Skip to content

m365_defender: Improve documentation and update vulnerability data stream URL - #17276

Merged
kcreddy merged 4 commits into
elastic:mainfrom
kcreddy:m365_defender-readme-layout
Feb 10, 2026
Merged

m365_defender: Improve documentation and update vulnerability data stream URL#17276
kcreddy merged 4 commits into
elastic:mainfrom
kcreddy:m365_defender-readme-layout

Conversation

@kcreddy

@kcreddy kcreddy commented Feb 6, 2026

Copy link
Copy Markdown
Contributor

Proposed commit message

m365_defender: Update vulnerability data stream URL and improve documentation

- Change default URL for the "vulnerability" data stream to 
  "https://api.security.microsoft.com". This is required as 
  older API will stop working on Feb 1, 2027[1].
- Improve documentation with correct links, updated input 
  titles and descriptions for all data streams.
- Update UI text to reflect updated titles.
- Disable alerts, eventhub, and vulnerability by default to 
  show minimal errors in the UI from required variables.

[1] https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0#migrate-from-the-older-apis

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

Screenshots

Recording (after changes)

m365-def-readme-layout.mp4
…scriptions for all data streams.

Change default URL for the `vulnerability` data stream
@kcreddy kcreddy self-assigned this Feb 6, 2026
@kcreddy kcreddy added enhancement New feature or request Integration:m365_defender Microsoft Defender XDR Category: Integration quality Category: Quality used for SI planning Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. labels Feb 6, 2026
@github-actions

github-actions Bot commented Feb 6, 2026

Copy link
Copy Markdown
Contributor

✅ Vale Linting Results

No issues found on modified lines!


The Vale linter checks documentation changes against the Elastic Docs style guide.

To use Vale locally or report issues, refer to Elastic style guide for Vale.

@kcreddy
kcreddy marked this pull request as ready for review February 6, 2026 08:35
@kcreddy
kcreddy requested a review from a team as a code owner February 6, 2026 08:35
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod

elastic-vault-github-plugin-prod Bot commented Feb 6, 2026

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@efd6 efd6 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nits only

Comment thread packages/m365_defender/_dev/build/docs/README.md Outdated
Comment thread packages/m365_defender/_dev/build/docs/README.md Outdated
Comment thread packages/m365_defender/_dev/build/docs/README.md Outdated
Comment thread packages/m365_defender/_dev/build/docs/README.md Outdated
@kcreddy
kcreddy requested a review from efd6 February 9, 2026 09:37
@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @kcreddy

@kcreddy
kcreddy merged commit 1889ed7 into elastic:main Feb 10, 2026
15 checks passed
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package m365_defender - 5.6.0 containing this change is available at https://epr.elastic.co/package/m365_defender/5.6.0/

jakubgalecki0 pushed a commit to jakubgalecki0/integrations that referenced this pull request Feb 19, 2026
…entation (elastic#17276)

- Change default URL for the "vulnerability" data stream to 
  "https://api.security.microsoft.com". This is required as 
  older API will stop working on Feb 1, 2027[1].
- Improve documentation with correct links, updated input 
  titles and descriptions for all data streams.
- Update UI text to reflect updated titles.
- Disable alerts, eventhub, and vulnerability by default to 
  show minimal errors in the UI from required variables.

[1] https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview?view=graph-rest-1.0#migrate-from-the-older-apis
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Category: Integration quality Category: Quality used for SI planning documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:m365_defender Microsoft Defender XDR Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

3 participants