Skip to main content

Connectors

Every connector page in this section follows the same layout so you can find what you need without hunting for it: what data it provides, how it authenticates, and exactly what permissions to grant are always in a table at the top, before any setup steps.

Supported connectors

ConnectorData providedAuthenticationStatus
1PasswordUsersOAuth application (Client ID + Secret)Beta
AzureDevices, VulnerabilitiesOAuth2 (Azure app registration)Beta
BitwardenUsersOrganization API keyBeta
Cisco DuoUsers, DevicesAdmin API integration key + secret keyBeta
Cloudflare Zero TrustDevices, UsersAPI tokenVerified
CrowdStrikeDevices, Users, VulnerabilitiesOAuth2 (API client)Beta
CyberhavenDevicesDeployment hostname + Refresh TokenBeta
Device42DevicesUsername + passwordVerified
GitLabUsersGroup or personal access tokenBeta
Google WorkspaceDevices, UsersService account with domain-wide delegationBeta
GoTo ResolveDevicesOAuth2 (Client ID + Secret + Personal Access Token)Verified
HuntressDevices, UsersAPI key + secretBeta
Jamf ProDevicesOAuth2 (API Client)Beta
Jamf ProtectDevicesAPI Client (Client ID + Password)Beta
KeeperDevices, UsersDedicated service account (email + master password + authenticator secret)Beta
Microsoft DefenderDevices, Users, Vulnerabilities, SoftwareOAuth2 (Azure app registration)Verified
Microsoft Entra IDDevices, UsersOAuth2 (Azure app registration)Verified
Microsoft IntuneDevicesOAuth2 (Azure app registration)Verified
N-able N-centralDevicesUser-API token (JWT)Beta
NodewareDevices, VulnerabilitiesAPI tokenVerified
OktaUsers, DevicesAPI tokenBeta
TailscaleDevices, UsersOAuth client (Client ID + Secret)Beta
TenableDevices, VulnerabilitiesAPI key (Access Key + Secret Key)Beta

What “Beta” means

A connector is marked Beta until it has been run against a real, live account. Beta connectors are built from the vendor’s own documentation, so the data they collect should be correct, but details we couldn’t confirm without a live account (exact field values, edge cases, less common configurations) may differ. You’ll see a Beta tag on the connector in Navigator and a note at the top of its page here. Beta connectors are supported: if something looks wrong, tell us at support@chartingcyber.com and we’ll fix it.

Entra ID, Intune, Defender, and Azure are four separate connectors, each configured with its own Azure app registration and credentials. You don’t need to connect all four, and connecting one doesn’t require or affect the others. If you already use one Azure app registration for multiple purposes, you can reuse the same tenant ID / client ID / secret across more than one of these connectors, but each is still added and credentialed independently in Navigator.

Azure is a different kind of connector from the other three: Entra ID, Intune, and Defender authenticate against Microsoft Graph (or the Defender-for-Endpoint API) to read identity and endpoint data. Azure authenticates against Azure Resource Manager instead, to read cloud infrastructure inventory (virtual machines) and cloud vulnerability findings. Its app registration needs an Azure RBAC role assignment on your subscriptions, not Graph API permissions; see the Azure connector page for the exact setup.

A note on Jamf Pro and Jamf Protect

These are two separate Jamf products, each with its own connector, its own credentials, and its own console to generate them in. Jamf Pro is device management (MDM) and provides computer inventory. Jamf Protect is endpoint security and provides both device inventory and security alerts. You can connect either one on its own; connecting one doesn’t require or affect the other.

Connecting more than one instance of the same tool

If you manage more than one instance of the same tool (for example, two separate Okta organizations), you can add the same connector type more than once. Just give each one a distinct connection name when you set it up. See Managing Connectors for details.

Don’t see your tool listed?

Let us know at support@chartingcyber.com. New connectors are added regularly.