Skip to content

[REQUEST]: 8.18: Document new Connector for Microsoft Defender for Endpoint (in Tech. Preview) #249

@paul-tavares

Description

@paul-tavares

Description

Description

Add documentation for new Microsoft Defender for Endpoint connector. This new connector will (at this time) be in Tech. Preview, but that could change by the time we enable it (currently hidden behind a feature flag.

When

Looking to make this connector available with v8.18 / v9.0.
It may be enabled for serverless prior to these release dates.

Resources

Implementation PR: elastic/kibana#203183

Note that this connector is an EDR only connector. The EDR sub-privileges implementation is being done here and that PR may have impacts to how you word the documentation for this new connector (as well as the existing SentinelOne + Crowdstrike connectors)

Relates to elastic/kibana#207136

Which documentation set does this change impact?

Elastic On-Prem and Cloud (all)

Feature differences

From the connector's standpoint, all is the same.

See below for screen capture of required data for creating the connector:

Image

The data required closely mirrors the same data required to set the Fleet Microsoft Defender for Endpoint integration - screen capture of the input fields in fleet:

Image

What release is this request related to?

8.18, 9.0

Collaboration model

The documentation team

Point of contact.

Main contact:

Stakeholders:

??

Metadata

Metadata

Assignees

Labels

Team:PlatformIssues owned by the Platform Docs Team

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions