Microsoft
Enriching OT and IT asset visibility in Nozomi Vantage with endpoint security, software inventory and vulnerability data from Microsoft Defender for Endpoint.

Microsoft Defender for Endpoint is a endpoint security platform delivering preventative protection, post-breach detection, automated investigation and response across Windows, Linux, macOS, Android, iOS and IoT devices. By integrating Microsoft Defender for Endpoint with Nozomi Vantage, security teams gain a consolidated view of managed assets across IT and OT environments — importing endpoint security, software inventory and vulnerability data directly into Vantage. This enriches the asset registry with authoritative data from the Microsoft management plane, accelerating incident investigation, reducing blind spots in critical infrastructure environments and enabling analysts to correlate edr xdr telemetry with OT network observations without switching consoles.

Features
Importer Data Types
Asset Details Enrichment and Create New in Vantage
Asset Software Inventory Import
Asset CPE and CVE Import
Joint Use Cases
Correlating Microsoft signals with OT network alerts
Closing asset inventory gaps across IT and OT
Prioritizing vulnerability remediation on critical OT assets
Integration Prerequesites
- Active Nozomi Vantage tenant with the connector-configuration role assigned to the administering account
- Microsoft Defender for Endpoint Plan 2 (or Defender Vulnerability Management add-on) with an Entra ID app registration granted the Machine.Read.All and Vulnerability.Read.All API permissions
- Microsoft Defender for Endpoint license tier and feature set that includes software-inventory collection
- Microsoft Defender for Endpoint module or license that produces per-asset CVE findings enabled in the source tenant
- Consistent hostname, IP or MAC addressing between Microsoft Defender for Endpoint-recorded assets and Vantage-observed assets to enable accurate asset correlation and deduplication

