Security Operations
Help Centre
❓
Configure integrations

The Configuration Centre lists every integration your subscription requires. Each integration shows its status:

Connected - working normally
Configuration required - enter credentials and test
Connection failed - check the reason and fix
Demo - demo mode active
Configure API credentials β€” hover the ? next to any field in the Configuration Centre for step-by-step instructions
CredentialPurposeWhere to get itHow to get it
Tenant IDIdentifies your Microsoft Entra tenantAzure portal β†’ Microsoft Entra ID β†’ Overviewportal.azure.com β†’ search β€œMicrosoft Entra ID” β†’ copy β€œTenant ID” (36-char GUID)
Client IDIdentifies the ProPera app registrationEntra ID β†’ App registrations β†’ your app β†’ OverviewApp registrations β†’ New registration (if none) β†’ copy β€œApplication (client) ID”
Client SecretAuthenticates the app to Microsoft APIsEntra ID β†’ App registrations β†’ Certificates & secretsβ€œNew client secret” β†’ expiry β†’ copy the Value (shown only once). Required for LIVE mode + real MDE actions
MDE / Graph API URLDefender + Graph endpointsPre-filledLeave the defaults; change only for sovereign/government clouds
Sentinel subscription / resource group / workspace IDSentinel hunting & queriesAzure portal β†’ Microsoft Sentinel β†’ your workspaceSubscription ID: Azure β†’ Subscriptions. Workspace ID: Sentinel β†’ Settings β†’ Workspace settings
Teams webhook URLAlerts & approvals to a Teams channelTeams channel β†’ β‹― β†’ ConnectorsAdd β€œIncoming Webhook” β†’ name it β†’ copy the URL
Vanta Client ID / SecretCompliance evidence synchttps://developer.vanta.com β†’ your appCreate an app in the Vanta developer console, copy Client ID + Secret
VirusTotal API keyIP/hash/URL enrichmentvirustotal.com β†’ My profile β†’ API KeyFree community key works; higher tiers allow more requests
AbuseIPDB API keyIP abuse checksabuseipdb.com β†’ Account β†’ APICopy the key from the API tab
OTX API keyOpen Threat Exchange enrichmentotx.alienvault.com β†’ Settings β†’ APICopy the key from the API section
Slack webhook URLNotifications to a Slack channelapi.slack.com/apps β†’ your app β†’ Incoming WebhooksCreate an app β†’ enable Incoming Webhooks β†’ add to workspace β†’ copy URL
ServiceNow instance / user / passwordTicket creationYour ServiceNow instance URLUse the browser address, e.g. https://yourcompany.service-now.com; create a dedicated integration user
Jira URL / email / API tokenTicket creationid.atlassian.com β†’ Security β†’ API tokensβ€œCreate API token” β†’ name it β†’ copy (shown once); email = your Atlassian login email
πŸ”’ Secrets are encrypted at rest, never displayed after saving, and every change is audit-logged.
Configure government feeds

Official intelligence feeds (CISA KEV + advisories, NZ NCSC/CERT NZ, UK NCSC, NVD/CVE, Microsoft MSRC, ENISA) are built in. On the Data Sources page you can view their health, see the last fetch and trigger ingestion. Feeds are only ever taken from official channels - no scraping, no fabricated live status.

View Data Sources β†’
Configure notifications, countries, industries & watchlists

Notifications - choose channels (in-app, Teams, Slack, webhook) when creating alert rules.
Countries & industries - follow the countries you operate in and sectors you protect on the Watchlists page.
Technology watchlists - add the products you run (e.g. Fortinet, Cisco, Microsoft Exchange) to be alerted when a relevant advisory appears.

Open Watchlists β†’
Troubleshooting
πŸ”΄ Authentication failed
What happened? The provider rejected the authentication request.
Why? The Client Secret may be expired or incorrect.
How to fix: generate a new secret in your identity provider β†’ update it in the Configuration Centre β†’ click Test Connection.
🟑 Configuration required
What happened? The integration is required by your subscription but has no valid credentials.
Why? Credentials were never set, or were rotated/cleared.
How to fix: open the Configuration Centre, enter the credentials, save and test.