Endpoint Security - Microsoft Defender for Endpoint
Use Endpoint Security - Microsoft Defender for Endpoint in Recued for edr, alerts, machines, and vulnerabilities. It includes 14 built-in actions and 5 ready-to-run workflows. Connect your Microsoft Defender account to use it. Actions that change data use Recued's approval controls.
What this pack installs
- Microsoft Defender endpoint security digest Recipe
- Microsoft Defender machine investigation brief Recipe
- Isolate a Microsoft Defender endpoint machine Recipe
- Release a Microsoft Defender endpoint machine from isolation Recipe
- Update a Microsoft Defender endpoint alert Recipe
- microsoft-defender-endpoint Ingredient
Trust & control
What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.
What it's allowed to do
Admin
Web APIs
microsoft-defender-endpoint
external change
Read: alert.read · No approvalRead: alert.search · No approvalWrite: alert.update · Asks approvalRead: exposure_score.read · No approvalRead: machine.alert.search · No approvalAdmin: machine.isolate · Always asksRead: machine.logon_user.search · No approvalRead: machine.read · No approvalRead: machine.search · No approvalAdmin: machine.unisolate · Always asksRead: machine.vulnerability.search · No approvalRead: machine_action.search · No approvalRead: recommendation.search · No approvalRead: vulnerability.search · No approval