Skip to content

Microsoft Defender for Endpoint integration

The Block in Defender for Endpoint rule response submits each lookalike domain a matched rule cites to Microsoft Defender for Endpoint as a Block indicator that expires after seven days. The rule decides which alerts trigger the response. Connecting a tenant alone blocks nothing.

  • Microsoft Defender for Endpoint Plan 1 or Plan 2, or Microsoft Defender for Business, with the devices to protect onboarded.
  • A Global Administrator, Privileged Role Administrator, or Cloud Application Administrator in Microsoft Entra ID to grant admin consent.
  • Custom network indicators turned on in the Microsoft Defender portal under Settings > Endpoints > Advanced features. Without it, Defender stores the indicators but does not enforce them.
  • Network protection in block mode on devices. Microsoft Edge on Windows enforces domain indicators through Microsoft Defender SmartScreen; other browsers and processes need network protection.
  • The network enforcement add-on on the Have I Been Squatted organization, and an organization admin to configure it.

Have I Been Squatted uses one multi-tenant Microsoft Entra application for this integration, separate from the Microsoft 365 Email Intelligence application. Consent grants it:

Permission API Type Purpose
Ti.ReadWrite WindowsDefenderATP Application Submit and renew indicators
User.Read Microsoft Graph Delegated Sign-in only, to identify the tenant

Microsoft describes Ti.ReadWrite as “Read and write IOCs belonging to the app”, where IOCs are indicators of compromise. It limits the application to indicators it created. It cannot see or change indicators created by people or by other applications, and it has no access to devices, alerts, incidents, or tenant settings.

The customer supplies no credential. Have I Been Squatted authenticates with its own application secret and requests a short-lived token for the tenant on each delivery.

  1. In the app, open Connectors > Microsoft Defender for Endpoint.
  2. Select Connect tenant and sign in as an administrator who can grant admin consent.
  3. Review the requested permissions and accept them on behalf of the organization.
  4. Microsoft returns to the settings page, which runs a connection check.

The tenant is taken from the verified identity token of the administrator who signed in, never from the address bar. A Microsoft tenant can be connected to only one Have I Been Squatted organization. Connecting a tenant held by another organization fails with “This Microsoft tenant is already connected to another organization”.

The check requests the same token delivery uses, confirms that it carries the Ti.ReadWrite role for the tenant, and reads one indicator through the Defender API. Blocking stays off until a check passes. Select Test connection to run it again.

Admin consent can take a few minutes to reach Defender, so the check that runs immediately after connecting may report missing consent. Test the connection again shortly afterward.

Result Meaning
Consent missing Microsoft has not granted admin consent for the tenant yet, or it was revoked. Test again after a few minutes, then reconnect if it persists.
Permission missing The token lacks Ti.ReadWrite, or Defender rejected it. Reconnect with an administrator who can grant admin consent.
Defender unavailable The tenant has no Defender for Endpoint API, usually because it is not licensed or not onboarded.
Unreachable Microsoft timed out, throttled the request, or returned a server error. Test again later.
Configuration The Have I Been Squatted application credential was rejected. This is a platform problem; contact support.

A failed check pauses blocking until a later check passes. Consent and permission failures mark the connection as needing reauthorization.

Indicators apply to every device in the tenant by default. To limit them, enter up to 10 Defender device group names on the settings page, exactly as they appear under Settings > Endpoints > Device groups. Each name can have up to 128 characters and cannot contain commas or control characters. Leave the list empty to block on all devices.

Ti.ReadWrite cannot list device groups, so saved names are not checked against Defender. Changes apply to indicators submitted afterward, including renewals.

  1. Create or edit a rule and open the Response tab.
  2. Select Add action > Block in Defender for Endpoint.
  3. Select the Defender for Endpoint destination.
  4. Save the rule.

The destination is listed only after a connection check has passed. The response needs at least one domain condition in the rule, because only cited lookalike domain records produce indicators; the builder does not save it on a rule with only email or canary conditions.

For each active rule alert that cites lookalike domain records, Have I Been Squatted submits one indicator per distinct cited domain, up to 10 domains per alert:

Field Value
indicatorType DomainName
indicatorValue The cited lookalike domain
action Block
generateAlert true
severity From the rule level: Informational, Low, Medium, or High. Critical rules use High, the highest Defender severity.
expirationTime Seven days after submission
rbacGroupNames The configured device groups; omitted for all devices
title, description Name Have I Been Squatted and the rule
  • Only domains from cited domain (lookalike permutation) records are sent.
  • The monitored domain and its subdomains are never blocked.
  • Email and canary evidence never produce indicators, and no email content, addresses, or canary data is sent.

Defender returns each submitted indicator, and Have I Been Squatted checks that it blocks the submitted domain. A later alert for the same domain submits it again. Defender’s submit API updates an existing indicator with the same value and type, so the resubmission renews the seven-day expiry and applies the current severity and device groups. Nothing renews an indicator while its finding stops alerting.

If Defender refuses one domain, the others are still submitted. If Microsoft times out, returns a server error, or rejects the token, the remaining domains are not submitted and the delivery is not retried.

Have I Been Squatted stores the connected tenant ID, the consent time, the granted permission, the device groups, and the time and outcome of the last connection check. For each alert and response, it records the delivery status, the Defender indicator ID and domain of each applied indicator, the domains Defender refused or that were not submitted, the expiry, and, when a delivery fails, a short error code. Access tokens and Microsoft response bodies are not stored.

Disable stops new indicators and keeps the connection, device groups, and rule responses. A passing connection test turns blocking back on.

Disconnect removes the connection, its device groups, and the Block in Defender for Endpoint response from every rule, along with those responses’ delivery records. The tenant can then be connected to another organization.

Neither action deletes indicators already in Defender. They stay until they expire, within seven days, or until an administrator removes them in the Microsoft Defender portal under Settings > Endpoints > Indicators.

Disconnecting does not revoke the consent. To remove the application’s access, delete the Have I Been Squatted Defender for Endpoint application under Enterprise applications in the Microsoft Entra admin center. Deliveries and connection checks then fail with missing consent.

  • Defender allows 15,000 active indicators per tenant across all sources. Indicators from Have I Been Squatted expire after seven days, so they occupy capacity only for recent alerts.
  • The Defender indicator API allows 100 calls per minute. Each domain uses one submission.
  • Indicators block domains only. They do not block URLs or IP addresses, and enforcement depends on the settings listed under Prerequisites.
  • The integration uses the Microsoft global cloud. Sovereign clouds such as GCC High and DoD are not supported.