Security

Defender for Endpoint Device Backup

CONFIG365 backs up the full Microsoft Defender for Endpoint (MDE) device inventory to the tenant Git repository on every backup pipeline run. The web portal reads this data to identify devices that do not meet app protection policy requirements, enabling targeted user notifications.

MDE APIDevice InventoryApp ProtectionBackup PipelineMachine.Read

How It Works

The backup pipeline runs scripts/backup/Backup-DefenderDevices.ps1 as a pipeline step. The script authenticates to the MDE API using a delegated token from the CONFIG365 token-api (same Graph access app and tenant Connect refresh token — no separate app registration or client-credentials flow), fetches all machines and their logon users, and writes the results as JSON files into the tenant repo.

1

Authenticate

Delegated refresh-token exchange via the CONFIG365 token-api for https://api.securitycenter.microsoft.com/.default. Requires Machine.Read delegated permission plus an MDE role on the signed-in admin.

2

Fetch All Machines

Pages through GET /api/machines until all records are retrieved, then fetches GET /api/machines/{id}/logonusers for each device to associate user principal names.

3

Write to Tenant Repo

Splits the device list by platform and writes JSON files to backups/defender-devices/ in the tenant Git repository, committed and pushed as part of the backup pipeline.

API Permission Required

Grant this permission on the same app registration used for Microsoft Graph. No separate MDE app registration is needed.

Permission Type
Machine.Read Delegated

How to add in Azure Portal

  1. 1. Go to Entra ID → App registrations → [your app] → API permissions
  2. 2. Click Add a permission → APIs my organization uses
  3. 3. Search for WindowsDefenderATP or use App ID fc780465-2017-40d4-a0c5-307022471b92
  4. 4. Select Delegated permissions → check Machine.Read
  5. 5. Click Grant admin consent

Tenant-level consent: This permission must be granted in each managed tenant — not just the MSP tenant. Admin consent for MDE follows the same process as the Graph permissions granted during tenant onboarding.

Backup Output

Files written to backups/defender-devices/ in the tenant repo after each backup pipeline run.

File Contents
all-devices.json Every device across all platforms
ios-devices.json iOS / iPadOS devices only
android-devices.json Android devices only
windows-devices.json Windows devices only
macos-devices.json macOS devices only
other-devices.json All other / unclassified platforms

Device Record Shape

Key fields present in each device object within the JSON files.

Field
id
computerDnsName
osPlatform
osVersion
lastSeen
riskScore
exposureLevel
healthStatus
logonUsers

App Protection Integration

The CONFIG365 portal's App Protection page reads ios-devices.json and android-devices.json from the tenant repo to identify devices whose osVersion falls below the new policy minimum.

Impacted Device Detection

The portal compares osVersion from the backup against the required minimum version entered by the admin. Devices with a lower version are listed as impacted and can be exported as CSV.

Email Notifications

User email addresses are derived from logonUsers[].userPrincipalName on each impacted device. The portal schedules a mobile-patch-warning email to all unique recipients, sent via the SMTP credentials stored in the CONFIG365 portal platform settings.

Data freshness: The portal always reads from the latest backup commit. Run the backup pipeline on demand if you need up-to-date device data before scheduling notifications.