Microsoft Defender for Identity
Identity protection

Connect SailPoint Identity Security Cloud to Microsoft Defender for Identity (Preview)

In brief

The article now describes connecting SailPoint Identity Security Cloud through the Defender portal API connector, updates role-based access terminology, and instructs administrators to create a dedicated SailPoint user before generating a personal access token.

What Defender admins need to know

Administrators setting up this integration should follow the revised user and token creation sequence.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Connect SailPoint Identity Security Cloud to Microsoft Defender for Identity (Preview)

This article describes how to connect Defender for Identity to your SailPoint Identity Security Cloud account. This connection helpsto Microsoft Defender for Identity by using the API connector in the Microsoft Defender portal. After you seeset up this integration, security administrators can gain visibility into SailPoint-managed identities, investigate identity-related threats, and manage SailPoint identities.monitor account activity directly from Defender for Identity. Before you start, make sure you have the required SailPoint IdentityNow Admin role and the necessary Microsoft Entra or Defender XDR permissions. For full details, review the prerequisites for connecting SailPoint.

Prerequisites

  • The IdentityNow Admin role is required only to create an application.

Microsoft Entra and Defender XDR role-based access options

Your account needs one of these access options to set up the connector:

- Security Admin
  • Defender XDR Unified RBAC permission:
    • Core security settings (manage)

Connect SailPoint Identity Security Cloud to Microsoft Defender for Identity

Create a SailPoint Identity Security Cloud Personal Access Token

Create a personal access token in SailPoint Identity Security Cloud for this integration:

  1. Sign in to SailPoint Identity Security Cloud.
  2. CreateBefore you begin, create a dedicated SailPoint Identity Security Cloud user for this integration. Then create a personal access token for that user:
    1. Sign in to SailPoint Identity Security Cloud as the dedicated user.
    2. Go to User's Preferences > Personal Access Tokens.
    3. Select New Token.
    4. Add the following scopes to the token:
    5. Review the information and select Connect.
    6. Verify that the SailPoint Identity connector appears in the My Connector table as Connection Status: Ok.

    Related articlescontent