Skip to main content

Documentation Index

Fetch the complete documentation index at: https://help.dsalta.com/llms.txt

Use this file to discover all available pages before exploring further.

Overview

DSALTA connects to Microsoft Defender for Endpoint using read-only API access to collect compliance evidence automatically. Data syncs every 24 hours and feeds into your Data Library modules.
Read-only access. DSALTA never modifies, creates, or deletes resources in your Microsoft Defender for Endpoint environment.

How to Connect

  1. Go to Integrations in the DSALTA sidebar.
  2. Find Microsoft Defender for Endpoint and click Connect.
  3. Authenticate with admin-level access.
  4. Select the scope (accounts, projects, or resources to monitor).
  5. DSALTA performs an initial sync (5–15 minutes). Tests activate after sync completes.

Automated Compliance Tests

TestDescription
Device encryption should be enabledChecks that disk encryption is enabled on all devices managed by Microsoft Defender.
Screen lock should be enabled on devicesChecks that screen lock is enabled on all devices managed by Microsoft Defender.
OS should be up to dateChecks that the OS is up to date on all Defender-managed devices.
User access to critical systems should be validChecks that users with access to critical systems are authorized in Microsoft Defender.

Troubleshooting

Re-authenticate from Integrations → Microsoft Defender for Endpoint → Reconnect. This usually happens when API tokens expire.
Verify the connected account has admin permissions. Try a manual sync from the integration settings.