Install Guide
Azure Entra App Registration
Log in to the Azure portal, register the Logpresso app, and grant read permission for Defender for Endpoint.
Click the API Permissions menu and select the Add a permission button.
In the new dialog that opens, select WindowsDefenderATP.
Click Application Permissions and add the Alert.Read.All and Machine.Read.All permissions.
Finally, click the Grant admin consent button to complete the permission setup.
Register API Key
Go to the Certificates & Secrets menu, click on the Client Secrets tab, and add a new client secret.
Copy the newly created client secret and store it in a safe location.
Lastly, copy and store the Application (Client) ID and Directory (Tenant) ID in a secure location.
Firewall Policy Setup
Ensure the firewall policies allow Defender for Endpoint to connect to the following endpoints:
- https://login.microsoftonline.com (for OAuth authentication)
- https://api.securitycenter.microsoft.com (for API communication)
Logpresso Connect Profile Setup
Go to the Connect profiles menu and click the Add button. Select the Microsoft Defender for Endpoint profile type and enter the App ID, Tenant ID, and Client Secret to register the new connection profile.
Defender for Endpoint Alert Logger Setup
Select the Defender for Endpoint Alert logger model and enter the connect profile identifier to complete the setup. The default dashboards and datasets refer to the EPP_DEFENDER table.









