This is a Discovery Integration.
This integration collects 30 days of history by default upon first connection.
Number of days is configurable by customer. Ask your Calero representative for more information.
For this integration, the required access (step 4 below) is read only.

Microsoft Graph API Endpoints
For more information, refer to security: runHuntingQuery - Microsoft Graph v1.0 | Microsoft Learn.
This is the only endpoint that is currently used in the Microsoft Defender connector. We query this to get DeviceProcessEvents (process run on the host machine) and to get DeviceNetworkEvents (web URLs accessed).
For the initial fetch we retrieve a month’s worth of events and from that point onwards will fetch every 24 hours.
For the events retrieved we fetch and persist:
Basic information about the process name or URL to help us identify the vendor and application
Timestamp for the event
Email address of the person the event is for
Onboard This Discovery Integration
- Go to SaaS Management > Applications.
- Select Add Integration.
- From the Discovery Apps tab, select the card with the vendor's name.
- From the API tab, select the Authorize button.
- You will be redirected to the vendor portal login page.
- Enter your administrator credentials and sign in.
- Within the vendor portal, authorize the Calero.com application to fetch data.
SUCCESS!
You will now be redirected to the Integrations page in Calero.com, where the data sync will continue in the background, and you can monitor progress.
SUGGESTION:
Access Help through your Calero.com instance if links between articles return errors or if there are fewer sections in the Help menu than expected. Doing so will ensure you see all Help articles.