A community member has associated this post with a similar question:
Inquiry About Accessing Multi-Tenant Alerts and Incidents via API

Only moderators can edit this content.

Inquiry About Accessing Multi-Tenant Alerts and Incidents via API

Nicholas Lim 0 Reputation points
2024-07-25T23:28:54.2166667+00:00

I am currently working on integrating Microsoft Defender with our system and have encountered an issue. In the Multi-Tenant Management portal, I can view multi-tenant alerts and incidents without any problems. However, I am unable to access the same information through the Graph API or any other API.

I have created an app registration in my Azure portal as a multi-tenant application. But when I call the alerts and incidents through Graph API, it only returns one tenant rather than the multi-tenant information.

Could you please clarify if there's a specific API, such as the Graph API or a dedicated Defender API, that allows querying multi-tenant alerts and incidents?

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
12,002 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,373 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more