# MS Defender for Endpoint integration

**URL:** <https://discuss.elastic.co/t/ms-defender-for-endpoint-integration/381572>\
**Category:** Elastic Agent\
**Created:** [September 3, 2025, 4:55pm UTC](https://discuss.elastic.co/t/ms-defender-for-endpoint-integration/381572 "2025-09-03T16:55:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bbreer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bbreer/32/130059_2.png) [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Post date:** [September 3, 2025, 4:55pm UTC](https://discuss.elastic.co/t/ms-defender-for-endpoint-integration/381572/1 "2025-09-03T16:55:16Z")

</div>

After upgrading to 8.19.2, the MS Defender for Endpoint integration said Reauthorization required. It worked fine before the upgrade.

 ![reauthorizarion_required](https://us1.discourse-cdn.com/elastic/original/3X/a/e/aee2ed5f9c1bc2984931fc7fb0b61bc4d302140d.png)

When I click on that integration and then click on the Assets tab, it says the installation has been deferred and wants a _Transforms_ reauthorized.

 ![integration](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fbc074c57b654552c9b060efe1c7d3b2db348779.png)

When I click the _Reauthorize_ or the _Reauthorize all_ buttons or the it fails.

 ![authorize0](https://us1.discourse-cdn.com/elastic/original/3X/1/4/14b13b17eb8c3e875588c11d815448aca1868eae.png)

When I look at the details of the elastic agent using that integration, it shows this

 ![httpjson](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e3d07971c5860cb0e8eada3f966311501233ff2a.png)

Any pointers to what the issue may be would be appreciated.

Thank you,

Brad

---

<div class="post-metadata">

**Author:** ![bbreer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bbreer/32/130059_2.png) [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Post date:** [September 3, 2025, 5:30pm UTC](https://discuss.elastic.co/t/ms-defender-for-endpoint-integration/381572/2 "2025-09-03T17:30:53Z")

</div>

I removed the integration from the agent policy and then re-added it and it seems to have solved the Inputs issue

 ![integration2](https://us1.discourse-cdn.com/elastic/original/3X/7/6/76b8d00685b3ae44bb2e778d796fc8f220f755e9.png)

However, the reauthorization issue remains. I’m wondering if it could be related to this issue.  
[m365\_defender,microsoft\_defender\_endpoint}: Add mapping and transform for CDR workflows](https://github.com/elastic/integrations/pull/14809)

---

<div class="post-metadata">

**Author:** ![bbreer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bbreer/32/130059_2.png) [@bbreer](https://discuss.elastic.co/u/bbreer)\
**Post date:** [October 16, 2025, 3:17pm UTC](https://discuss.elastic.co/t/ms-defender-for-endpoint-integration/381572/3 "2025-10-16T15:17:38Z")

</div>

Just to follow up in case anyone else runs into this issue. I submitted a support ticket to Elastic and sent a bunch of diagnostic files they worked on it for a few weeks but before they could provide a fix, I upgraded to the latest version 4.0.0 and the issue was resolved. I had upgraded the integration a couple times since the issue first started but those didn’t solve it.
