category: Analytics & SIEM provider: Microsoft sectionorder: - Connect - Collect commonfields: id: Microsoft 365 Defender Event Collector version: -1 configuration: - additionalinfo: |- When selecting the Custom option, the Server URL parameter must be filled. More information can be found on the integration page - https://xsoar.pan.dev/docs/reference/integrations/microsoft-365-defender-event-collector defaultvalue: Worldwide display: Endpoint Type name: endpoint_type type: 15 section: Connect options: - Worldwide - EU Geo Proximity - UK Geo Proximity - US Geo Proximity - US GCC - US GCC-High - DoD - Custom advanced: true required: false - display: Tenant ID name: tenant_id required: true type: 0 section: Connect advanced: false - name: client_id required: true type: 0 section: Connect additionalinfo: The Client (Application) ID to use to connect. display: Client (Application) ID - name: credentials required: true type: 9 section: Connect displaypassword: Client Secret hiddenusername: true - defaultvalue: 3 days display: First fetch timestamp (