Entra app registration
Setting up the Entra app registration
Section titled “Setting up the Entra app registration”xdr can instead authenticate as you through an app registration in your
tenant, over Microsoft’s supported APIs. One registration can be shared by
everyone on the team.
-
Azure Portal → Microsoft Entra ID → App registrations → New registration. Name it (
xdr-cli), choose Single tenant, and add a Public client/native redirect URI ofhttp://localhost. If anyone will sign in on Windows, also addms-appx-web://Microsoft.AAD.BrokerPlugin/<client-id>(your application ID from step 2), which the Windows sign-in broker (WAM) requires. -
From Overview, copy the Application (client) ID and Directory (tenant) ID.
-
API permissions → Add a permission. Add these delegated permissions:
API Permission Used by Microsoft Graph SecurityIncident.ReadWrite.Allincidents list/show/update,investigateMicrosoft Graph SecurityAlert.Read.Allalerts list/showMicrosoft Graph ThreatHunting.Read.Allhunt run,library run,investigate,schemaMicrosoft Graph Domain.Read.AllEntra portion of domains listWindowsDefenderATP¹ Machine.Readdevice show,device action-status, hostname lookupsWindowsDefenderATP Machine.Isolatedevice isolate/unisolateWindowsDefenderATP Machine.Scandevice scanWindowsDefenderATP Machine.CollectForensicsdevice collect-packageWindowsDefenderATP Machine.RestrictExecutiondevice restrict,device unrestrictWindowsDefenderATP AdvancedQuery.ReadHunting fallback only (see below) ¹ Under APIs my organization uses, search for WindowsDefenderATP. Defender for Endpoint tokens are still issued for the
api.securitycenter.microsoft.comaudience even though requests go toapi.security.microsoft.com; that is why these live under WindowsDefenderATP rather than Microsoft Graph.The minimum for the quick start above is the first three Graph rows plus
Machine.Read(used byinvestigateto enrich devices). Grant only what the commands you intend to use need.device download-packageand the Active Directory part ofdomains listhave no official API and stay cookie-only.Hunting goes through Microsoft Graph. If Graph hunting returns 403 or 404,
xdrretries the query once against the Defender for Endpoint hunting API (api.security.microsoft.com/api/advancedqueries/run), which needsAdvancedQuery.Readand only sees Defender for Endpoint tables. Microsoft began retiring that API in January 2026, so configure Graph hunting and treat the fallback as temporary. -
Grant admin consent for your tenant. Every permission above is delegated, so a Cloud Application Administrator, Application Administrator, or Privileged Role Administrator can grant it (Microsoft’s requirements). Security Administrator alone cannot. The service-principal setup described under Configuration uses Microsoft Graph application permissions, which need Privileged Role Administrator.
-
Authentication → Advanced settings → Allow public client flows → Yes.
-
Sign in. This opens an interactive sign-in (the WAM broker on Windows, your browser elsewhere); if neither can start, e.g. on a headless host, it prints a device code instead.
tenant_idandclient_idare saved to~/.xdr-cli/config.toml.Terminal window xdr auth login --tenant-id <TENANT_ID> --client-id <CLIENT_ID>xdr auth status # main.backend: official
The signed-in user also needs the Defender roles that match what they run (Security Reader for triage; Active remediation actions for device actions). The app registration cannot grant more than the user has.
If you add a permission after signing in, run xdr auth logout && xdr auth login afterwards. Until then xdr keeps using the cached access token
issued before the change, and the new permission fails with
PERMISSION_MISSING_SCOPE until that token expires (up to about 90 minutes).