Microsoft Defender Machines API
Manage devices (machines) that have communicated with Microsoft Defender for Endpoint. Retrieve device information, health status, risk scores, and exposure levels.
Documentation
Documentation
https://learn.microsoft.com/en-us/defender-endpoint/api/apis-intro
Authentication
https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-create-app-webapp
APIReference
https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-list
Documentation
https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview
Specifications
Schemas & Data
Other Resources
JSONLD
https://raw.githubusercontent.com/api-evangelist/microsoft-defender/refs/heads/main/json-ld/microsoft-defender-context.jsonld
Pricing
https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint-pricing
ReleaseNotes
https://learn.microsoft.com/en-us/defender-endpoint/api/api-release-notes
Management APIs
https://learn.microsoft.com/en-us/defender-endpoint/api/management-apis
Alerts API
https://learn.microsoft.com/en-us/defender-endpoint/api/get-alerts
Vulnerabilities API
https://learn.microsoft.com/en-us/defender-endpoint/api/get-all-vulnerabilities
Security Recommendations API
https://learn.microsoft.com/en-us/defender-endpoint/api/get-security-recommendations
SDKs
https://learn.microsoft.com/en-us/graph/sdks/sdks-overview
Code Samples
https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview#common-use-cases