Deployment Architecture

Can microsoft defender add on use certificates?

siuolkl
Explorer

Hi Experts,

would like to check if anyone tried using certificates for the Microsoft defender add-on.

how / where do I generate the certificates to upload to azure app registration.

currently from splunkbase im using this add on. 

https://splunkbase.splunk.com/app/4959/#/details 

would like to check if there is any supported version by splunk ?

 

 

Labels (2)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hi @siuolkl ,

Can you please explain the reason you need to add a certificate?

I would just generate credentials on Azure App Registration and just add in the Add-on configuration UI and that's all.

0 Karma

siuolkl
Explorer

@VatsalJagani  hello thank you for the reply.

the add on is working fine but I am posting this question as my environment requires the use of certificates.

I am not sure if splunk support this method.

 

Also from Microsoft documentation. the option to use cert is more secure compared to client secrets for app registration from azure.

https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-register-app 

 

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@siuolkl - My understanding of this tells me that following the document you have on Microsoft Azure and below for the Add-on should give you what you need.

VatsalJagani_0-1647439238176.png

 

FYI, communication is done by the Add-on, Splunk is not involved here. The screenshot is from the Add-on document.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...