Microsoft Defender XDR
Endpoint protection

Microsoft 365 Security Center Mde

In brief

The documentation now says the alerts API works across all Defender products, replacing “all Defender XDR products.” The migration link is unchanged.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

APIs and MSSPs

The Microsoft Defender XDR alerts API is the official API that enables customers to work with alerts across all Defender XDR products using a single integration. For more information, see Migrate from the MDE SIEM API to the Microsoft Defender XDR alerts API.

To authorize a managed security service provider (MSSP) to access receive alerts, you need to provide the application and tenant IDs of the MSSP. For more information, see MSSP integration.