Deployment Architecture

Can microsoft defender add on use certificates?

siuolkl
Explorer

Hi Experts,

would like to check if anyone tried using certificates for the Microsoft defender add-on.

how / where do I generate the certificates to upload to azure app registration.

currently from splunkbase im using this add on. 

https://splunkbase.splunk.com/app/4959/#/details 

would like to check if there is any supported version by splunk ?

 

 

Labels (2)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hi @siuolkl ,

Can you please explain the reason you need to add a certificate?

I would just generate credentials on Azure App Registration and just add in the Add-on configuration UI and that's all.

0 Karma

siuolkl
Explorer

@VatsalJagani  hello thank you for the reply.

the add on is working fine but I am posting this question as my environment requires the use of certificates.

I am not sure if splunk support this method.

 

Also from Microsoft documentation. the option to use cert is more secure compared to client secrets for app registration from azure.

https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-register-app 

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...