Skip to content

Commit 3ddfb03

Browse files
committed
unified security operations replacements
1 parent e8329c1 commit 3ddfb03

11 files changed

+21
-274
lines changed

articles/sentinel/connect-microsoft-365-defender.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn how to ingest incidents, alerts, and raw event data from Micr
44
author: yelevin
55
ms.author: yelevin
66
ms.topic: how-to
7-
ms.date: 11/26/2024
7+
ms.date: 05/22/2025
88
appliesto:
99
- Microsoft Sentinel with Defender XDR in the Microsoft Defender portal
1010
- Microsoft Sentinel in the Azure portal
@@ -19,7 +19,7 @@ ms.collection: usx-security
1919

2020
The Microsoft Defender XDR connector for Microsoft Sentinel allows you to stream all Microsoft Defender XDR incidents, alerts, and advanced hunting events into Microsoft Sentinel. This connector keeps the incidents synchronized between both portals. Microsoft Defender XDR incidents include alerts, entities, and other relevant information from all the Microsoft Defender products and services. For more information, see [Microsoft Defender XDR integration with Microsoft Sentinel](microsoft-365-defender-sentinel-integration.md).
2121

22-
The Defender XDR connector, especially its incident integration feature, is the foundation of Microsoft's unified security operations platform. If you're onboarding Microsoft Sentinel to the Microsoft Defender portal, you must first enable this connector with incident integration.
22+
The Defender XDR connector, especially its incident integration feature, is the foundation of unified security operations in the Microsoft Defender portal. The Defender XDR data connector is automatically connected when you onboard Microsoft Sentinel to the Defender portal.
2323

2424
[!INCLUDE [unified-soc-preview](includes/unified-soc-preview.md)]
2525

@@ -198,4 +198,4 @@ See more information on the following items used in the preceding examples, in t
198198

199199
In this document, you learned how to integrate Microsoft Defender XDR incidents, alerts, and advanced hunting event data from Microsoft Defender services, into Microsoft Sentinel, by using the Microsoft Defender XDR connector.
200200

201-
To use Microsoft Sentinel integrated with Defender XDR in Microsoft's unified security operations platform, see [Connect Microsoft Sentinel to the Microsoft Defender portal](/defender-xdr/microsoft-sentinel-onboard).
201+
To use Microsoft Sentinel together with Defender XDR in the Defender portal, see [Connect Microsoft Sentinel to the Microsoft Defender portal](/unified-secops-platform/microsoft-sentinel-onboard?toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json)

articles/sentinel/data-type-cloud-support.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,4 +56,4 @@ In this article, you learned about the types of clouds that affect the supported
5656

5757
- To get started with Microsoft Sentinel, you need a subscription to Microsoft Azure. If you don't have a subscription, you can sign up for a [free trial](https://azure.microsoft.com/free/).
5858
- Learn how to [onboard your data to Microsoft Sentinel](quickstart-onboard.md) and [get visibility into your data and potential threats](get-visibility.md).
59-
- Microsoft Sentinel is available as part of the unified security operations platform in the Microsoft Defender portal. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md) and [Connect Microsoft Sentinel to Microsoft Defender XDR](/microsoft-365/security/defender/microsoft-sentinel-onboard).
59+
- Microsoft Sentinel is also available for unified security operations in the Microsoft Defender portal. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md) and [Connect Microsoft Sentinel to Microsoft Defender XDR](/microsoft-365/security/defender/microsoft-sentinel-onboard).

articles/sentinel/includes/unified-soc-preview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,4 +10,4 @@ ms.custom: "include file"
1010
---
1111

1212
> [!IMPORTANT]
13-
> Microsoft Sentinel is generally available within Microsoft's unified security operations platform in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md).
13+
> Microsoft Sentinel is generally available in the Microsoft Defender portal, including for customers without Microsoft Defender XDR or an E5 license. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](../microsoft-sentinel-defender-portal.md).

articles/sentinel/index.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -54,11 +54,11 @@ landingContent:
5454
url: sentinel-solutions-deploy.md
5555

5656
# Card
57-
- title: Microsoft's unified security operations platform
57+
- title: Unified security operations
5858
linkLists:
5959
- linkListType: overview
6060
links:
61-
- text: "What is Microsoft's unified SecOps platform?"
61+
- text: "What are unified security operations?"
6262
url: /unified-secops-platform/overview-unified-security
6363
- text: "Microsoft Defender portal overview"
6464
url: /unified-secops-platform/overview-defender-portal

articles/sentinel/microsoft-365-defender-sentinel-integration.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,9 @@ ms.collection: usx-security
1919

2020
Integrate Microsoft Defender XDR with Microsoft Sentinel to stream all Defender XDR incidents and advanced hunting events into Microsoft Sentinel and keep the incidents and events synchronized between the Azure and Microsoft Defender portals. Incidents from Defender XDR include all associated alerts, entities, and relevant information, providing you with enough context to perform triage and preliminary investigation in Microsoft Sentinel. Once in Microsoft Sentinel, incidents remain bi-directionally synced with Defender XDR, allowing you to take advantage of the benefits of both portals in your incident investigation.
2121

22-
Alternatively, onboard Microsoft Sentinel with Defender XDR to Microsoft's unified security operations (SecOps) platform in the Defender portal. Microsoft's unified SecOps platform brings together the full capabilities of Microsoft Sentinel, Defender XDR, and generative AI built specifically for cybersecurity. For more information, see the following resources:
22+
Alternatively, onboard Microsoft Sentinel to the Defender portal to use it together with Defender XDR for unified security operations. For more information, see the following resources:
2323

24-
- [What is Microsoft's unified security operations platform?](/unified-secops-platform/overview-unified-security)
24+
- [What are unified security operations?](/unified-secops-platform/overview-unified-security)
2525
- [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md)
2626

2727
## Microsoft Sentinel and Defender XDR

articles/sentinel/microsoft-sentinel-defender-portal.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ When you onboard Microsoft Sentinel to the Defender portal without Defender XDR
4747

4848
## Quick reference
4949

50-
Some Microsoft Sentinel capabilities, like the unified incident queue, are integrated with Microsoft Defender XDR in Microsoft's unified security operations platform. Many other Microsoft Sentinel capabilities are available in the Microsoft Sentinel section of the Defender portal.
50+
Some Microsoft Sentinel capabilities, like the unified incident queue, are integrated with Microsoft Defender XDR in the Defender portal. Many other Microsoft Sentinel capabilities are available in the **Microsoft Sentinel** section of the Defender portal.
5151

5252
The following image shows the Microsoft Sentinel menu in the Defender portal:
5353

@@ -108,6 +108,6 @@ The following table lists the changes in navigation between the Azure and Defend
108108

109109
## Related content
110110

111-
- [What is Microsoft's unified security operations platform?](/unified-secops-platform/overview-unified-security)
111+
- [What are unified security operations?](/unified-secops-platform/overview-unified-security)
112112
- [Microsoft Defender XDR integration with Microsoft Sentinel](microsoft-365-defender-sentinel-integration.md)
113113
- [Connect Microsoft Sentinel to Microsoft Defender XDR](/microsoft-365/security/defender/microsoft-sentinel-onboard)

articles/sentinel/sap/deployment-attack-disrupt.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Automatic attack disruption for SAP | Microsoft Sentinel
3-
description: Learn about deploying automatic attack disruption for SAP with the unified security operations platform.
3+
description: Learn about deploying automatic attack disruption for SAP with Microsoft Sentinel in the Defender portal.
44
author: batamig
55
ms.author: bagol
66
ms.topic: concept-article
@@ -17,7 +17,7 @@ ms.collection: usx-security
1717

1818
Microsoft Defender XDR correlates millions of individual signals to identify active ransomware campaigns or other sophisticated attacks in the environment with high confidence. While an attack is in progress, Defender XDR disrupts the attack by automatically containing compromised assets that the attacker is using through automatic attack disruption. Automatic attack disruption limits lateral movement early on and reduces the overall impact of an attack, from associated costs to loss of productivity. At the same time, it leaves security operations teams in complete control of investigating, remediating, and bringing assets back online.
1919

20-
When you add a new SAP system to Microsoft Sentinel, your default configuration includes attack disruption functionality in Microsoft's unified security operations platform. This article describes how to ensure that your SAP system is ready to support automatic attack disruption for SAP in the Microsoft Defender portal.
20+
When you add a new SAP system to Microsoft Sentinel, your default configuration includes attack disruption functionality for use in the Microsoft Defender portal with Defender XDR. This article describes how to ensure that your SAP system is ready to support automatic attack disruption for SAP in the Microsoft Defender portal.
2121

2222
For a video demonstration of attack disruption for SAP, watch the following video:
2323
<br><br>
@@ -28,7 +28,7 @@ Content in this article is intended for your **security**, **infrastructure**, a
2828
> [!NOTE]
2929
> Attack disruption requires a data connector agent and isn't supported for the [SAP agentless data connector](deployment-overview.md#data-connector) (Limited preview).
3030
31-
## Attack disruption for SAP in Microsoft's unified security operations platform
31+
## Attack disruption for SAP in the Defender portal
3232

3333
Attack disruption for SAP is configured by updating your data connector agent version and ensuring that the relevant roles are applied in Azure and your SAP system. However, automatic attack disruption itself surfaces only in the Microsoft Defender portal.
3434

articles/sentinel/sap/update-sap-data-connector.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@ Be sure to check for any other available updates, such as SAP change requests.
8888

8989
## Update your system for attack disruption
9090

91-
Automatic attack disruption for SAP is supported in Microsoft's unified security operations platform, and requires:
91+
Automatic attack disruption for SAP is supported in the Microsoft Defender portal with Defender XDR, and requires:
9292

9393
- A workspace [onboarded to the Defender portal](../microsoft-sentinel-defender-portal.md).
9494

articles/sentinel/sentinel-security-copilot.md

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -39,17 +39,13 @@ This integration primarily supports the standalone experience accessed through [
3939

4040
## Key features
4141

42-
Microsoft Sentinel data integrates with Security Copilot in two ways.
42+
Microsoft Sentinel data integrates with Security Copilot in the Defender portal as follows:
4343

44-
- In Microsoft's unified security operations platform, Copilot in Microsoft Defender XDR benefits from unified incidents integrated with Microsoft Sentinel.
45-
- In the standalone experience, Microsoft Sentinel provides two plugins to integrate with Security Copilot:
44+
- When you also have Microsoft Defender XDR, Copilot in Microsoft Defender XDR benefits from unified incidents integrated with Microsoft Sentinel.
45+
- In the standalone experience, Microsoft Sentinel provides the following plugins to integrate with Security Copilot:
4646
<br>**Microsoft Sentinel (Preview)**
4747
<br>**Natural language to KQL for Microsoft Sentinel (Preview)**.
4848

49-
> [!IMPORTANT]
50-
> The "Microsoft Sentinel" and "Natural Language to KQL for Microsoft Sentinel" plugins are currently in PREVIEW. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
51-
>
52-
5349
## Enable Security Copilot integration with Microsoft Sentinel
5450

5551
To maximize your Security Copilot integration with Microsoft Sentinel do the following:

articles/sentinel/soc-optimization/soc-optimization-access.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ Watch the following video for an overview and demo of SOC optimization in the Mi
3939

4040
## Access the SOC optimization page
4141

42-
Use one of the following tabs, depending on whether you're working in the Azure portal or Defender portal. When your workspace is onboarded for unified security operations, SOC optimizations include coverage from across Microsoft security services.
42+
Use one of the following tabs, depending on whether you're working in the Azure portal or Defender portal. When your workspace is onboarded to the Defender portal, SOC optimizations include coverage from across Microsoft security services.
4343

4444
### [Defender portal](#tab/defender-portal)
4545

0 commit comments

Comments
 (0)