Deployment Architecture

Can microsoft defender add on use certificates?

siuolkl
Explorer

Hi Experts,

would like to check if anyone tried using certificates for the Microsoft defender add-on.

how / where do I generate the certificates to upload to azure app registration.

currently from splunkbase im using this add on. 

https://splunkbase.splunk.com/app/4959/#/details 

would like to check if there is any supported version by splunk ?

 

 

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hi @siuolkl ,

Can you please explain the reason you need to add a certificate?

I would just generate credentials on Azure App Registration and just add in the Add-on configuration UI and that's all.

0 Karma

siuolkl
Explorer

@VatsalJagani  hello thank you for the reply.

the add on is working fine but I am posting this question as my environment requires the use of certificates.

I am not sure if splunk support this method.

 

Also from Microsoft documentation. the option to use cert is more secure compared to client secrets for app registration from azure.

https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-register-app 

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...