Skip to main content
DSALTA connects to Microsoft Defender for Endpoint using read-only API access to collect compliance evidence automatically. Data feeds into your Data Library modules.
Read-only access. DSALTA never modifies, creates, or deletes resources in your Microsoft Defender for Endpoint environment.
DSALTA collects this integration’s data when you connect it — you can refresh it at any time with Sync from integrations on the Integrations page. The compliance checks below re-run once a day at 02:00 America/New_York.

What DSALTA reads

DSALTA reads the organization-wide vulnerability (CVE) list that Microsoft Defender Vulnerability Management produces, which appears on your Vulnerabilities page. Each row is one CVE affecting your organization, recorded against the integration as a whole — Defender’s /api/vulnerabilities response is a per-CVE summary and does not name the affected devices, so DSALTA cannot attribute a finding to an individual endpoint. This integration does not collect a user roster or a device roster.It calls these Microsoft Defender for Endpoint endpoints:
  • /api/vulnerabilities
Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Microsoft Defender for Endpoint environment.

Troubleshooting

There is no Reconnect button. Open Integrations → Connected, click Manage on the Microsoft Defender for Endpoint card, and check the Status tab — it shows either Connected and working properly or Connection issues detected. To restore a broken connection you must Disconnect and connect again, which permanently deletes the data and tests collected from Microsoft Defender for Endpoint. This usually happens when API tokens expire.
Verify the connected account still holds the permissions this integration requires. Then open Integrations in the DSALTA sidebar, stay on the Connected tab, and click Sync from integrations at the top right. That button refreshes every connected integration at once — there is no per-integration sync control.