Skip to main content

Connecting Vanta & Microsoft Defender for Endpoint

Overview

The Microsoft Defender for Endpoint integration connects your Defender tenant to Vanta over OAuth, importing the devices onboarded to your tenant along with the vulnerability findings raised against them. It is best suited for teams that already use Defender for Endpoint as their endpoint security and vulnerability management tool.

Vanta links each finding to the device it affects and brings in device health status, risk score, and exposure level alongside CVE severity and CVSS v3 scores, so you can prioritize remediation the same way Defender does.

Estimated setup time: 5 minutes

ℹ️ Note: This guide covers the commercial Defender for Endpoint integration. GCC High tenants on the Vanta Government instance use a separate integration — see Connecting Vanta & Microsoft Defender for Endpoint for US Government (GCC High). Microsoft Defender for Cloud, which reports on cloud infrastructure rather than devices, is part of Vanta's Azure integration.


Use cases and capabilities

  • Device Monitoring: Connect your Defender tenant and we import each active device onboarded to Defender for Endpoint, maintaining it as a monitored asset in Vanta. This gives you a continuously updated view of your fleet without manual tracking.

  • Vulnerability Management: We sync CVE-based findings from Microsoft Defender Vulnerability Management and link each finding to the device it affects. These findings power four automated tests in Vanta, one each for critical, high, medium, and low severity.

  • Remediation Acceleration: For each finding, we surface the affected software product and version and, where Microsoft publishes one, the KB article that remediates it. Your team can see what action is needed without opening the Defender portal for each CVE.

  • Posture Monitoring: We import the risk score and exposure level Defender assigns to each device, so you can review which devices carry elevated risk as part of your ongoing posture review.

  • Evidence Collection: Device and vulnerability data synced through this integration is available as continuous evidence in Vanta, reducing manual screenshots and exports at audit time.

Capabilities overview

Resource / Capability

Supported

How it is used in Vanta

Devices

Yes

Imported as monitored assets with health status, risk score, and exposure level

Vulnerability findings

Yes

Per-device CVE findings with severity and CVSS v3 score populate the Vulnerabilities page

Remediation guidance

Yes

Affected software product and version, plus the fixing Microsoft KB article where one is published

Automated tests

Yes

Four tests, one each for critical, high, medium, and low severity findings

Evidence collection

Yes

Device vulnerability evidence applies to every compliance framework you monitor in Vanta

Device selection from Vanta

No

Not supported — which devices sync is determined by their health status and exclusion state in Defender

Alerts

No

Not imported — use the Defender portal to review alerts

Write access to Defender

No

Not supported — access is read-only


Prerequisites

Before starting setup, confirm the following:

  • You have a Vanta admin account.

  • Your tenant has a Microsoft Defender for Endpoint Plan 2 or Microsoft Defender Vulnerability Management license.

  • You have a Microsoft Entra account with the Global Administrator or Privileged Role Administrator role, so you can grant admin consent on behalf of your whole tenant.

💡 Tip: Confirm your devices are onboarded and showing an Active health status in the Microsoft Defender portal before you connect. We import only devices in that state, so connecting before any devices qualify leaves the integration with nothing to sync.


Explore the integrations page

When you navigate to the Microsoft Defender for Endpoint integration, you'll land on its listing page, which includes five tabs that cover what you need to know before (and after) you connect.

  • Overview — Start here. A summary of what the integration does, its top capabilities, and the prerequisites you'll need in place before connecting. When you're ready, click Connect to begin setup.

  • API permissions — Exactly what access Vanta requests from Microsoft Defender for Endpoint: each permission's scope, whether it's read or write, and what data it covers, etc. Share this tab with your security team if they need to review access before you connect.

  • Resource types — Every resource type Vanta imports from this integration, down to the specific fields collected for each. Use this to understand exactly what data will show up in Vanta once connected.

  • Automated tests — How many tests connecting this integration unlocks and which frameworks and controls they map to (SOC 2, ISO 27001, etc.), plus the full list of tests by name. Useful for scoping compliance coverage ahead of an audit.

  • Security — How Vanta protects the data it collects — encryption, data retention, access controls, and infrastructure. Visit Vanta's Trust Center for the full picture.

When you’re ready to connect, continue to the setup guide below.


Setup guide

Step 1: Find the Defender for Endpoint integration in Vanta

  • In Vanta, go to the Integrations page, click Add integration, and search for Microsoft Defender for Endpoint. For help navigating, see our guide to the Integrations Page.

  • Click the integration card.

  • A detailed integration listing page will open. To learn more about this experience, review Explore the integration page section.

  • Click Connect.

Step 2: Authorize the connection

  • On the Connect Microsoft Defender for Endpoint step, click Connect. Vanta opens Microsoft's sign-in flow.

  • Sign in with the Microsoft Entra account that holds the Global Administrator or Privileged Role Administrator role.

  • Review the access Vanta is requesting and click Accept to grant consent on behalf of your organization. For what we request and why Microsoft may list more, see the Permissions section of this article.

Step 3: Confirm the connection

  • Microsoft redirects you back to Vanta, which confirms You're connected and begins syncing your resources.

  • Click Manage integration to follow sync progress, review your synced data, or update integration settings.


Permissions

Read access

We use the authorization you grant during setup to read the devices onboarded to your Defender tenant, including each device's health status, risk score, and exposure level, and to read the vulnerability findings Microsoft Defender Vulnerability Management raises against those devices, including CVE ID, severity, and CVSS v3 score. We do not import Defender alerts.

For the full list of permissions this integration requests, open the integration's listing page in Vanta and select the API permissions tab.

Write access

We have no write access to your Defender environment. We cannot create, modify, close, or remediate anything in Defender.


Troubleshooting and FAQs

Setup fails with an authorization error

  • Likely cause: The account used to grant consent does not hold a role that can consent on behalf of the organization.

  • How to confirm: In the Microsoft Entra admin center, check the roles assigned to the account you used.

  • Fix: Reconnect the integration and grant admin consent using an account with the Global Administrator or Privileged Role Administrator role.

Setup fails with a permissions error

  • Likely cause: Consent was granted, but not for all of the permissions the integration needs.

  • How to confirm: The error names the permissions we could not use. You can compare them against the API permissions tab of the integration's listing page in Vanta.

  • Fix: Reconnect the integration and grant admin consent for all requested permissions.

The integration is connected but no devices appear

  • Likely cause: No devices in your Defender tenant have an Active health status, or all of them are marked as excluded.

  • How to confirm: In the Microsoft Defender portal, check that your onboarded devices show a health status of Active and are not excluded.

  • Fix: Confirm your devices are actively onboarded to Defender for Endpoint and are not excluded, then allow the next sync to complete.

Devices appear but no vulnerability findings appear

  • Likely cause: The initial device sync has not finished. We record your devices first, then pull the vulnerability findings for them, so findings cannot appear until the devices have synced.

  • How to confirm: Open the integration in Vanta and click the Activity tab to check sync progress.

  • Fix: Allow another sync cycle to complete. If your devices are present and findings still do not appear, confirm your Defender license includes vulnerability management.

Where can I see sync progress or find out why a sync failed?

Open the integration in Vanta and click the Activity tab. The activity log shows sync history and error details for each run.