Integrations & API

Connect Unsave to
your existing workflow

Read-only into 12+ Microsoft services - Entra ID, Defender, Sentinel, Purview, Intune, and more - then out to ITSM ticketing, SIEM forwarding, REST API, Terraform drift detection, and webhooks.

12+ Microsoft services + your ITSM/SIEM stack · REST API · IaC drift

IntegrationsConnected

Reads from

Entra IDEntra ID ProtectionSecure ScoreDefender XDRDefender for CloudSentinelAdvisorPurviewIntunePIMKey VaultCost Management

Sends to

ServiceNowJiraPagerDutySlackTeamsSplunkElasticWebhooks
12+
Microsoft services
8+
Destinations
Full
REST API

12+

Microsoft services, read-only

8+

ITSM, SIEM & chat destinations

Full

REST API - scans, findings, scores

0

Agents or infrastructure to deploy

The problem

Signal siloed across
a dozen portals.

Entra ID Protection lives in one tab, Secure Score in another, Defender and Sentinel in two more. By the time a finding reaches the right person, it's a screenshot in a Slack DM - if it gets there at all.

A dozen portals, one team

Identity, threat, governance, and cost signal each live in their own Microsoft console. Nobody has the whole picture in one place.

Findings die in the queue

Without a route out, every finding becomes a manual copy-paste into a ticket - if anyone remembers to file it.

Drift goes unnoticed

Terraform state says one thing, Azure says another. Without continuous comparison, that gap stays invisible until an outage or an audit.

Every signal in, every finding out

Read-only into your Microsoft stack, then out to the ITSM, SIEM, and chat tools your team already runs - plus a full REST API and Terraform drift detection.

Inbound

Read every signal from your Microsoft stack

Unsave connects read-only into every Microsoft service you already run - identity, threat signal, governance, and cost - no agents, nothing to deploy. Twelve-plus services feed one unified view of posture, risk, and spend.

Entra ID, ID Protection, PIM & Access Reviews
Secure Score, Defender XDR, Defender for Cloud & Sentinel
Advisor, Purview & Intune device compliance
Key Vault inventory & Cost Management spend

12+ services · read-only

Entra IDEntra ID ProtectionSecure ScoreDefender XDRDefender for CloudSentinelAdvisorPurviewIntunePIMKey VaultCost Management

Outbound

Send findings everywhere your team works

Route every finding, alert, and drift event to the tools your team already lives in - ITSM ticketing, SIEM forwarding, chat, or a webhook - with severity mapping and zero-code configuration.

ServiceNow, Jira & PagerDuty ticketing
Sentinel, Splunk & Elastic - CEF or JSON
Slack & Teams alerts, in real time
Webhooks with retry & backoff

Outbound destinations

ServiceNowJiraPagerDutySlackTeamsSplunkElasticWebhooks
Critical NSG exposure→ ServiceNow
Suspicious sign-in alert→ PagerDuty
Key Vault soft-delete off→ Jira
Scan completed→ Slack

Programmatic access

A full REST API for everything Unsave sees

Pull scans, findings, posture scores, resources, and compliance mappings programmatically - with permission-scoped API keys, rotation schedules, and rate limiting built in.

Full CRUD across scans, findings & resources
Permission-scoped keys with rotation & expiry
Rate limiting & usage audit trail
OpenAPI documentation
/api/v1/posture200 OKGET
/api/v1/findings200 OKGET
/api/v1/compliance200 OKGET
/api/v1/scans202 AcceptedPOST

Infrastructure as code

Catch drift between Terraform and live Azure

Import your Terraform state and Unsave continuously diffs it against what's actually deployed - flagging modified resources, deleted resources, and anything running in Azure that was never declared in code.

Terraform state import
Live drift detection, resource by resource
Unmanaged resource flags
IaC coverage tracked over time
azurerm_network_security_group.webstateIn sync
azurerm_storage_account.datadriftModified
azurerm_key_vault.secretsdriftDeleted
vm-jumpbox-03live onlyUnmanaged

How it works

From OAuth consent to routed findings, in minutes.

01

Connect read-only

One-time OAuth admin consent grants read-only access to Microsoft Graph and Azure Resource Manager across 12+ services. Nothing is deployed in your tenant.

02

Point it at your stack

Configure outbound routes to ServiceNow, Jira, PagerDuty, Slack, Teams, your SIEM, or a webhook - zero-code and severity-mapped.

03

Stay in sync automatically

New findings, drift, and alerts flow out the moment they're detected. Pull anything programmatically through the REST API.

Two-way, out of the box

Every read. Every route. One connector.

Reads from Microsoft

Entra ID
Secure Score
Defender XDR
Sentinel

Sends to your stack

ServiceNow
Slack
PagerDuty
Splunk

How it connects

OAuth admin consent
Zero-code routing
Full REST API
12+ Microsoft services
ITSM, SIEM & chat routing
Full REST API access
Terraform drift detection

Connect Unsave to
your stack today

Free to start. 12+ Microsoft services plus your full ITSM/SIEM stack.