{
 "categories": [
  "enterprise",
  "observability"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-12",
   "fact": "homepage",
   "note": "Microsoft presents Microsoft Defender XDR as a unified pre- and post-breach enterprise defense suite across endpoints, identities, email, and applications, used in the Microsoft Defender portal at security.microsoft.com.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "license",
   "note": "Microsoft states Defender XDR licensing requirements must be met before enabling the service. This pass did not open a public price list. The product is a commercial Microsoft Security suite.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "platforms",
   "note": "Microsoft documents Defender XDR in the Microsoft Defender portal. That console is a web application.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.api.exists",
   "note": "Microsoft documents Defender XDR APIs to automate workflows on the shared incident queue, advanced hunting, and event streaming.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.api.kinds[0]",
   "note": "The native incident and hunting host is https://api.security.microsoft.com. Regional hosts exist for the United States, Europe, and the United Kingdom.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-supported",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.api.kinds[1]",
   "note": "Microsoft states that all APIs along the /api path use the OData protocol, for example https://api.security.microsoft.com/api/incidents.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-supported",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.api.auth[0]",
   "note": "API access requires OAuth 2.0. User context creates a Microsoft Entra native application, assigns permissions, and obtains a token using the signed-in user's credentials.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-access",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.api.auth[1]",
   "note": "Application-context daemons register a Microsoft Entra app, add Microsoft Threat Protection application permissions, and obtain a client-credentials token for resource https://api.security.microsoft.com. Callers send Authorization: Bearer.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-create-app-web",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.api.coverage",
   "note": "Supported native APIs are Advanced Hunting, Incident list/update, and Streaming. Graph security adds incident and hunting operations. Neither page claims the entire Defender portal.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-supported",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.api.docs",
   "note": "Opened Microsoft's current Defender XDR API overview, including Graph security guidance and links to access, user-context, and application-context auth.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.extensibility.scripting[0]",
   "note": "Microsoft documents advanced hunting as KQL over up to 30 days of Microsoft 365 Defender raw data via runHuntingQuery.",
   "source": "https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.data_access.export[0]",
   "note": "Hunting results return structured schema and results objects. Incident Graph and native REST operations return JSON resource documents.",
   "source": "https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "modalities.rpa.ui_stack[0]",
   "note": "Operators use the Microsoft Defender portal, so the interactive UI stack in scope is web DOM. No UI probe was run.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "verdict.scores.api",
   "note": "Graph plus native REST are documented, Entra-authenticated, and cover incident read/write, hunting, and streaming. License gates, hunting quotas, and the February 2027 native-hunting retirement keep the path below unusual completeness.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "freshness.watch[0].url",
   "note": "Opened Microsoft's current Defender XDR API overview, including incident, hunting, and streaming surfaces and the Graph security preference.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-overview",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "freshness.watch[1].url",
   "note": "Opened Microsoft's current Defender XDR API access page, including OAuth 2.0 user, application, and partner contexts.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-access",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "freshness.watch[2].url",
   "note": "Opened Microsoft's current Graph security API overview, including incident/alert resources and the hunting migration to graph.microsoft.com with a 1 February 2027 native-endpoint retirement.",
   "source": "https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0",
   "tier": "declared"
  },
  {
   "date": "2026-09-12",
   "fact": "freshness.watch[3].url",
   "note": "Opened Microsoft's current application-context auth guide, including Microsoft Threat Protection permissions and client-credentials token examples against api.security.microsoft.com.",
   "source": "https://learn.microsoft.com/en-us/defender-xdr/api-create-app-web",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-12",
  "volatility": "high",
  "watch": [
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/defender-xdr/api-overview"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/defender-xdr/api-access"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0"
   },
   {
    "type": "docs",
    "url": "https://learn.microsoft.com/en-us/defender-xdr/api-create-app-web"
   }
  ]
 },
 "homepage": "https://learn.microsoft.com/en-us/defender-xdr/microsoft-365-defender",
 "id": "microsoft-defender-xdr",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": "unknown"
  },
  "api": {
   "auth": [
    "oauth2",
    "service-principal"
   ],
   "coverage": "partial",
   "docs": "https://learn.microsoft.com/en-us/defender-xdr/api-overview",
   "exists": true,
   "kinds": [
    "rest",
    "odata"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": []
  },
  "extensibility": {
   "scripting": [
    "advanced-hunting-kql"
   ],
   "webhooks": "unknown"
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": "unknown"
  },
  "mcp": {
   "first_party": "unknown",
   "third_party": [],
   "verdict": "unknown"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Microsoft Graph security APIs and Defender XDR REST at api.security.microsoft.com cover incidents and hunting without browser control of the Defender portal. This record is Microsoft Defender XDR, not Microsoft Sentinel.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "Microsoft Defender XDR",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "microsoft-sentinel",
   "crowdstrike-falcon",
   "ibm-qradar",
   "wiz"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "Microsoft",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": null,
   "computer_use": null,
   "integrations": null,
   "mcp": null,
   "overall": 8,
   "rpa": null
  },
  "summary": "Microsoft Defender XDR is automatable today through Microsoft Graph security APIs and native Defender XDR REST. This record is the unified XDR suite formerly documented as Microsoft 365 Defender. It is not Microsoft Sentinel, CrowdStrike Falcon, IBM QRadar, or Wiz. Graph lists and updates incidents at GET/PATCH https://graph.microsoft.com/v1.0/security/incidents with delegated or application SecurityIncident.Read.All or ReadWrite.All. Native incidents and hunting use https://api.security.microsoft.com/api/ and OData along the /api path. Microsoft tells callers to prefer Graph; the older hunting endpoints at api.security.microsoft.com stop returning data on 1 February 2027. Authentication is OAuth 2.0 against Microsoft Entra ID. User-context apps use an authorization-code flow. Application-context daemons use client credentials against resource https://api.security.microsoft.com, with Microsoft Threat Protection application permissions such as Incident.Read.All. Advanced hunting runs KQL over up to 30 days of raw signals, with per-tenant CPU and 45-calls-per-minute floors. Coverage is partial because the documented surfaces are incidents, hunting, and streaming, not the entire Defender portal. A first-party Defender XDR MCP server is not established on the opened pages. Sentinel's hosted MCP can expose Defender triage tools after lake onboarding; that server belongs to the Sentinel identity. Connector catalogs were not opened. Computer-use viability is unassessed. API scores 8 and is the best path.\n"
 }
}