | Reference |
| ARM | Gap | No ARM resource is recorded for this capability. |
| Bicep | Gap | No Bicep resource is recorded for this capability. |
| Terraform | Gap | Defender XDR integration is service-side capability wiring, not an ARM/Terraform resource. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |