You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/microsoft-365-defender-sentinel-integration.md
+36-6Lines changed: 36 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: Learn how using Microsoft Defender XDR together with Microsoft Sent
4
4
author: yelevin
5
5
ms.author: yelevin
6
6
ms.topic: conceptual
7
-
ms.date: 07/01/2024
7
+
ms.date: 07/03/2024
8
8
appliesto:
9
9
- Microsoft Sentinel in the Azure portal and the Microsoft Defender portal
10
10
ms.collection: usx-security
@@ -21,11 +21,43 @@ Alternatively, onboard Microsoft Sentinel with Defender XDR to the unified secur
21
21
-[Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md)
22
22
-[Microsoft Copilot in Microsoft Defender](/defender-xdr/security-copilot-in-microsoft-365-defender)
23
23
24
-
## Integration of Defender XDR with Microsoft Sentinel
24
+
## Microsoft Sentinel and Defender XDR
25
25
26
-
Watch this short overview of Microsoft Sentinel integration with Microsoft Defender XDR (4 minutes). This video applies to the Defender XDR integration with Microsoft Sentinel in the Azure portal.
26
+
Microsoft Sentinel customers can use one of the following methods to integrate Microsoft Sentinel with Microsoft Defender XDR services:
- Ingest Microsoft Defender XDR service data into Microsoft Sentinel and view Microsoft Sentinel data in the Azure portal. Enable the Defender XDR connector in Microsoft Sentinel.
29
+
30
+
- Integrate Microsoft Sentinel and Defender XDR into a single, unified security operations platform in the Microsoft Defender portal. In this case, view Microsoft Sentinel data directly in the Microsoft Defender portal with the rest of your Defender incidents, alerts, vulnerabilities, and other security data. Enable the Defender XDR connector in Microsoft Sentinel and onboard Microsoft Sentinel to unified operations platform in the Defender portal.
31
+
32
+
Select the appropriate tab to see what the Microsoft Sentinel integration with Defender XDR looks like depending on which integration methods you use.
33
+
34
+
## [Azure portal](#tab/azure-portal)
35
+
36
+
The following illustration shows how Microsoft's XDR solution seamlessly integrates with Microsoft Sentinel.
37
+
38
+
:::image type="content" source="./media/microsoft-365-defender-sentinel-integration/sentinel-xdr.png" alt-text="Diagram of the integration of Microsoft Sentinel and Microsoft XDR." lightbox="./media/microsoft-365-defender-sentinel-integration/sentinel-xdr.png" border="false":::
39
+
40
+
In this diagram:
41
+
42
+
- Insights from signals across your entire organization feed into Microsoft Defender XDR and Microsoft Defender for Cloud.
43
+
- Microsoft Defender XDR and Microsoft Defender for Cloud send SIEM log data through Microsoft Sentinel connectors.
44
+
- SecOps teams can then analyze and respond to threats identified in Microsoft Sentinel and Microsoft Defender XDR.
45
+
- Microsoft Sentinel provides support for multicloud environments and integrates with third-party apps and partners.
46
+
47
+
## [Defender portal](#tab/defender-portal)
48
+
49
+
The following illustration shows how Microsoft's XDR solution seamlessly integrates with Microsoft Sentinel with the unified security operations platform.
50
+
51
+
:::image type="content" source="./media/microsoft-365-defender-sentinel-integration/sentinel-xdr-usx.png" alt-text="Diagram of a Microsoft Sentinel and Microsoft Defender XDR architecture with the unified security operations platform." lightbox="./media/microsoft-365-defender-sentinel-integration/sentinel-xdr-usx.png" border="false":::
52
+
53
+
In this diagram:
54
+
55
+
- Insights from signals across your entire organization feed into Microsoft Defender XDR and Microsoft Defender for Cloud.
56
+
- Microsoft Sentinel provides support for multicloud environments and integrates with third-party apps and partners.
57
+
- Microsoft Sentinel data is ingested together with your organization's data into the Microsoft Defender portal.
58
+
- SecOps teams can then analyze and respond to threats identified by Microsoft Sentinel and Microsoft Defender XDR in the Microsoft Defender portal.
59
+
60
+
---
29
61
30
62
## Incident correlation and alerts
31
63
@@ -46,9 +78,7 @@ The Defender XDR connector also brings incidents from Microsoft Defender for Clo
46
78
47
79
In addition to collecting alerts from these components and other services, Defender XDR generates alerts of its own. It creates incidents from all of these alerts and sends them to Microsoft Sentinel.
48
80
49
-
The following diagram shows how incident data flows into both the Azure and Defender portals.
50
81
51
-
:::image type="content" source="media/microsoft-365-defender-sentinel-integration/microsoft-365-defender-integration-with-azure-sentinel.png" alt-text="Diagram that shows the flow of incident data for Defender XDR to Microsoft Sentinel in both the Azure and Defender portals." lightbox="media/microsoft-365-defender-sentinel-integration/microsoft-365-defender-integration-with-azure-sentinel.png":::
0 commit comments