Configuration
The Configuration Centre lists every integration your subscription requires. Each integration shows its status:
| Credential | Purpose | Where to get it | How to get it |
|---|---|---|---|
| Tenant ID | Identifies your Microsoft Entra tenant | Azure portal β Microsoft Entra ID β Overview | portal.azure.com β search βMicrosoft Entra IDβ β copy βTenant IDβ (36-char GUID) |
| Client ID | Identifies the ProPera app registration | Entra ID β App registrations β your app β Overview | App registrations β New registration (if none) β copy βApplication (client) IDβ |
| Client Secret | Authenticates the app to Microsoft APIs | Entra ID β App registrations β Certificates & secrets | βNew client secretβ β expiry β copy the Value (shown only once). Required for LIVE mode + real MDE actions |
| MDE / Graph API URL | Defender + Graph endpoints | Pre-filled | Leave the defaults; change only for sovereign/government clouds |
| Sentinel subscription / resource group / workspace ID | Sentinel hunting & queries | Azure portal β Microsoft Sentinel β your workspace | Subscription ID: Azure β Subscriptions. Workspace ID: Sentinel β Settings β Workspace settings |
| Teams webhook URL | Alerts & approvals to a Teams channel | Teams channel β β― β Connectors | Add βIncoming Webhookβ β name it β copy the URL |
| Vanta Client ID / Secret | Compliance evidence sync | https://developer.vanta.com β your app | Create an app in the Vanta developer console, copy Client ID + Secret |
| VirusTotal API key | IP/hash/URL enrichment | virustotal.com β My profile β API Key | Free community key works; higher tiers allow more requests |
| AbuseIPDB API key | IP abuse checks | abuseipdb.com β Account β API | Copy the key from the API tab |
| OTX API key | Open Threat Exchange enrichment | otx.alienvault.com β Settings β API | Copy the key from the API section |
| Slack webhook URL | Notifications to a Slack channel | api.slack.com/apps β your app β Incoming Webhooks | Create an app β enable Incoming Webhooks β add to workspace β copy URL |
| ServiceNow instance / user / password | Ticket creation | Your ServiceNow instance URL | Use the browser address, e.g. https://yourcompany.service-now.com; create a dedicated integration user |
| Jira URL / email / API token | Ticket creation | id.atlassian.com β Security β API tokens | βCreate API tokenβ β name it β copy (shown once); email = your Atlassian login email |
Official intelligence feeds (CISA KEV + advisories, NZ NCSC/CERT NZ, UK NCSC, NVD/CVE, Microsoft MSRC, ENISA) are built in. On the Data Sources page you can view their health, see the last fetch and trigger ingestion. Feeds are only ever taken from official channels - no scraping, no fabricated live status.
View Data Sources β
Notifications - choose channels (in-app, Teams, Slack, webhook) when creating alert rules.
Countries & industries - follow the countries you operate in and sectors you protect on the Watchlists page.
Technology watchlists - add the products you run (e.g. Fortinet, Cisco, Microsoft Exchange) to be alerted when a relevant advisory appears.