Skip to content

Commit 0892506

Browse files
Merge pull request #89509 from memildin/asc-melvyn-test
Updated branding of WDATP
2 parents 3abf368 + 094f182 commit 0892506

File tree

5 files changed

+36
-39
lines changed

5 files changed

+36
-39
lines changed

articles/security-center/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,7 @@
6969
href: security-center-secure-score.md
7070
- name: Upgrade to advanced security
7171
href: security-center-onboarding.md
72-
- name: Server protection with Windows Defender ATP
72+
- name: Server protection with Microsoft Defender ATP
7373
href: security-center-wdatp.md
7474
- name: Advanced data security for SQL on Azure VMs (Public Preview)
7575
href: security-center-iaas-advanced-data.md

articles/security-center/security-center-alerts-iaas.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ Security Center extends its cloud workload protection platforms by integrating w
3030
> [!NOTE]
3131
> Windows Server Defender ATP sensor is automatically enabled on Windows servers that use Security Center.
3232
33-
When Windows Server Defender ATP detects a threat, it triggers an alert. The alert is shown on the Security Center dashboard. From the dashboard, you can pivot to the Windows Defender ATP console, and perform a detailed investigation to uncover the scope of the attack. For more information about Windows Server Defender ATP, see [Onboard servers to the Windows Defender ATP service](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints).
33+
When Windows Server Defender ATP detects a threat, it triggers an alert. The alert is shown on the Security Center dashboard. From the dashboard, you can pivot to the Microsoft Defender ATP console, and perform a detailed investigation to uncover the scope of the attack. For more information about Windows Server Defender ATP, see [Onboard servers to the Microsoft Defender ATP service](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/configure-server-endpoints).
3434

3535
### Crash dump analysis <a nanme="windows-dump"></a>
3636

articles/security-center/security-center-services.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.devlang: na
1111
ms.topic: conceptual
1212
ms.tgt_pltfrm: na
1313
ms.workload: na
14-
ms.date: 08/29/2019
14+
ms.date: 09/24/2019
1515
ms.author: memildin
1616
---
1717
# Supported features available in Azure Security Center
@@ -35,7 +35,7 @@ The following sections show Security Center features that are available for thei
3535
||**Virtual Machine**|**Virtual Machine Scale Set**||**Virtual Machine**|**Virtual Machine Scale Set**|
3636
|VMBA threat detection alerts||||✔ (on supported versions)|✔ (on supported versions)||Recommendations (Free) Threat Detection (Standard)|
3737
|Network-based threat detection alerts|||X|||X|Standard|
38-
|Windows Defender ATP integration|✔ (on supported versions)|✔ (on supported versions)||X|X|X|Standard|
38+
|Microsoft Defender ATP integration|✔ (on supported versions)|✔ (on supported versions)||X|X|X|Standard|
3939
|Missing patches|||||||Free|
4040
|Security configurations|||||||Free|
4141
|Endpoint protection assessment||||X|X|X|Free|

articles/security-center/security-center-wdatp.md

Lines changed: 30 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Windows Defender Advanced Threat Protection with Azure Security Center
3-
description: This document introduces the integration between Azure Security Center and Windows Defender Advanced Threat Protection.
2+
title: Microsoft Defender Advanced Threat Protection with Azure Security Center
3+
description: This document introduces the integration between Azure Security Center and Microsoft Defender Advanced Threat Protection.
44
services: security-center
55
documentationcenter: na
66
author: memildin
@@ -10,48 +10,48 @@ ms.devlang: na
1010
ms.topic: conceptual
1111
ms.tgt_pltfrm: na
1212
ms.workload: na
13-
ms.date: 08/21/2019
13+
ms.date: 09/24/2019
1414
ms.author: memildin
1515
---
16-
# Windows Defender Advanced Threat Protection with Azure Security Center
16+
# Microsoft Defender Advanced Threat Protection with Azure Security Center
1717

18-
Azure Security Center is extending its Cloud Workload Protection Platforms offering by integrating with [Windows Defender Advanced Threat Protection](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp) (ATP).
19-
This change brings comprehensive Endpoint Detection and Response (EDR) capabilities. With Windows Defender ATP integration, you can spot abnormalities. You can also detect and respond to advanced attacks on server endpoints monitored by Azure Security Center.
18+
Azure Security Center is extending its Cloud Workload Protection Platforms offering by integrating with [Microsoft Defender Advanced Threat Protection](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp) (ATP).
19+
This change brings comprehensive Endpoint Detection and Response (EDR) capabilities. With Microsoft Defender ATP integration, you can spot abnormalities. You can also detect and respond to advanced attacks on server endpoints monitored by Azure Security Center.
2020

21-
## Windows Defender ATP features in Security Center
21+
## Microsoft Defender ATP features in Security Center
2222

23-
When you use Windows Defender ATP you get:
23+
When you use Microsoft Defender ATP you get:
2424

25-
- **Next-generation post breach detection sensors**: Windows Defender ATP sensors for Windows servers collect a vast array of behavioral signals.
25+
- **Next-generation post breach detection sensors**: Microsoft Defender ATP sensors for Windows servers collect a vast array of behavioral signals.
2626

27-
- **Analytics-based, cloud-powered post breach detection**: Windows Defender ATP quickly adapts to changing threats. It uses advanced analytics and big data. Windows Defender ATP is amplified by the power of the Intelligent Security Graph with signals across Windows, Azure, and Office to detect unknown threats. It provides actionable alerts and enables you to respond quickly.
27+
- **Analytics-based, cloud-powered post breach detection**: Microsoft Defender ATP quickly adapts to changing threats. It uses advanced analytics and big data. Microsoft Defender ATP is amplified by the power of the Intelligent Security Graph with signals across Windows, Azure, and Office to detect unknown threats. It provides actionable alerts and enables you to respond quickly.
2828

29-
- **Threat intelligence**: Windows Defender ATP identifies attacker tools, techniques, and procedures. When it detects these, it generates alerts. It uses data generated by Microsoft threat hunters and security teams, augmented by intelligence provided by partners.
29+
- **Threat intelligence**: Microsoft Defender ATP identifies attacker tools, techniques, and procedures. When it detects these, it generates alerts. It uses data generated by Microsoft threat hunters and security teams, augmented by intelligence provided by partners.
3030

3131
These capabilities are now available in Azure Security Center:
3232

33-
- **Automated onboarding**: The Windows Defender ATP sensor is automatically enabled for Windows servers that are onboarded to Azure Security Center.
33+
- **Automated onboarding**: The Microsoft Defender ATP sensor is automatically enabled for Windows servers that are onboarded to Azure Security Center.
3434

35-
- **Single pane of glass**: The Azure Security Center console displays Windows Defender ATP alerts.
35+
- **Single pane of glass**: The Azure Security Center console displays Microsoft Defender ATP alerts.
3636

37-
- **Detailed machine investigation**: Azure Security Center customers can access Windows Defender ATP console to perform a detailed investigation to uncover the scope of a breach.
37+
- **Detailed machine investigation**: Azure Security Center customers can access Microsoft Defender ATP console to perform a detailed investigation to uncover the scope of a breach.
3838

3939
![Azure Security Center, displaying a list of alerts and general information about each alert](media/security-center-wdatp/image1.png)
4040

41-
You can further investigate the alert by pivoting to Windows Defender ATP. There you can see additional information such as the alert process tree and the incident graph. You can also see a detailed machine timeline that shows every behavior for a historical period of up to six months.
41+
You can further investigate the alert by pivoting to Microsoft Defender ATP. There you can see additional information such as the alert process tree and the incident graph. You can also see a detailed machine timeline that shows every behavior for a historical period of up to six months.
4242

43-
![Windows Defender ATP page with detailed information about an alert](media/security-center-wdatp/image3.png)
43+
![Microsoft Defender ATP page with detailed information about an alert](media/security-center-wdatp/image3.png)
4444

4545
## Platform support
4646

47-
Windows Defender ATP in Security Center supports detection on Windows Server 2016, 2012 R2, and 2008 R2 SP1 operating systems in a Standard service subscription.
47+
Microsoft Defender ATP in Security Center supports detection on Windows Server 2016, 2012 R2, and 2008 R2 SP1 operating systems in a Standard service subscription.
4848

4949
> [!NOTE]
50-
> When you use Azure Security Center to monitor servers, a Windows Defender ATP tenant is automatically created and the Windows Defender ATP data is stored in Europe by default. If you need to move your data to another location, you need to contact Microsoft Support to reset the tenant.
50+
> When you use Azure Security Center to monitor servers, a Microsoft Defender ATP tenant is automatically created and the Microsoft Defender ATP data is stored in Europe by default. If you need to move your data to another location, you need to contact Microsoft Support to reset the tenant.
5151
5252
## Onboarding servers to Security Center
5353

54-
To onboard servers to Security Center, click **Go to Azure Security Center to onboard servers** from the Windows Defender ATP server onboarding.
54+
To onboard servers to Security Center, click **Go to Azure Security Center to onboard servers** from the Microsoft Defender ATP server onboarding.
5555

5656
1. In the **Onboarding** blade select or create a workspace in which to store the data. <br>
5757
2. If you can’t see all your workspaces, it may be due to a lack of permissions, make sure your workspace is set to Azure Security Standard tier. For more information see [Upgrade to Security Center's Standard tier for enhanced security](security-center-pricing.md).
@@ -62,35 +62,32 @@ To onboard servers to Security Center, click **Go to Azure Security Center to on
6262

6363
![Onboard computers](media/security-center-wdatp/onboard-computers.png)
6464

65-
## Enable Windows Defender ATP integration
66-
67-
To view if Windows Defender ATP integration is enabled, select **Security center** > **Pricing & settings** > click on your subscription.
68-
69-
![Azure Security Center Policy Management](media/security-center-wdatp/policy-management.png)
65+
## Enable Microsoft Defender ATP integration
7066

67+
To view if Microsoft Defender ATP integration is enabled, select **Security center** > **Pricing & settings** > click on your subscription.
7168
Here you can see the integrations currently enabled.
7269

73-
![Azure Security Center Threat detection settings page with Windows Defender ATP integration enabled](media/security-center-wdatp/enable-integrations.png)
70+
![Azure Security Center Threat detection settings page with Microsoft Defender ATP integration enabled](media/security-center-wdatp/enable-integrations.png)
7471

75-
- If you've already onboarded the servers to Azure Security Center standard tier, you need take no further action. Azure Security Center will automatically onboard the servers to Windows Defender ATP. This might take up to 24 hours.
72+
- If you've already onboarded the servers to Azure Security Center standard tier, you need take no further action. Azure Security Center will automatically onboard the servers to Microsoft Defender ATP. This might take up to 24 hours.
7673

7774
- If you've never onboarded the servers to Azure Security Center standard tier, onboard them to Azure Security Center as usual.
7875

79-
- If you've onboarded the servers through Windows Defender ATP:
76+
- If you've onboarded the servers through Microsoft Defender ATP:
8077
- Refer to the documentation for guidance on [how to offboard server machines](https://go.microsoft.com/fwlink/p/?linkid=852906).
8178
- Onboard these servers to Azure Security Center.
8279

83-
## Access to the Windows Defender ATP portal
80+
## Access to the Microsoft Defender ATP portal
8481

85-
Follow the instructions in [Assign user access to the portal](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/assign-portal-access-windows-defender-advanced-threat-protection).
82+
Follow the instructions in [Assign user access to the portal](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/assign-portal-access).
8683

8784
## Set the firewall configuration
8885

89-
If you have a proxy or firewall that is blocking anonymous traffic, as a Windows Defender ATP sensor is connecting from the system context, make sure that anonymous traffic is permitted. Follow the instructions in [Enable access to Windows Defender ATP service URLs in the proxy server](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/configure-proxy-internet-windows-defender-advanced-threat-protection#enable-access-to-microsoft-defender-atp-service-urls-in-the-proxy-server).
86+
If you have a proxy or firewall that is blocking anonymous traffic, as a Microsoft Defender ATP sensor is connecting from the system context, make sure that anonymous traffic is permitted. Follow the instructions in [Enable access to Microsoft Defender ATP service URLs in the proxy server](https://docs.microsoft.com/windows/security/threat-protection/microsoft-defender-atp/configure-proxy-internet#enable-access-to-microsoft-defender-atp-service-urls-in-the-proxy-server).
9087

9188
## Test the feature
9289

93-
To generate a benign Windows Defender ATP test alert:
90+
To generate a benign Microsoft Defender ATP test alert:
9491

9592
1. Use Remote Desktop to access either a Windows Server 2012 R2 VM or a Windows Server 2016 VM. Open a Command Prompt window.
9693

@@ -102,11 +99,11 @@ To generate a benign Windows Defender ATP test alert:
10299
103100
![A Command Prompt window with the command above](media/security-center-wdatp/image4.jpeg)
104101
105-
3. If the command is successful, you'll see a new alert on the Azure Security Center dashboard and the Windows Defender ATP portal. This alert might take a few minutes to appear.
102+
3. If the command is successful, you'll see a new alert on the Azure Security Center dashboard and the Microsoft Defender ATP portal. This alert might take a few minutes to appear.
106103
107104
4. To review the alert in Security Center, go to **Security Alerts** > **Suspicious Powershell CommandLine**.
108105
109-
5. From the investigation window, select the link to go to the Windows Defender ATP portal.
106+
5. From the investigation window, select the link to go to the Microsoft Defender ATP portal.
110107
111108
## Next steps
112109

articles/security/fundamentals/operational-best-practices.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -93,7 +93,7 @@ The Free tier of Security Center offers limited security for only your Azure res
9393

9494
Use Security Center to get a central view of the security state of all your Azure resources. At a glance, verify that the appropriate security controls are in place and configured correctly, and quickly identify any resources that need attention.
9595

96-
Security Center also integrates with [Windows Defender Advanced Threat Protection (ATP)](../../security-center/security-center-wdatp.md), which provides comprehensive Endpoint Detection and Response (EDR) capabilities. With Windows Defender ATP integration, you can spot abnormalities. You can also detect and respond to advanced attacks on server endpoints monitored by Security Center.
96+
Security Center also integrates with [Microsoft Defender Advanced Threat Protection (ATP)](../../security-center/security-center-wdatp.md), which provides comprehensive Endpoint Detection and Response (EDR) capabilities. With Microsoft Defender ATP integration, you can spot abnormalities. You can also detect and respond to advanced attacks on server endpoints monitored by Security Center.
9797

9898
Almost all enterprise organizations have a security information and event management (SIEM) system to help identify emerging threats by consolidating log information from diverse signal gathering devices. The logs are then analyzed by a data analytics system to help identify what’s “interesting” from the noise that is inevitable in all log gathering and analytics solutions.
9999

@@ -119,7 +119,7 @@ The secure score, which is based on Center for Internet Security (CIS) controls,
119119
**Detail**: Use [Azure Monitor to gather and export data](/azure/azure-monitor/overview#integrate-and-export-data). This practice is critical for enabling security incident investigation, and online log retention is limited. If you’re using Azure Sentinel, see [Connect data sources](../../sentinel/connect-data-sources.md).
120120

121121
**Best practice**: Speed up your investigation and hunting processes and reduce false positives by integrating Endpoint Detection and Response (EDR) capabilities into your attack investigation.
122-
**Detail**: [Enable Windows Defender ATP integration](../../security-center/security-center-wdatp.md#enable-windows-defender-atp-integration) via your Security Center security policy. Consider using Azure Sentinel for threat hunting and incident response.
122+
**Detail**: [Enable Microsoft Defender ATP integration](../../security-center/security-center-wdatp.md#enable-microsoft-defender-atp-integration) via your Security Center security policy. Consider using Azure Sentinel for threat hunting and incident response.
123123

124124
## Monitor end-to-end scenario-based network monitoring
125125
Customers build an end-to-end network in Azure by combining network resources like a virtual network, ExpressRoute, Application Gateway, and load balancers. Monitoring is available on each of the network resources.

0 commit comments

Comments
 (0)