Skip to content

Commit 21f1583

Browse files
authored
Merge pull request #285490 from batamig/cust-intents-austin
Adding customer intents - Austin's files
2 parents 50b8993 + 344c4b5 commit 21f1583

34 files changed

+136
-17
lines changed

articles/sentinel/billing.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,10 @@ ms.collection: usx-security
1111
appliesto:
1212
- Microsoft Sentinel in the Azure portal
1313
- Microsoft Sentinel in the Microsoft Defender portal
14-
#Customer intent: As a SOC manager, plan Microsoft Sentinel costs so I can understand and optimize the costs of my SIEM.
14+
15+
16+
#Customer intent: As a SOC manager, I want to understand Microsoft Sentinel's pricing and billing models so that I can optimize costs and accurately forecast expenses.
17+
1518
---
1619

1720
# Plan costs and understand Microsoft Sentinel pricing and billing

articles/sentinel/bookmarks.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,10 @@ ms.collection: usx-security
99
appliesto:
1010
- Microsoft Sentinel in the Azure portal
1111
- Microsoft Sentinel in the Microsoft Defender portal
12+
13+
14+
#Customer intent: As a security analyst, I want to create and manage hunting bookmarks so that I can preserve and collaborate on relevant threat investigation data.
15+
1216
---
1317

1418
# Keep track of data during hunting with Microsoft Sentinel

articles/sentinel/ci-cd-custom-content.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,10 @@ ms.service: microsoft-sentinel
88
ms.topic: conceptual
99
ms.date: 8/24/2022
1010
ms.custom: template-concept
11-
#Customer intent: As a SOC collaborator or MSSP analyst, I want to manage dynamic Sentinel workspace content based on source control repositories for continuous integration and continuous delivery (CI/CD). Specifically as an MSSP content manager, I want to deploy one solution to many customer workspaces and still be able to tailor custom content for their environments.
11+
12+
13+
#Customer intent: As a SOC collaborator or MSSP analyst, I want to manage dynamic Microsoft Sentinel content as code based on source control repositories using CI/CD pipelines so that I can automate updates and ensure consistent configurations across workspaces. As an MSSP content manager, I want to deploy one solution to many customer workspaces and still be able to tailor custom content for their environments.
14+
1215
---
1316

1417
# Manage custom content with Microsoft Sentinel repositories (public preview)

articles/sentinel/ci-cd-custom-deploy.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,10 @@ author: austinmccollum
66
ms.topic: how-to
77
ms.date: 3/13/2024
88
ms.author: austinmc
9-
#Customer intent: As a SOC collaborator or MSSP analyst, I want to know how to optimize my source control repositories for continuous integration and continuous delivery (CI/CD). Specifically as an MSSP content manager, I want to know how to deploy one solution to many customer workspaces and still be able to tailor custom content for their environments.
9+
10+
11+
#Customer intent: As a SOC collaborator or MSSP analyst, I want to customize repository deployment workflows and pipelines so that I can control deployment triggers, paths, and parameter mappings for efficient and tailored content deployment to cloud workspaces.
12+
1013
---
1114

1215
# Customize repository deployments (Public Preview)

articles/sentinel/ci-cd.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,10 @@ appliesto:
1010
- Microsoft Sentinel in the Azure portal
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
13-
#Customer intent: As a SOC collaborator or MSSP analyst, I want to know how to connect my source control repositories for continuous integration and continuous delivery (CI/CD). Specifically as an MSSP content manager, I want to know how to deploy one solution to many customer workspaces and still be able to tailor custom content for their environments.
13+
14+
15+
#Customer intent: As a security administrator or MSSP analyst, I want to manage dynamic Microsoft Sentinel content as code based on source control repositories using CI/CD pipelines. I want to automate updates and ensure consistent configurations across workspaces in my security monitoring environment. As an MSSP content manager, I want to deploy one solution to many customer workspaces and still be able to tailor custom content for their environments.
16+
1417
---
1518

1619
# Deploy custom content from your repository (Public preview)

articles/sentinel/connect-mdti-data-connector.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,10 @@ appliesto:
1111
- Microsoft Sentinel in the Azure portal
1212
- Microsoft Sentinel in the Microsoft Defender portal
1313
ms.collection: usx-security
14-
#customer intent: As an SOC admin, I want to use the best threat intelligence from Microsoft so that I can generate high-fidelity alerts and incidents.
14+
15+
16+
#Customer intent: As a security administrator, I want to enable the data connector for Microsoft Defender Threat Intelligence so that I can ingest high fidelity indicators of compromise into my Microsoft Sentinel workspace for enhanced threat monitoring and response.
17+
1518
---
1619

1720
# Enable data connector for Microsoft Defender Threat Intelligence

articles/sentinel/connect-threat-intelligence-taxii.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,10 @@ appliesto:
1010
- Microsoft Sentinel in the Azure portal
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
13-
#customer intent: As an SOC admin, I want to connect Microsoft Sentinel to a STIX/TAXII feed to ingest threat intelligence so that I can generate alert incidents.
13+
14+
15+
#Customer intent: As a security admin, I want to integrate STIX/TAXII feeds into Microsoft Sentinel to ingest threat intelligence, generating alerts and incidents to enhance threat detection and response capabilities.
16+
1417
---
1518

1619
# Connect Microsoft Sentinel to STIX/TAXII threat intelligence feeds

articles/sentinel/connect-threat-intelligence-tip.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,10 @@ appliesto:
1010
- Microsoft Sentinel in the Azure portal
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
13-
#customer intent: As an SOC admin, I want to use a threat intelligence platform solution to ingest threat intelligence so that I can generate alerts incidents.
13+
14+
15+
#Customer intent: As a security admin, I want to integrate my threat intelligence platform with Microsoft Sentinel to ingest threat intelligence, generating alerts and incidents so that I can centralize and enhance threat detection and response.
16+
1417
---
1518

1619
# Connect your threat intelligence platform to Microsoft Sentinel

articles/sentinel/connect-threat-intelligence-upload-api.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,10 @@ appliesto:
1010
- Microsoft Sentinel in the Azure portal
1111
- Microsoft Sentinel in the Microsoft Defender portal
1212
ms.collection: usx-security
13-
#customer intent: As a security engineer, I want to connect a threat intelligence platform with the Upload Indicators API to ingest threat intelligence that so I can use the benefits of this updated API.
13+
14+
15+
#Customer intent: As a security admin, I want to connect my threat intelligence platform with Microsoft Sentinel using the appropriate API so that I can centralize and enhance threat detection and response capabilities.
16+
1417
---
1518

1619
# Connect your threat intelligence platform to Microsoft Sentinel with the Upload Indicators API

articles/sentinel/create-codeless-connector.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,10 @@ author: austinmccollum
55
ms.author: austinmc
66
ms.topic: how-to
77
ms.date: 09/26/2024
8+
9+
10+
#Customer intent: As a security engineer, I want to create custom data connectors for Microsoft Sentinel so that I can ingest and analyze data from various sources without writing code.
11+
812
---
913
# Create a codeless connector for Microsoft Sentinel
1014

0 commit comments

Comments
 (0)