Comodo Help
Find the desired product help
Managed Detection And Response

Managed Detection And Response

cWatch MDR Admin GuideEnglish

English

Print Help
Integrate Your Windows Defender Account With MDR
  • Introduction To Xcitium CWatch MDR
    • Purchase A License
    • Log-in To The Admin Console
  • The Home Screen
  • Service Summary
  • Incidents Overview
    • Incidents
    • Threat Summary
  • Log Collection Summary
  • Threat Communication Graph
  • Tickets
  • Reports
  • Notification Settings
  • Integrate Your Office 365 Account With MDR
  • Integrate Your Google Workspace Account With MDR
  • Integrate Your Microsoft Entra Account With MDR
  • Integrate Your CrowdStrike Account With MDR
  • Integrate Your Windows Defender Account With MDR
  • Integrate Your SentinelOne Account With MDR
  • About Xcitium Security Solutions

Integrate your Windows Defender Account with MDR 


You can integrate your Windows Defender account with MDR so any threats and behavioral anomalies are detected. Once integrated, our SOC team analyzes data logs from your Windows Defender account for malware activity and other anomalies. 

You have to first register an application in Microsoft Entra ID and then configure MDR to collect data. 


Configuration Steps 


Step 1 - Register an Application in Microsoft Entra ID 

Step 2 - Retrieve Required Identifiers 

Step 3 - Generate a Client Secret 

Step 4 - Assign API Permissions 

Step 5 - Configure MDR with Microsoft Defender credentials (Tenant ID, Client ID, Secret Key) 

 

 Step 1 - Register an Application in Microsoft Entra ID 
  • Sign in to the Azure Portal. 
  • Open Microsoft Entra ID. 
  • Select App Registrations. 
  • Click New Registration. 
  • Provide a Name → Register. 

Step 2 - Retrieve Required Identifiers 

After registration: 

  • Open your app. 
  • Copy the following: 
    • Application (Client) ID 
    • Directory (Tenant) ID 


Step 3 - Generate a Client Secret 

  • Go to Certificates & Secrets. 
  • Under Client Secrets<>, click New Client Secret. 
  • Add description → choose expiry → Add. 
  • Copy the Secret Value (only shown once). 


Step 4 - Assign API Permissions 

  • Go to API Permissions → Add a Permission. 
  • Choose Microsoft Graph → Application Permissions and add the following: 
  • Device.Read.All — Allows the application to retrieve the list of all devices onboarded to Microsoft Defender. 
  • Directory.Read.All — Allows the application to read tenant and directory metadata required to resolve device and user context. 
  • SecurityAlert.Read.All — Allows the application to retrieve Microsoft Defender security alerts, including DLP-related alerts. 
  • SecurityIncident.Read.All — Allows the application to retrieve incidents associated with Microsoft Defender alerts. 




 

Step 5 - Configure MDR with Microsoft Defender Credentials 

  • Log into your Xcitium account and open MDR. 
  • Click 'Managed Security' in the top navigation, then select the 'Integrations' tab. 
  • Scroll down to 'Integrate your Windows Defender account' and fill in the following fields: 
    • Tenant ID
    • Client ID 
    • Secret Key 
  • Click 'Register Your Account'. 
 

That's it, your Windows Defender account is integrated with MDR. Contact your Xcitium account manager for support if you have any trouble integrating your cloud account with MDR. 
Our Products
  • Free Antivirus
  • Free Internet Security
  • Website Malware Removal
  • Free Anti-Malware
  • Anti-Spam (Free Trial)
  • Windows Antivirus
  • Antivirus for Windows 7
  • Antivirus for Windows 8
  • Antivirus for Windows 10
  • Antivirus for MAC
  • Antivirus for Linux
  • Free Endpoint Security
  • Free ModSecurity
  • Free RMM
  • Free Website Malware Scanner
  • Free Device Manager for Android
  • Free Demo
  • Network Security
  • Endpoint Protection
  • Antivirus for Android
  • Comodo Antivirus
  • Wordpress Security
Cheap CDN
  • Bootstrap CDN
  • Semantic UI CDN
  • Jquery CDN
  • CDN Plans
  • CDN
  • Free CDN
Enterprise
  • Patch Management Software
  • Patch Manager
  • Service Desk
  • Website Down
  • Endpoint Protection Solutions
  • Website Security Check
  • Remote Monitoring and Management
  • Website Security
  • Device Manager
  • ITSM
  • CRM
  • MSP
  • Android Device Manager
  • MDR Services
  • Managed IT Support Services
  • Free EDR
Free SSL Certificate
Support Partners Terms and Conditions Privacy Policy

© Comodo Group, Inc. 2026. All rights reserved.