Defender for Cloud integration update (effective Jan 25, 2026):
Zscaler MDR no longer supports creating the standalone Defender for Cloud integration described below. If you set up this integration before January 25, 2026, it remains active and appears as an alert data source on the Integrations page. New customers must instead set up the Azure integration, which includes configuring automated export of Defender for Cloud alerts and synchronization of alert states.
The Defender for Cloud integration enables Zscaler MDR to ingest and analyze Azure Cloud alerts, helping you identify and respond to a wide range of suspicious cloud activity.
This integration guide is intended to connect Zscaler MDR with a single Azure subscription that’s using Microsoft Defender for Cloud. If you have multiple Azure subscriptions associated with Defender for Cloud, you’ll need to set up a separate integration in Zscaler MDR for each subscription.
Prerequisites
Before you start the Defender for Cloud integration, please make sure the following requirements are met:
You’re an Azure Global Admin user
You consent to granting Zscaler MDR the required permissions to ingest Microsoft data
You have an active Microsoft subscription that includes a Defender for Cloud workload. To check if your subscription plan includes Defender for Cloud, refer to Microsoft's Subscription Matrix.
1 Zscaler MDR | Add the Integration
In the Zscaler MDR portal, go to the Integrations page, then click Add Integration.

On the Add integration dialog, search for “Defender for Cloud” and click Configure.

On the Zscaler MDR configuration page, enter a name for the integration.

2 Zscaler MDR | Choose How Zscaler MDR Will Receive This Data
On the Zscaler MDR configuration page, set Ingest Format / Method to Microsoft Defender for Cloud via API Poll.

Click Next.
3 Azure/Zscaler MDR | Configure Zscaler MDR to Retrieve Data from This Integration
Sign in to the Azure portal using a Global Admin account for the tenant you plan to integrate with Zscaler MDR.
In the search bar, type and select Subscriptions.
Identify a subscription connected to Defender for Cloud and copy the Subscription ID.
Note
If you have multiple Azure subscriptions connected to Defender for Cloud, you’ll need to create an integration for each subscription, even if they all share the same Tenant ID.

Return to Zscaler MDR and paste it into Microsoft Defender for Cloud Subscription ID.

In the Azure search bar, type and select Tenant properties.
Copy the Tenant ID.

Return to Zscaler MDR and paste it into Microsoft Defender for Cloud Tenant ID.

Click this consent link to grant Zscaler MDR access to your Microsoft tenant.
Note
You must be a Global Admin Azure user to successfully grant permissions to Zscaler MDR.
To learn more about which permissions we require, see Permission Requirements for Microsoft.

Check the Confirm Microsoft Defender For Cloud API Access Granted box.

Copy the Zscaler MDR ARM template and save it in a local file.

In Azure, search for and select Service providers.
Click Service Provider Offers, then Add offer > Add via template.

Upload the ARM template and click Upload.
On the Custom deployment page:
From the Subscription dropdown, select the subscription with which Defender for Cloud is associated.
Note
If you have multiple Azure subscriptions connected to Defender for Cloud, you’ll need to create an integration for each subscription, even if they all share the same Tenant ID.
From the Region dropdown, select the region in which your Defender for Cloud instance is deployed.

Click Review + create.
Note
If you receive an error, it may be because you do not have Global Admin user permissions.
4 Zscaler MDR | Customize How Data From This Integration is Handled
[OPTIONAL] Check the Enable process correlation for user-defined alerts box to enable Process Correlation, which allows Zscaler MDR to correlate user-defined alerts from Defender for Cloud with our rule metadata when displaying them in the timeline.

[OPTIONAL] In the Actions in the Source Platform section, you can disable or enable alert actions to control how Zscaler MDR engages with alerts. These settings manage how Zscaler MDR engages with alerts. The table below describes the outcome of each setting when enabled.
Setting
Default State
Outcome
As Zscaler MDR validates the alert
Enabled
When enabled, Zscaler MDR adds comments to the alert in notifying users of the current investigation status as the alert is investigated and resolved.
When Zscaler MDR validates the alert as non-threatening
Enabled
When enabled, Zscaler MDR resolves the alert as
Informationalif the state is Not a Threat.When Zscaler MDR validates the alert as suspicious
Disabled
When enabled, Zscaler MDR resolves the alert as
True Positiveif the state isSuspicious,Highly Suspicious, orThreatbut no threat has been published.When Zscaler MDR publishes a threat involving the alert
Enabled
When enabled, Zscaler MDR resolves the alert as
True Positiveif the state isThreatand a threat has been published.
Click Next.
5 Zscaler MDR | Customize How This Data Is Retained
[OPTIONAL] If you’re subscribed to the Zscaler MDR Security Data Lake, you can choose to copy the telemetry generated by the integration to long-term storage for later query or retrieval:
Check the Store in the Security Data Lake box.
Enter your desired data retention period in days. The maximum is 1095 days (three years).

6 Zscaler MDR | Activate the Integration
After you’ve completed the configuration, click Save to activate the integration.
The Defender for Cloud integration is now live!
Data will appear in Zscaler MDR on the Integrations page.
7 Zscaler MDR | Modify the Integration
After the Defender for Cloud integration is active, you can make the following modifications to the configuration:
Update the API configuration used by the integration
Adjust the Security Data Lake retention period
Decommission the integration
To modify the configuration:
In the Zscaler MDR portal, go to the Integrations page, then click on the name of the integration you want to modify.

After you’ve finished editing the configuration, click Save to apply your changes.
Deleting the Integration
To delete the integration from Zscaler MDR, click the
button, then click OK to confirm.
Important
Deleting the integration will prevent any new alerts from being sent to Zscaler MDR. While existing threat data will remain, all processed alerts will be permanently deleted, and this action cannot be undone.
For this reason, we recommend deactivating the integration instead, which will retain all previously processed alerts but stop further ingestion. You can reactivate the integration at any time.