Issue with Finding Vulnerability.read.all Permission in Azure AD for Defender API

DYK 5 Reputation points
2023-08-11T15:31:08.8566667+00:00

Product & Version: Azure AD, Microsoft Defender Endpoint API

Issue Description: I'm trying to access the Microsoft Defender API using the link: Defender Endpoint - Get All Vulnerabilities. The documentation mentions the Vulnerability.read.all permission, but when I go to Azure AD to register an app and assign this permission, it is missing.

Steps Already Taken:

  1. Navigated to Azure AD.
  2. Tried registering a new app.
  3. Searched for the Vulnerability.read.all permission during the permission assignment step.

Question: Has the Vulnerability.read.all permission been deprecated? If so, what alternative permissions or methods should I use to access vulnerability details from the Defender API?

Additional Information: None at the moment, but happy to provide more details if necessary.

Microsoft Security Microsoft Graph
0 comments No comments
{count} vote

2 answers

Sort by: Most helpful
  1. Jonathan Green 10 Reputation points
    2023-10-04T14:42:57.45+00:00

    Navigate to "APIs my organization users".
    Type into the search box "WindowsDefenderATP"
    Select "Delegated permissions" or "Application permissions".
    Scroll to the bottom.

    2 people found this answer helpful.
    0 comments No comments

  2. Sander van de Velde | MVP 36,761 Reputation points MVP Volunteer Moderator
    2023-08-11T15:45:22.4233333+00:00

    Hello DYK,

    thank you for visiting this moderated community forum.

    Azure Active Directory (Azure AD) is a cloud-based identity and access management service. Azure AD enables your employees access external resources, such as Microsoft 365, the Azure portal, and thousands of other SaaS applications.

    Please also check out the free training about Azure Active Directory.


    If the response helped, do "Accept Answer". If it doesn't work, please let us know the progress. All community members with similar issues will benefit by doing so. Your contribution is highly appreciated.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.