Deployment Architecture

Can microsoft defender add on use certificates?

siuolkl
Explorer

Hi Experts,

would like to check if anyone tried using certificates for the Microsoft defender add-on.

how / where do I generate the certificates to upload to azure app registration.

currently from splunkbase im using this add on. 

https://splunkbase.splunk.com/app/4959/#/details 

would like to check if there is any supported version by splunk ?

 

 

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hi @siuolkl ,

Can you please explain the reason you need to add a certificate?

I would just generate credentials on Azure App Registration and just add in the Add-on configuration UI and that's all.

0 Karma

siuolkl
Explorer

@VatsalJagani  hello thank you for the reply.

the add on is working fine but I am posting this question as my environment requires the use of certificates.

I am not sure if splunk support this method.

 

Also from Microsoft documentation. the option to use cert is more secure compared to client secrets for app registration from azure.

https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-register-app 

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...