Connecting the Integration
Microsoft Defender is a comprehensive security solution from Microsoft. It's comprised of various services that are designed to protect devices, identities, email, and applications against cyber threats. It includes anti-virus and threat intelligence and can be used to respond to threats like malware, ransomware, and phishing.
Microsoft Defender can be integrated into Secureframe to automate the evaluation and evidence collection related to compliance frameworks.
To integrate Microsoft Defender with Secureframe, navigate to Integrations and search for "Microsoft Defender" on the "Available Integrations" page and click "Connect." (If you have the Custom Integration feature, click on "Add native connection").
Follow the steps in the provided form to connect the integration.
Once the integration is connected you will be able to see it in the "Integrations" page, you can control the following actions for your Microsoft Defender integration through this page:
Check the connection status
Run a sync
Rename the connection
Archive the connection
Reconnect
Frequently Asked Questions (FAQ)
Secureframe shows far more critical Defender vulnerabilities than the Defender portal. Why?
Secureframe and Defender often count different things, so the totals will not match a side-by-side glance.
Secureframe's Vulnerabilities page counts one row per CVE per device. Defender's vulnerabilities / weaknesses views often count unique CVEs. One CVE on 19 machines can be 1 line in Defender and 19 rows in Secureframe.
Secureframe does not default-filter to open findings only. Severity charts and table totals can include closed or remediated findings. Defender typically shows current exposures. Filter Secureframe to Status = Open before comparing.
After filtering to open findings, compare again. If counts still look wrong after a successful Defender sync, contact Support with the connection name and the filters you used in both tools.
