Deployment Architecture

Can microsoft defender add on use certificates?

siuolkl
Explorer

Hi Experts,

would like to check if anyone tried using certificates for the Microsoft defender add-on.

how / where do I generate the certificates to upload to azure app registration.

currently from splunkbase im using this add on. 

https://splunkbase.splunk.com/app/4959/#/details 

would like to check if there is any supported version by splunk ?

 

 

Labels (2)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hi @siuolkl ,

Can you please explain the reason you need to add a certificate?

I would just generate credentials on Azure App Registration and just add in the Add-on configuration UI and that's all.

0 Karma

siuolkl
Explorer

@VatsalJagani  hello thank you for the reply.

the add on is working fine but I am posting this question as my environment requires the use of certificates.

I am not sure if splunk support this method.

 

Also from Microsoft documentation. the option to use cert is more secure compared to client secrets for app registration from azure.

https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-register-app 

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...