Skip to content

Commit 4c8543b

Browse files
authored
Merge pull request #250887 from ElazarK/WI147804-mdc-m365
WI 147804 MDC & M365 integration
2 parents 38537b0 + 79617d1 commit 4c8543b

8 files changed

+93
-14
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 7 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -39,21 +39,21 @@
3939
expanded: false
4040
items:
4141
- name: Connect your Azure subscriptions
42-
displayName: enable, defender for cloud, activate, turn on
42+
displayName: enable, defender for cloud, activate, turn on, Microsoft 365 Defender, alerts, integration, m365, m365d, m365 defender
4343
href: connect-azure-subscription.md
4444
- name: Connect your AWS accounts
45-
displayName: hybrid, multicloud, multicloud, amazon, arc, AWS, accounts
45+
displayName: hybrid, multicloud, multicloud, amazon, arc, AWS, accounts, Microsoft 365 Defender, alerts, integration, m365, m365d, m365 defender
4646
href: quickstart-onboard-aws.md
4747
- name: Connect your GCP projects
48-
displayName: hybrid, multicloud, multicloud, google, gcp
48+
displayName: hybrid, multicloud, multicloud, google, gcp, Microsoft 365 Defender, alerts, integration, m365, m365d, m365 defender
4949
href: quickstart-onboard-gcp.md
5050
- name: Connect individual non-Azure machines
5151
items:
5252
- name: Connect machines with Defender for Endpoint
5353
displayName: azure stack, ash, windows, linux, hybrid, defender for endpoint
5454
href: onboard-machines-with-defender-for-endpoint.md
5555
- name: Connect machines with Azure Arc
56-
displayName: azure stack, ash, windows, linux, hybrid, arc, on-premises
56+
displayName: azure stack, ash, windows, linux, hybrid, arc, on-premises, Microsoft 365 Defender, alerts, integration, m365, m365d, m365 defender
5757
href: quickstart-onboard-machines.md
5858
- name: Enable specific Defender plans
5959
expanded: false
@@ -259,6 +259,9 @@
259259
displayName: security, alerts, classification, incident, threat, detection,
260260
analytics,
261261
href: alerts-overview.md
262+
- name: Alerts and incidents in Microsoft 365 Defender
263+
displayName: Microsoft 365 Defender, alerts, integration, m365, m365d, m365 defender
264+
href: concept-integration-365.md
262265
- name: Security alerts
263266
items:
264267
- name: Security alerts reference list
Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
---
2+
title: Alerts and incidents in Microsoft 365 Defender
3+
description: Learn about the benefits of receiving Microsoft Defender for Cloud's alerts in Microsoft 365 Defender
4+
ms.topic: conceptual
5+
ms.date: 11/02/2023
6+
---
7+
8+
# Alerts and incidents in Microsoft 365 Defender
9+
10+
Microsoft Defender for Cloud's integration with Microsoft 365 Defender allows security teams to access Defender for Cloud alerts and incidents within the Microsoft 365 Defender portal. This integration provides richer context to investigations that span cloud resources, devices, and identities.
11+
12+
The partnership with Microsoft 365 Defender allows security teams to get the complete picture of an attack, including suspicious and malicious events that happen in their cloud environment. This is achieved through immediate correlations of alerts and incidents.
13+
14+
Microsoft 365 Defender offers a comprehensive solution that combines protection, detection, investigation, and response capabilities to protect against attacks on device, email, collaboration, identity, and cloud apps. Our detection and investigation capabilities are now extended to cloud entities, offering security operations teams a single pane of glass to significantly improve their operational efficiency.
15+
16+
Incidents and alerts are now part of [Microsoft 365 Defender's public API](/microsoft-365/security/defender/api-overview?view=o365-worldwide). This integration allows exporting of security alerts data to any system using a single API. As Microsoft Defender for Cloud, we're committed to providing our users with the best possible security solutions, and this integration is a significant step towards achieving that goal.
17+
18+
## Investigation experience in Microsoft 365 Defender
19+
20+
The following table describes the detection and investigation experience in Microsoft 365 Defender with Defender for Cloud alerts.
21+
22+
| Area | Description |
23+
|--|--|
24+
| Incidents | All Defender for Cloud incidents are integrated to Microsoft 365 Defender. <br> - Searching for cloud resource assets in the [incident queue](/microsoft-365/security/defender/incident-queue?view=o365-worldwide) is supported. <br> - The [attack story](/microsoft-365/security/defender/investigate-incidents?view=o365-worldwide#attack-story) graph shows cloud resource. <br> - The [assets tab](/microsoft-365/security/defender/investigate-incidents?view=o365-worldwide#assets) in an incident page shows the cloud resource. <br> - Each virtual machine has its own entity page containing all related alerts and activity. <br> <br> There are no duplications of incidents from other Defender workloads. |
25+
| Alerts | All Defender for Cloud alerts, including multicloud, internal and external providers’ alerts, are integrated to Microsoft 365 Defender. Defenders for Cloud alerts show on the Microsoft 365 Defender [alert queue](/microsoft-365/security/defender-endpoint/alerts-queue-endpoint-detection-response?view=o365-worldwide). <br> <br> The `cloud resource` asset shows up in the Asset tab of an alert. Resources are clearly identified as an Azure, Amazon, or a Google Cloud resource. <br> <br> Defenders for Cloud alerts are automatically be associated with a tenant. <br> <br> There are no duplications of alerts from other Defender workloads.|
26+
| Alert and incident correlation | Alerts and incidents are automatically correlated, providing robust context to security operations teams to understand the complete attack story in their cloud environment. |
27+
| Threat detection | Accurate matching of virtual entities to device entities to ensure precision and effective threat detection. |
28+
| Advanced hunting | |
29+
| Unified API | Defender for Cloud alerts and incidents are now included in [Microsoft 365 Defender’s public API](/microsoft-365/security/defender/api-overview?view=o365-worldwide), allowing customers to export their security alerts data into other systems using one API. |
30+
31+
Learn more about [handling alerts in Microsoft 365 Defender](/microsoft-365/security/defender/microsoft-365-security-center-defender-cloud?view=o365-worldwide).
32+
33+
## Next steps
34+
35+
[Security alerts - a reference guide](alerts-reference.md)

articles/defender-for-cloud/connect-azure-subscription.md

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Connect your Azure subscriptions
33
description: Learn how to connect your Azure subscriptions to Microsoft Defender for Cloud
44
ms.topic: install-set-up-deploy
5-
ms.date: 07/10/2023
5+
ms.date: 11/02/2023
66
ms.custom: mode-other
77
---
88

@@ -16,7 +16,7 @@ Microsoft Defender for Cloud is a cloud-native application protection platform (
1616
- A cloud security posture management (CSPM) solution that surfaces actions that you can take to prevent breaches
1717
- A cloud workload protection platform (CWPP) with specific protections for servers, containers, storage, databases, and other workloads
1818

19-
Defender for Cloud includes Foundational CSPM capabilities for free, complemented by additional paid plans required to secure all aspects of your cloud resources. To learn more about these plans and their costs, see the Defender for Cloud [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/).
19+
Defender for Cloud includes Foundational CSPM capabilities and access to [Microsoft 365 Defender](/microsoft-365/security/defender/microsoft-365-defender?view=o365-worldwide) for free. You can add additional paid plans to secure all aspects of your cloud resources. To learn more about these plans and their costs, see the Defender for Cloud [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/).
2020

2121
Defender for Cloud helps you find and fix security vulnerabilities. Defender for Cloud also applies access and application controls to block malicious activity, detect threats using analytics and intelligence, and respond quickly when under attack.
2222

@@ -95,6 +95,14 @@ If you want to disable any of the plans, toggle the individual plan to **off**.
9595
> [!TIP]
9696
> To enable Defender for Cloud on all subscriptions within a management group, see [Enable Defender for Cloud on multiple Azure subscriptions](onboard-management-group.md).
9797
98+
## Integrate with Microsoft 365 Defender
99+
100+
When you enable Defender for Cloud, Defender for Cloud's alerts are automatically integrated into the Microsoft 365 Defender portal. No further steps are needed.
101+
102+
The integration between Microsoft Defender for Cloud and Microsoft 365 Defender brings your cloud environments into Microsoft 365 Defender. With Defender for Cloud's alerts and cloud correlations integrated into Microsoft 365 Defender, SOC teams can now access all security information from a single interface.
103+
104+
Learn more about Defender for Cloud's [alerts in Microsoft 365 Defender](concept-integration-365.md).
105+
98106
## Next steps
99107

100108
In this guide, you enabled Defender for Cloud on your Azure subscription. The next step is to set up your hybrid and multicloud environments.

articles/defender-for-cloud/data-security.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn how data is managed and safeguarded in Microsoft Defender for
44
ms.topic: overview
55
ms.author: dacurwin
66
author: dcurwin
7-
ms.date: 07/18/2023
7+
ms.date: 11/02/2023
88
---
99
# Microsoft Defender for Cloud data security
1010

@@ -77,10 +77,13 @@ Customers can access Defender for Cloud related data from the following data str
7777
| [Azure Monitor logs](../azure-monitor/data-platform.md) | All security alerts. |
7878
| [Azure Resource Graph](../governance/resource-graph/overview.md) | Security alerts, security recommendations, vulnerability assessment results, secure score information, status of compliance checks, and more. |
7979
| [Microsoft Defender for Cloud REST API](/rest/api/defenderforcloud/) | Security alerts, security recommendations, and more. |
80-
8180
> [!NOTE]
8281
> If there are no Defender plans enabled on the subscription, data will be removed from Azure Resource Graph after 30 days of inactivity in the Microsoft Defender for Cloud portal. After interaction with artifacts in the portal related to the subscription, the data should be visible again within 24 hours.
8382
83+
## Defender for Cloud and Microsoft Defender 365 Defender integration
84+
85+
When you enable any of Defender for Cloud's paid plans you automatically gain all of the benefits of Microsoft 365 Defender. Information from Defender for Cloud will be shared with Microsoft 365 Defender. This data may contain customer data and will be stored according to [Microsoft 365 data handling guidelines](/microsoft-365/security/defender/data-privacy?view=o365-worldwide).
86+
8487
## Next steps
8588

8689
In this document, you learned how data is managed and safeguarded in Microsoft Defender for Cloud.

articles/defender-for-cloud/defender-for-cloud-introduction.md

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,8 @@
11
---
22
title: What is Microsoft Defender for Cloud?
3-
43
description: Use Microsoft Defender for Cloud to protect your Azure, hybrid, and multicloud resources and workloads.
54
ms.topic: overview
6-
ms.date: 07/24/2023
5+
ms.date: 11/02/2023
76
---
87

98
# What is Microsoft Defender for Cloud?
@@ -14,11 +13,18 @@ Microsoft Defender for Cloud is a cloud-native application protection platform (
1413
- A cloud security posture management (CSPM) solution that surfaces actions that you can take to prevent breaches
1514
- A cloud workload protection platform (CWPP) with specific protections for servers, containers, storage, databases, and other workloads
1615

17-
![Diagram that shows the core functionality of Microsoft Defender for Cloud.](media/defender-for-cloud-introduction/defender-for-cloud-pillars.png)
16+
:::image type="content" source="media/defender-for-cloud-introduction/defender-for-cloud-pillars.png" alt-text="Diagram that shows the core functionality of Microsoft Defender for Cloud.":::
1817

1918
> [!NOTE]
2019
> For Defender for Cloud pricing information, see the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/).
2120
21+
When you [enable Defender for Cloud on your](connect-azure-subscription.md), you'll automatically gain access to Microsoft 365 Defender.
22+
23+
The Microsoft 365 Defender portal provides richer context to investigations that span cloud resources, devices, and identities. In addition, security teams are able to get the complete picture of an attack, including suspicious and malicious events that happen in their cloud environment, through the immediate correlation of all alerts and incidents, including cloud alerts and incidents.
24+
25+
You can learn more about the [integration between Microsoft Defender for Cloud and Microsoft 365 Defender](concept-integration-365.md).
26+
27+
2228
## Secure cloud applications
2329

2430
Defender for Cloud helps you to incorporate good security practices early during the software development process, or DevSecOps. You can protect your code management environments and your code pipelines, and get insights into your development environment security posture from a single location. Defender for Cloud empowers security teams to manage DevOps security across multi-pipeline environments.
@@ -31,7 +37,7 @@ Today’s applications require security awareness at the code, infrastructure, a
3137

3238
## Improve your security posture
3339

34-
The security of your cloud and on-premises resources depends on proper configuration and deployment. Defender for Cloud recommendations identify the steps that you can take to secure your environment.
40+
The security of your cloud and on-premises resources depends on proper configuration and deployment. Defender for Cloud recommendations identifies the steps that you can take to secure your environment.
3541

3642
Defender for Cloud includes Foundational CSPM capabilities for free. You can also enable advanced CSPM capabilities by enabling the Defender CSPM plan.
3743

articles/defender-for-cloud/quickstart-onboard-aws.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Connect your AWS account
33
description: Defend your AWS resources by using Microsoft Defender for Cloud.
44
ms.topic: install-set-up-deploy
55
ms.custom: devx-track-linux
6-
ms.date: 10/22/2023
6+
ms.date: 11/02/2023
77
---
88

99
# Connect your AWS account to Microsoft Defender for Cloud
@@ -241,6 +241,14 @@ To view all the active recommendations for your resources by resource type, use
241241
242242
:::image type="content" source="./media/quickstart-onboard-aws/aws-resource-types-in-inventory.png" alt-text="Screenshot of AWS options in the asset inventory page's resource type filter." lightbox="media/quickstart-onboard-aws/aws-resource-types-in-inventory.png":::
243243
244+
## Integrate with Microsoft 365 Defender
245+
246+
When you enable Defender for Cloud, Defender for Cloud's alerts are automatically integrated into the Microsoft 365 Defender portal. No further steps are needed.
247+
248+
The integration between Microsoft Defender for Cloud and Microsoft 365 Defender brings your cloud environments into Microsoft 365 Defender. With Defender for Cloud's alerts and cloud correlations integrated into Microsoft 365 Defender, SOC teams can now access all security information from a single interface.
249+
250+
Learn more about Defender for Cloud's [alerts in Microsoft 365 Defender](concept-integration-365.md).
251+
244252
## Learn more
245253
246254
Check out the following blogs:

articles/defender-for-cloud/quickstart-onboard-gcp.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -208,6 +208,14 @@ To view all the active recommendations for your resources by resource type, use
208208

209209
:::image type="content" source="./media/quickstart-onboard-gcp/gcp-resource-types-in-inventory.png" alt-text="Screenshot of GCP options in the asset inventory page's resource type filter." lightbox="media/quickstart-onboard-gcp/gcp-resource-types-in-inventory.png":::
210210

211+
## Integrate with Microsoft 365 Defender
212+
213+
When you enable Defender for Cloud, Defender for Cloud's alerts are automatically integrated into the Microsoft 365 Defender portal. No further steps are needed.
214+
215+
The integration between Microsoft Defender for Cloud and Microsoft 365 Defender brings your cloud environments into Microsoft 365 Defender. With Defender for Cloud's alerts and cloud correlations integrated into Microsoft 365 Defender, SOC teams can now access all security information from a single interface.
216+
217+
Learn more about Defender for Cloud's [alerts in Microsoft 365 Defender](concept-integration-365.md).
218+
211219
## Next steps
212220

213221
Connecting your GCP project is part of the multicloud experience available in Microsoft Defender for Cloud:

articles/defender-for-cloud/quickstart-onboard-machines.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Connect on-premises machines
33
description: Learn how to connect your non-Azure machines to Microsoft Defender for Cloud.
44
ms.topic: install-set-up-deploy
5-
ms.date: 06/29/2023
5+
ms.date: 11/02/2023
66
ms.custom: mode-other
77
---
88

@@ -147,6 +147,14 @@ To verify that your machines are connected:
147147

148148
![Defender for Cloud icon for an Azure Arc-enabled server.](./media/quickstart-onboard-machines/arc-enabled-machine-icon.png) Azure Arc-enabled server
149149

150+
## Integrate with Microsoft 365 Defender
151+
152+
When you enable Defender for Cloud, Defender for Cloud's alerts are automatically integrated into the Microsoft 365 Defender portal. No further steps are needed.
153+
154+
The integration between Microsoft Defender for Cloud and Microsoft 365 Defender brings your cloud environments into Microsoft 365 Defender. With Defender for Cloud's alerts and cloud correlations integrated into Microsoft 365 Defender, SOC teams can now access all security information from a single interface.
155+
156+
Learn more about Defender for Cloud's [alerts in Microsoft 365 Defender](concept-integration-365.md).
157+
150158
## Clean up resources
151159

152160
There's no need to clean up any resources for this article.

0 commit comments

Comments
 (0)