Configure
Console route · /integrations
Integrations
Connector registry, health, sync entry points, and guided setup. Microsoft Sentinel is the first fully in-console credentialed path; other kinds are registered with setup guides. Unavailable registry responses show honest banners — not fake healthy connectors.
Registry and sync
Integrations lists connector kinds, route (live versus evaluation), status, and configure links. The sync panel can trigger Sentinel sync, Defender sync, and NDR graph rebuild when live credentials exist. If the registry cannot be loaded, the UI shows an honest banner rather than a wall of green healthy tiles.
Setup . /integrations/connect
Microsoft Sentinel presents a credential form (directory tenant, client, secret, subscription, resource group, workspace) with save, validate, and disable. Other registered kinds . Defender XDR family, AWS, Okta, CrowdStrike, Splunk, Wazuh, and similar — open guided setup with external documentation links and a return path to Integrations. Unknown connector ids show an error panel instead of a blank form.
Current connector honesty
Workspace can pause/resume connectors for day-to-day ops once they exist. Coarse health checks may still share Azure validation across some Microsoft routes — treat detailed per-connector health as evolving. Hunt Ledger and detections that depend on real telemetry will look empty until connectors actually deliver events.
| Kind | In-console credentials today |
|---|---|
| Microsoft Sentinel | Yes — persist, validate, disable, sync |
| Defender XDR / Endpoint / Identity / Cloud Apps / Office 365 | Guide-first |
| AWS, Okta, CrowdStrike, Splunk, Wazuh | Guide-first |