Overview of Microsoft 365 Defender APIs
Want to experience Microsoft 365 Defender? Learn more about how you can evaluate and pilot Microsoft 365 Defender.
- Microsoft 365 Defender
Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Microsoft 365 Defender is built on top of an integration-ready platform.
Use the Microsoft 365 Defender APIs to automate workflows based on the shared incident and advanced hunting tables.
Combined incidents queue - Focus on what's critical by grouping the full attack scope and all impacted assets together under the incident API.
Cross-product threat hunting - Leverage your security team's organizational knowledge to hunt for signs of compromise, by creating your own custom queries to sift over raw data collected across multiple protection products.
Event streaming API - Ship real-time events and alerts in a single data stream as they occur.
Along with these Microsoft 365 Defender-specific APIs, each of our other security products expose additional APIs to help you take advantage of their unique capabilities.
The transition to the unified portal should not affect the PowerBi dashboards based on Microsoft Defender for Endpoint APIs. You can continue to work with the existing APIs regardless of the interactive portal transition.
Watch this short video to learn how you can use Microsoft 365 Defender to automate workflows and integrate apps.
Submit and view feedback for