Zscaler MDR’s integration with the Microsoft Defender for Endpoint (MDE) platform begins with our deep integration with the Microsoft Defender for Endpoint product and a standard data exchange initially created in partnership between our engineering teams.
While most Defender for Endpoint integrations are focused on the alerts generated by the platform, Zscaler MDR’s low-level integration ingests both the alerts and raw telemetry generated by the Defender for Endpoint sensor. This telemetry is processed and analyzed by the Zscaler MDR platform and our Cyber Incident Response Team (CIRT) to confirm and investigate threats while eliminating false positives.
This combination of Defender for Endpoint alerts, telemetry, and Zscaler MDR’s detection and response delivers the best security outcomes for Microsoft Defender for Endpoint users.
How it works
Zscaler MDR and Microsoft Defender for Endpoint use several integration points to implement exceptional security operations:

Getting started
Note: Minimum requirements for Defender for Endpoint can be found here.
Connect your Defender for Endpoint deployment to Zscaler MDR by following these simple steps:
Set up data export from your Defender for Endpoint instance to Zscaler MDR’s Azure event hub. This configuration instructs the Defender platform to send your telemetry to Zscaler MDR for processing.
Grant Zscaler MDR permissions to your Defender for Endpoint API. This enables the Zscaler MDR platform to retrieve alerts and endpoint metadata and orchestrate actions on endpoints.
Grant your Zscaler MDR threat hunter read-only access to your Microsoft Defender console. This enables your threat hunter to perform ad-hoc hunting and investigation of potential threats in your environment.
Learn more about how to set up Defender for Endpoint with Zscaler MDR. This process generally takes 4-6 hours to configure and confirm data is flowing properly.
FAQ
How does MDE Data get into the Azure Event Hub?
MDE Endpoint Detection and Response (EDR) streams telemetry data in near real-time to the Microsoft Security Center with which it is configured to communicate.
Note: This step is part of the standard Microsoft offering; Zscaler MDR is not involved yet.
Security Center then sends individual telemetry messages to an Azure Event Hub, which Zscaler MDR provisions and maintains for your organization within Zscaler MDR’s Azure environment. Azure bundles those messages and temporarily saves them in a dedicated Azure Storage blob.
How does the Data in the Event Hub get into Zscaler MDR?
Once the data is saved successfully, an Azure function triggers the Zscaler MDR application within AWS to request and collect that data from Azure via an API request.
Data is not stored long-term in Azure. Once collected by the Zscaler MDR app, the telemetry messages age out of the Azure platform after a few days.
What kind of Microsoft data does Zscaler MDR process?
We receive all of the data collected by your Defender for Endpoint sensors and a number of system events generated by the Microsoft platform. As Microsoft continues developing APIs in its XDR suite, Zscaler MDR will receive additional telemetry and alert types from other Microsoft security platforms.
What happens to my Microsoft alerts when I activate Zscaler MDR?
Zscaler MDR processes every alert generated by Defender for Endpoint detection rules to determine if the alert is a true or false positive. Zscaler MDR’s investigation of these alerts adds additional context to confirmed alerts to accelerate your response.
You can enable alert synchronization to automatically update and close the alerts in the MDE platform once Zscaler MDR has completed our review to keep your console tidy.
Can I also export the data collected by Microsoft?
Absolutely. You can either set up another export directly out of MDE or use Canary Exporter to export Microsoft telemetry from Zscaler MDR that has been ingested and standardized into your SIEM, long-term storage, or another processing pipeline. Learn more about Export data from Zscaler MDR.