Contact sales
Details

Microsoft Entra ID, formerly known as Azure Active Directory, is an identity and access management solution that helps organizations secure and manage identities in cloud and on-premises environments.

Microsoft Entra ID, formerly known as Azure Active Directory, is an identity and access management solution that helps organizations secure and manage identities in cloud and on-premises environments.

When you configure the Microsoft Entra ID integration, data about your Entra users will become available in the Cisco XDR assets feature. This information is then used to enrich investigations and enhance incident triage with user context. A target will also become available in XDR automation for automated workflows.

Capabilities
Automation
Automatic target creation for Cisco XDR automation
Device Insights
Provides information about assets
Regions
North America
Europe
Asia-Pacific, Japan & China
Installable workflows

These are workflows that you can install in Cisco XDR automation and use with this integration. These are different from built-in workflows which are built into Cisco XDR by default for all customers.

Cisco Managed
This workflow appears in the pivot menu and allows you to disable a user in Microsoft Entra ID using their email or username.
Cisco Managed
This incident response workflow allows you to disable one or more users in Microsoft Entra ID from a playbook.
Cisco Managed
This workflow appears in the pivot menu and allows you to enable a user in Microsoft Entra ID using their email or username.
Cisco Managed
This incident response workflow allows you to enable one or more users in Microsoft Entra ID from a playbook.
Built-in workflows

These workflows are built into Cisco XDR automation and can be used with this integration. These are different from installable workflows, which are optional workflows you can install from Cisco and its partners.

Built-in actions

These actions can be used in Cisco XDR automation to build workflows for this product. Workflows can help you automate how you investigate, respond to incidents, and more.

Configuration details