Skip to content

Commit 54f8277

Browse files
committed
Add diagrams from zero trust and lift some text
1 parent 4b749af commit 54f8277

File tree

4 files changed

+36
-6
lines changed

4 files changed

+36
-6
lines changed
129 KB
Loading
120 KB
Loading

articles/sentinel/microsoft-365-defender-sentinel-integration.md

Lines changed: 36 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn how using Microsoft Defender XDR together with Microsoft Sent
44
author: yelevin
55
ms.author: yelevin
66
ms.topic: conceptual
7-
ms.date: 07/01/2024
7+
ms.date: 07/03/2024
88
appliesto:
99
- Microsoft Sentinel in the Azure portal and the Microsoft Defender portal
1010
ms.collection: usx-security
@@ -21,11 +21,43 @@ Alternatively, onboard Microsoft Sentinel with Defender XDR to the unified secur
2121
- [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md)
2222
- [Microsoft Copilot in Microsoft Defender](/defender-xdr/security-copilot-in-microsoft-365-defender)
2323

24-
## Integration of Defender XDR with Microsoft Sentinel
24+
## Microsoft Sentinel and Defender XDR
2525

26-
Watch this short overview of Microsoft Sentinel integration with Microsoft Defender XDR (4 minutes). This video applies to the Defender XDR integration with Microsoft Sentinel in the Azure portal.
26+
Microsoft Sentinel customers can use one of the following methods to integrate Microsoft Sentinel with Microsoft Defender XDR services:
2727

28-
>[!VIDEO https://www.microsoft.com/en-us/videoplayer/embed/RWFIRo]
28+
- Ingest Microsoft Defender XDR service data into Microsoft Sentinel and view Microsoft Sentinel data in the Azure portal. Enable the Defender XDR connector in Microsoft Sentinel.
29+
30+
- Integrate Microsoft Sentinel and Defender XDR into a single, unified security operations platform in the Microsoft Defender portal. In this case, view Microsoft Sentinel data directly in the Microsoft Defender portal with the rest of your Defender incidents, alerts, vulnerabilities, and other security data. Enable the Defender XDR connector in Microsoft Sentinel and onboard Microsoft Sentinel to unified operations platform in the Defender portal.
31+
32+
Select the appropriate tab to see what the Microsoft Sentinel integration with Defender XDR looks like depending on which integration methods you use.
33+
34+
## [Azure portal](#tab/azure-portal)
35+
36+
The following illustration shows how Microsoft's XDR solution seamlessly integrates with Microsoft Sentinel.
37+
38+
:::image type="content" source="./media/microsoft-365-defender-sentinel-integration/sentinel-xdr.png" alt-text="Diagram of the integration of Microsoft Sentinel and Microsoft XDR." lightbox="./media/microsoft-365-defender-sentinel-integration/sentinel-xdr.png" border="false":::
39+
40+
In this diagram:
41+
42+
- Insights from signals across your entire organization feed into Microsoft Defender XDR and Microsoft Defender for Cloud.
43+
- Microsoft Defender XDR and Microsoft Defender for Cloud send SIEM log data through Microsoft Sentinel connectors.
44+
- SecOps teams can then analyze and respond to threats identified in Microsoft Sentinel and Microsoft Defender XDR.
45+
- Microsoft Sentinel provides support for multicloud environments and integrates with third-party apps and partners.
46+
47+
## [Defender portal](#tab/defender-portal)
48+
49+
The following illustration shows how Microsoft's XDR solution seamlessly integrates with Microsoft Sentinel with the unified security operations platform.
50+
51+
:::image type="content" source="./media/microsoft-365-defender-sentinel-integration/sentinel-xdr-usx.png" alt-text="Diagram of a Microsoft Sentinel and Microsoft Defender XDR architecture with the unified security operations platform." lightbox="./media/microsoft-365-defender-sentinel-integration/sentinel-xdr-usx.png" border="false":::
52+
53+
In this diagram:
54+
55+
- Insights from signals across your entire organization feed into Microsoft Defender XDR and Microsoft Defender for Cloud.
56+
- Microsoft Sentinel provides support for multicloud environments and integrates with third-party apps and partners.
57+
- Microsoft Sentinel data is ingested together with your organization's data into the Microsoft Defender portal.
58+
- SecOps teams can then analyze and respond to threats identified by Microsoft Sentinel and Microsoft Defender XDR in the Microsoft Defender portal.
59+
60+
---
2961

3062
## Incident correlation and alerts
3163

@@ -46,9 +78,7 @@ The Defender XDR connector also brings incidents from Microsoft Defender for Clo
4678

4779
In addition to collecting alerts from these components and other services, Defender XDR generates alerts of its own. It creates incidents from all of these alerts and sends them to Microsoft Sentinel.
4880

49-
The following diagram shows how incident data flows into both the Azure and Defender portals.
5081

51-
:::image type="content" source="media/microsoft-365-defender-sentinel-integration/microsoft-365-defender-integration-with-azure-sentinel.png" alt-text="Diagram that shows the flow of incident data for Defender XDR to Microsoft Sentinel in both the Azure and Defender portals." lightbox="media/microsoft-365-defender-sentinel-integration/microsoft-365-defender-integration-with-azure-sentinel.png":::
5282

5383
## Common use cases and scenarios
5484

0 commit comments

Comments
 (0)