ContraForce Integration with Microsoft Defender XDR
Reviewed by ContraForce Security Operations Team ยท Updated 2026-08-12
The ContraForce integration with Microsoft Defender XDR turns Defender incidents into governed security-delivery work. Defender remains the detection and response control. ContraForce applies the provider's Gamebook, gathers supported evidence, records a verdict, routes approvals, executes permitted actions, and synchronizes the service record.
Integration boundary
| System | Responsibility |
|---|---|
| Microsoft Defender XDR | Detection, incident correlation, security evidence, and supported response controls |
| ContraForce | Investigation procedure, action governance, multi-tenant delivery, evidence record, ticketing, reporting, and tuning workflow |
| Human operator | Policy ownership, approval of consequential actions, exception handling, and customer accountability |
Delivery flow
- Defender XDR creates or updates an incident.
- ContraForce receives the eligible incident through the configured tenant connection.
- A Security Delivery Agent follows the assigned Gamebook and queries approved evidence.
- The agent records observations and reaches an auditable verdict.
- Low-risk actions may run automatically; controlled actions stop for approval.
- The final outcome and evidence synchronize to the configured service workflow.
Multitenant access
Microsoft's multitenant management model respects permissions granted by each managed tenant. Providers should grant only the roles and actions required for the agreed service. See Microsoft Defender multitenant management requirements.
Controls to validate
- Tenant connection and delegated relationship
- Read permissions for incidents, alerts, identities, devices, and relevant evidence
- Write permissions for incident state and comments
- Separate permission for containment or remediation actions
- Customer-specific approval gates
- Ticket board, priority, and closure mapping
- Failure behavior when an API, credential, or evidence source is unavailable
Proof-of-value test
Use an approved benign incident or simulation. Verify that the incident is acquired, the correct Gamebook runs, evidence remains tenant-scoped, the response authority is enforced, the ticket receives the expected record, and every action is attributable.
Related pages
Sources and review method
Product capabilities were reviewed against primary sources on 2026-08-12. ContraForce performance figures are product telemetry, not independent industry benchmarks.