> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/cloud-log-forwarding/azure-microsoft/microsoft-defender-atp/enable-siem-integration-in-microsoft-defender-atp.md).

# Enable SIEM integration in Microsoft Defender ATP

This procedure is only necessary if the Windows Defender SIEM Connector has not previously been activated. If the Windows Defender SIEM Connector has already been activated, proceed to the next section.

To activate the Windows Defender SIEM Connector:

1. Follow steps 1 and 2 of the procedure described at

[ https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration)[atp/enable-siem-integration](https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/enable-siem-integration)

2\. Save the Client ID and Client secret for later use; they will be needed in a subsequent procedure. **Note:** the Client secret is displayed only once. Do not leave the

&#x20;SIEM Settings page without saving the Client secret.

###
