Back Arrow Back to All Integrations

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint


Integrate Microsoft Defender for Endpoint With Blumira’s Cloud SIEM

Click here for the most updated version of this documentation.


Microsoft Defender for Endpoint, (formerly Defender Advanced Threat Protection) is an enterprise endpoint security platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats.


Blumira integrates with Microsoft Defender for endpoint to stream Office endpoint security events and alerts to the Blumira service for threat detection, alerting and actionable response.


Sign Up For Your Free Account Today

Get your free account with Blumira and secure your Microsoft 365 environment in minutes. No credit card required.


Free Trial

Integrating with Microsoft Defender for Endpoint

Before you begin

First, integrate Azure Event Hubs with Blumira by completing the steps in Integrating with Microsoft Azure Event Hubs.

Forwarding events to Blumira

To connect Defender for Endpoints to your Blumira event hub in Azure:

  1. Log in to endpoint.microsoft.com.
  2. Click Tenant Administration.
  3. Click Diagnostic Settings.
  4. Click + Add Diagnostic Setting.
  5. Type a name such as “Blumira Logging” or whatever you prefer.
  6. Select all Log Categories.
  7. Select Stream to an Event Hub.
  8. Under Event hub name, select the name of the hub you created for the Blumira integration.
  9. Click Save.