# Microsoft Defender

**Canonical:** https://apis.io/providers/microsoft-defender/  
**Website:** https://security.microsoft.com  
**APIs profiled:** 9

Collection of Microsoft Defender security APIs for threat protection, endpoint security, and security operations.

## Kin Score — 38.3 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 38.3).

| Facet | Score |
|---|---|
| Discoverability | 37.0 |
| Contract Quality | 73.4 |
| Governance | 9.8 |
| Contract Governance | 9.8 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 21.4 |
| Commercial Clarity | 36.8 |
| Access Clarity | 36.8 |

## Agent readiness — 35.0 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | no |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Freemium · Self-serve signup — onboarding: self-serve, pricing: freemium, trial: no (confidence: high).

## APIs (9)

- **Microsoft Defender for Cloud Apps API** — Cloud Access Security Broker (CASB) API for discovering, investigating, and governing cloud apps.
- **Microsoft Defender Threat Intelligence API** — Access threat intelligence data, indicators of compromise (IOCs), and threat analytics.
- **Microsoft Defender for Office 365 API** — API for email and collaboration protection including anti-phishing, anti-malware, and safe attachments.
- **Microsoft Defender XDR API** — Unified extended detection and response API for automating workflows based on shared incident and advanced hunting tables across Microsoft security products.
- **Microsoft Defender for Cloud REST API** — REST API for unified security management and advanced threat protection across hybrid cloud workloads in Azure, other clouds, and on-premises.
- **Microsoft Defender for Identity API** — API for identity-based attack detection and investigation across on-premises Active Directory and hybrid environments, with sensor management via Microsoft Graph.
- **Microsoft Defender Alerts API** — Manage security alerts generated by Microsoft Defender for Endpoint. Alerts represent detected threats, suspicious activities, and security events on endpoints.
- **Microsoft Defender Machines API** — Manage devices (machines) that have communicated with Microsoft Defender for Endpoint. Retrieve device information, health status, risk scores, and exposure levels.
- **Microsoft Defender Vulnerabilities API** — Retrieve vulnerability information from Microsoft Defender Vulnerability Management. Access CVE data, severity scores, exploit information, and exposure metrics.

## Agentic access (1)

- **Microsoft Defender Agentic Access** — 10 operations · 1 acting

## Security (3)

- **Microsoft Defender Authentication** — oauth2 · 1 scheme
- **Microsoft Defender Domain Security** — TLSv1.3 · HSTS · DMARC
- **Microsoft Defender Vulnerability Disclosure** — security.txt · contact published

## Plans (1)

- **Microsoft Defender Plans Pricing**

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/microsoft-defender/). Scores are computed from the provider's own public artifacts under a published rubric.
