Defender for Endpoint Device Backup
CONFIG365 backs up the full Microsoft Defender for Endpoint (MDE) device inventory to the tenant Git repository on every backup pipeline run. The web portal reads this data to identify devices that do not meet app protection policy requirements, enabling targeted user notifications.
How It Works
The backup pipeline runs scripts/backup/Backup-DefenderDevices.ps1 as
a pipeline step. The script authenticates to the MDE API using a delegated token from the CONFIG365 token-api
(same Graph access app and tenant Connect refresh token — no separate app registration or client-credentials flow),
fetches all machines and their logon users, and writes the results as JSON files into the tenant repo.
Authenticate
Delegated refresh-token exchange via the CONFIG365 token-api for
https://api.securitycenter.microsoft.com/.default.
Requires Machine.Read delegated permission plus an MDE role on the signed-in admin.
Fetch All Machines
Pages through GET /api/machines until all records are retrieved, then fetches
GET /api/machines/{id}/logonusers for each device to associate user principal names.
Write to Tenant Repo
Splits the device list by platform and writes JSON files to
backups/defender-devices/ in the tenant Git repository, committed and pushed as part of the backup pipeline.
API Permission Required
Grant this permission on the same app registration used for Microsoft Graph. No separate MDE app registration is needed.
| Permission | Type |
|---|---|
Machine.Read | Delegated |
How to add in Azure Portal
- 1. Go to Entra ID → App registrations → [your app] → API permissions
- 2. Click Add a permission → APIs my organization uses
- 3. Search for
WindowsDefenderATPor use App IDfc780465-2017-40d4-a0c5-307022471b92 - 4. Select Delegated permissions → check
Machine.Read - 5. Click Grant admin consent
Tenant-level consent: This permission must be granted in each managed tenant — not just the MSP tenant. Admin consent for MDE follows the same process as the Graph permissions granted during tenant onboarding.
Backup Output
Files written to backups/defender-devices/ in the tenant repo after each backup pipeline run.
| File | Contents |
|---|---|
all-devices.json | Every device across all platforms |
ios-devices.json | iOS / iPadOS devices only |
android-devices.json | Android devices only |
windows-devices.json | Windows devices only |
macos-devices.json | macOS devices only |
other-devices.json | All other / unclassified platforms |
Device Record Shape
Key fields present in each device object within the JSON files.
| Field |
|---|
id |
computerDnsName |
osPlatform |
osVersion |
lastSeen |
riskScore |
exposureLevel |
healthStatus |
logonUsers |
App Protection Integration
The CONFIG365 portal's App Protection page reads ios-devices.json and
android-devices.json from the tenant repo to identify devices whose
osVersion falls below the new policy minimum.
Impacted Device Detection
The portal compares osVersion from the backup against the required minimum version entered by the admin.
Devices with a lower version are listed as impacted and can be exported as CSV.
Email Notifications
User email addresses are derived from logonUsers[].userPrincipalName on each impacted device.
The portal schedules a mobile-patch-warning email to all unique recipients,
sent via the SMTP credentials stored in the CONFIG365 portal platform settings.
Data freshness: The portal always reads from the latest backup commit. Run the backup pipeline on demand if you need up-to-date device data before scheduling notifications.