Recued
Menu
← Back to packs

Endpoint Security - Microsoft Defender for Endpoint

by recued-core v1 app_pack 8 views

Use Endpoint Security - Microsoft Defender for Endpoint in Recued for edr, alerts, machines, and vulnerabilities. It includes 14 built-in actions and 5 ready-to-run workflows. Connect your Microsoft Defender account to use it. Actions that change data use Recued's approval controls.

Trust & control

What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.

What it's allowed to do

Admin Web APIs microsoft-defender-endpoint external change
Read: alert.read · No approvalRead: alert.search · No approvalWrite: alert.update · Asks approvalRead: exposure_score.read · No approvalRead: machine.alert.search · No approvalAdmin: machine.isolate · Always asksRead: machine.logon_user.search · No approvalRead: machine.read · No approvalRead: machine.search · No approvalAdmin: machine.unisolate · Always asksRead: machine.vulnerability.search · No approvalRead: machine_action.search · No approvalRead: recommendation.search · No approvalRead: vulnerability.search · No approval

Data it touches

SurfacesWeb APIs

About

Tags

pack:microsoft-defender-endpointmicrosoft-defender-endpointdefender-for-endpointmicrosoft-defenderendpoint-securityedralertsmachinesvulnerabilitiessecurity-recommendationsincident-responseapiv3composition