What Myrmex Can Do
Alerts & incidents
Read Defender XDR alerts and incidents for live triage.
Endpoint & identity signals
Review device, identity, and app risk across the estate.
Threat context
Correlate Defender findings with the rest of your connected stack.
Guided response
Get recommended next steps for incidents, with approval for any action.
Before You Start
Microsoft Defender connects from the cloud — no Collector is required. You’ll need:- A Microsoft Defender tenant and your Tenant ID.
- An account with the Global Administrator (or Security Administrator) role, to grant tenant-wide admin consent.
Step 1 — Create the Credential in Microsoft
1
Find your Tenant ID
In the Microsoft Entra admin center, open Overview and copy the Tenant ID (Directory ID).
2
Confirm your role
Make sure your account can grant tenant-wide admin consent — Global Administrator or Security Administrator.
3
Grant consent during Connect
Myrmex uses a pre-registered application. When you add the integration you’ll be redirected to Microsoft to review and grant the requested read permissions.
Step 2 — Add the Integration in Myrmex
From the Directory, choose Add Integration → Microsoft Defender, then fill in:When you connect, you’re redirected to Microsoft to sign in and grant admin consent. The authentication method and the set of granted permissions are captured automatically during consent — you don’t enter them by hand.
Connect
Click Connect and complete the Microsoft admin-consent prompt. Microsoft Defender then appears under Environment → Integrations, and you can start asking the AI about your alerts and incidents in the Workspace.Myrmex requests read-oriented Microsoft Graph permissions for triage. Consent can be revoked at any time from the Microsoft Entra admin center.