Cloud Workload Protection (CWP) Integration

Microsoft Defender for Cloud alerts on your phone

PocketSOC connects to Microsoft Defender for Cloud through an Azure app registration with appropriate RBAC. Responders can view Defender for Cloud security alerts across Azure subscriptions and update alert status — dismiss, resolve, or reactivate — from iOS or Android. Useful when a misconfiguration or runtime threat needs immediate triage outside business hours.

Defender for Cloud raises a high-severity alert on a production subscription after hours. Your phone gets the push, you open the alert — affected resource, alert description, recommended actions — and triage it on the spot. No laptop, no VPN, no Azure Portal login.

Supported actions for Defender for Cloud

Authentication and credentials

Microsoft Defender for Cloud uses an Azure app registration with the appropriate Azure RBAC role at the subscription scope. PocketSOC supports either Delegated permissions (user_impersonation) or Application permissions with the Security Reader or Security Admin role. Subscription scope is bound to the credential — you can grant access to only the subscriptions you want PocketSOC to surface.

How PocketSOC authenticates to security platforms · Where credentials are stored · Trust Center

Connect Defender for Cloud in about 2 minutes

Create an app registration in Microsoft Entra, assign it the Security Reader role at the subscription scope, and paste the Tenant ID, Client ID, Client Secret, and Subscription ID into PocketSOC. Viewing is free, and the reader role is all you need to start — grant broader rights later only if you adopt Pro response actions.

  1. In Azure Portal, go to App registrations → New registration
  2. Add user_impersonation (Delegated) or assign Security Reader/Admin RBAC role at the subscription scope
  3. Capture Tenant ID, Client ID, and Subscription ID
  4. Create a client secret if using Application permissions
  5. In PocketSOC, enter Tenant ID, Client ID, Client Secret, and Subscription ID

See the full Quick Start guide for Organization-mode setup with the PocketSOC Portal.

Free vs Pro

Free — unlimited viewing

  • Unlimited viewing of Defender for Cloud alerts across subscriptions
  • Full alert detail with resource context and recommended actions
  • Cross-vendor correlation across your connected platforms
  • Your first connected vendor profile

Pro — take action

$9.99/month or $99.99/year, with a 7-day free trial.

  • Change alert status — dismiss, resolve, or reactivate
  • Assign and set disposition on alerts
  • Cross-vendor containment
  • Push notifications for high-severity cloud alerts
  • Additional vendor connections

See full pricing and plans including Organization mode for teams.

Your credentials stay on your device

In Personal Use mode, your Microsoft API credentials are stored in the device Keychain and every API call goes directly from your phone to Microsoft's API. Requests never route through PocketSOC servers — there is no proxy or relay in the data path. Read how we verify that claim on the Security & Architecture page.

Defender for Cloud integration FAQ

Which Defender for Cloud subscriptions are visible?

Only the subscriptions where the Azure app registration has Security Reader or Security Admin role assignments. You can scope PocketSOC to a single subscription, a management group, or any subset of your Azure estate by managing role assignments in Azure RBAC.

Can PocketSOC remediate cloud misconfigurations?

No. PocketSOC surfaces Defender for Cloud alerts and allows status changes (dismiss / resolve / reactivate). Remediation actions on the underlying Azure resources happen in Azure itself; PocketSOC does not modify resource configurations. This is intentional — see our stance on automation.

Does PocketSOC use Microsoft Graph?

For Defender for Cloud, PocketSOC uses the Microsoft Defender for Cloud REST API directly. Microsoft Graph is not required for this integration.

See the full PocketSOC FAQ covering all vendors and security topics.