Description:
Microsoft Defender for Cloud can integrate with Microsoft Defender for Endpoint to provide advanced threat detection, endpoint protection, and vulnerability management for Azure and hybrid workloads. When integration is enabled, Defender for Cloud pushes its security recommendations, alerts, and telemetry to Defender for Endpoint, improving endpoint security posture and centralizing investigation workflows. Ensuring this integration is selected provides unified visibility and strengthens endpoint monitoring.
Rationale:
Enabling Defender for Endpoint integration ensures endpoints receive advanced behavioral sensors, automated investigation capabilities, and enhanced threat intelligence. Without integration, Defender for Cloud cannot forward threat data to Defender for Endpoint, reducing detection effectiveness and creating monitoring gaps across servers and virtual machines.
Impact:
Positive impacts include improved endpoint security, centralized monitoring, and expanded threat detection. Enabling integration may require appropriate licensing for Defender for Endpoint.
Default Value:
Integration is not enabled by default and must be manually configured.
Pre-Requisites:
Microsoft Defender for Endpoint Plan 1 or Plan 2 license
Required permissions: Security Admin or Owner, Ability to configure workload protection settings
Test Plan:
Sign in to the Azure portal https://portal.azure.com
Search for "Microsoft Defender for Cloud"
Under the management section, click Environment Settings.
Select the subscription, click on Defender Plans
Click Settings & monitoring,
Locate Endpoint protection
Verify Endpoint protection is set to On
If Endpoint protection is not set to On, follow the implementation steps
Implementation Steps:
Sign in to the Azure portal https://portal.azure.com
Search for "Microsoft Defender for Cloud"
Under the management section, select Environment Settings
Select the subscription
Under the settings, click on Defender Plans
Click Settings & monitoring
Set Endpoint protection to On to enable Microsoft Defender for Endpoint integration
Continue to save the configuration
Backout Plan:
Sign in to the Azure Portal https://portal.azure.com
Search for and open Microsoft Defender for Cloud
Under the Management section, select Environment settings
Select the relevant subscription
Open Defender plans or the page showing Endpoint protection
Set Endpoint protection to Off
Save the changes
Reference:



