Skip to main content
Connect Microsoft Defender (Defender XDR) so Myrmex can read alerts, incidents, and risk signals across endpoints, identities, apps, and email, and help you triage them. Myrmex connects from the cloud over Microsoft Graph after you grant admin consent — reading in real time, on demand, with no Collector required and nothing stored on the Myrmex side.

What Myrmex Can Do

Alerts & incidents

Read Defender XDR alerts and incidents for live triage.

Endpoint & identity signals

Review device, identity, and app risk across the estate.

Threat context

Correlate Defender findings with the rest of your connected stack.

Guided response

Get recommended next steps for incidents, with approval for any action.

Before You Start

Microsoft Defender connects from the cloud — no Collector is required. You’ll need:
  • A Microsoft Defender tenant and your Tenant ID.
  • An account with the Global Administrator (or Security Administrator) role, to grant tenant-wide admin consent.

Step 1 — Create the Credential in Microsoft

1

Find your Tenant ID

In the Microsoft Entra admin center, open Overview and copy the Tenant ID (Directory ID).
2

Confirm your role

Make sure your account can grant tenant-wide admin consent — Global Administrator or Security Administrator.
3

Grant consent during Connect

Myrmex uses a pre-registered application. When you add the integration you’ll be redirected to Microsoft to review and grant the requested read permissions.

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → Microsoft Defender, then fill in:
When you connect, you’re redirected to Microsoft to sign in and grant admin consent. The authentication method and the set of granted permissions are captured automatically during consent — you don’t enter them by hand.

Connect

Click Connect and complete the Microsoft admin-consent prompt. Microsoft Defender then appears under Environment → Integrations, and you can start asking the AI about your alerts and incidents in the Workspace.
Myrmex requests read-oriented Microsoft Graph permissions for triage. Consent can be revoked at any time from the Microsoft Entra admin center.