Skip to content

Commit 58db3a0

Browse files
committed
Microsoft 365 Defender integration to GA
1 parent 4866c5d commit 58db3a0

File tree

1 file changed

+46
-33
lines changed

1 file changed

+46
-33
lines changed

articles/sentinel/microsoft-365-defender-cloud-support.md

Lines changed: 46 additions & 33 deletions
Original file line numberDiff line numberDiff line change
@@ -15,56 +15,69 @@ Read more about [data type support for different clouds in Microsoft Sentinel](d
1515

1616
## Microsoft Defender for Endpoint
1717

18-
|Data type |Commercial |GCC |GCC-High |DoD |
19-
|---------|---------|---------|---------|---------|
20-
|DeviceInfo |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
21-
|DeviceNetworkInfo |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
22-
|DeviceProcessEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</ul></li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
23-
|DeviceNetworkEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |
24-
|DeviceFileEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
25-
|DeviceRegistryEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
26-
|DeviceLogonEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
27-
|DeviceImageLoadEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
28-
|DeviceEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
29-
|DeviceFileCertificateInfo |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |
18+
| Data type | Commercial | GCC | GCC-High | DoD |
19+
| --------- | ---------- | --------- | --------- | --------- |
20+
| **DeviceInfo** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
21+
| **DeviceNetworkInfo** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
22+
| **DeviceProcessEvents** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
23+
| **DeviceNetworkEvents** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
24+
| **DeviceFileEvents** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
25+
| **DeviceRegistryEvents** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
26+
| **DeviceLogonEvents** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
27+
| **DeviceImageLoadEvents** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
28+
| **DeviceEvents** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
29+
| **DeviceFileCertificateInfo** | GA | GA | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview | <li>**Microsoft 365 Defender:** GA<li>**Microsoft Sentinel:** Public preview |
3030

3131
## Microsoft Defender for Identity
3232

33-
|Data type |Commercial |GCC |GCC-High |DoD |
34-
|---------|---------|---------|---------|---------|
35-
|IdentityDirectoryEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |Unsupported |Unsupported |Unsupported |
36-
IdentityLogonEvents|<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |Unsupported |Unsupported |Unsupported |
37-
IdentityQueryEvents|<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li> |Unsupported |Unsupported |Unsupported |
33+
| Data type | Commercial | GCC | GCC-High | DoD |
34+
| --------------------------- | ---------- | --- | ----------- | ----------- |
35+
| **IdentityDirectoryEvents** | GA | GA | Unsupported | Unsupported |
36+
| **IdentityLogonEvents** | GA | GA | Unsupported | Unsupported |
37+
| **IdentityQueryEvents** | GA | GA | Unsupported | Unsupported |
3838

3939
## Microsoft Defender for Cloud Apps
4040

41-
|Data type |Commercial |GCC |GCC-High |DoD |
42-
|---------|---------|---------|---------|---------|
43-
|CloudAppEvents |<ul><li>Microsoft 365 Defender: GA</li><li>Microsoft Sentinel: Public Preview</li></ul> |Unsupported |Unsupported |Unsupported |
41+
| Data type | Commercial | GCC | GCC-High | DoD |
42+
| ------------------ | ---------- | --- | ----------- | ----------- |
43+
| **CloudAppEvents** | GA | GA | Unsupported | Unsupported |
44+
45+
## Microsoft Defender for Office 365
46+
47+
| Data type | Commercial | GCC | GCC-High | DoD |
48+
| --------------------------- | ---------- | --- | -------------- | -------------- |
49+
| **EmailEvents** | GA | GA | Public preview | Public preview |
50+
| **EmailAttachmentInfo** | GA | GA | Public preview | Public preview |
51+
| **EmailUrlInfo** | GA | GA | Public preview | Public preview |
52+
| **EmailPostDeliveryEvents** | GA | GA | Public preview | Public preview |
53+
| **UrlClickEvents** | GA | GA | Public preview | Public preview |
4454

4555
## Microsoft 365 Defender incidents
4656

47-
|Data type |Commercial |GCC |GCC-High |DoD |
48-
|---------|---------|---------|---------|---------|
49-
|SecurityIncident |Microsoft Sentinel: Public Preview |Microsoft Sentinel: Public Preview |Microsoft Sentinel: Public Preview |Microsoft Sentinel: Public Preview |
57+
| Data type | Commercial | GCC | GCC-High | DoD |
58+
| ---------------- | -------------- | -------------- | -------------- | -------------- |
59+
| SecurityIncident | Public preview | Public preview | Public preview | Public preview |
5060

5161
## Alerts
5262

53-
|Connector/Data type |Commercial |GCC |GCC-High |DoD |
54-
|---------|---------|---------|---------|---------|
55-
|Microsoft 365 Defender Alerts: SecurityAlert |Public Preview |Public Preview |Public Preview |Public Preview |
56-
|Microsoft Defender for Endpoint Alerts (standalone connector): SecurityAlert (MDATP) |Public Preview |Public Preview |Public Preview |Public Preview |
57-
| Microsoft Defender for Office 365 Alerts (standalone connector): SecurityAlert (OATP) |Public Preview |Public Preview |Public Preview |Public Preview |
58-
Microsoft Defender for Identity Alerts (standalone connector): SecurityAlert (AATP) |Public Preview |Unsupported |Unsupported |Unsupported |
59-
Microsoft Defender for Cloud Apps Alerts (standalone connector): SecurityAlert (MCAS), |Public Preview |Unsupported |Unsupported |Unsupported |
60-
|Microsoft Defender for Cloud Apps Alerts (standalone connector): McasShadowItReporting |Public Preview |Unsupported |Unsupported |Unsupported |
63+
| Data type | Commercial | GCC | GCC-High | DoD |
64+
| ----------------- | ---------- | --- | -------------- | -------------- |
65+
| **AlertInfo** | GA | GA | Public preview | Public preview |
66+
| **AlertEvidence** | GA | GA | Public preview | Public preview |
67+
|
68+
| Microsoft 365 Defender Alerts:<br>SecurityAlert |Public preview |Public preview |Public preview |Public preview |
69+
| Microsoft Defender for Endpoint Alerts (standalone connector):<br>SecurityAlert (MDATP) |Public preview |Public preview |Public preview |Public preview |
70+
| Microsoft Defender for Office 365 Alerts (standalone connector):<br>SecurityAlert (OATP) |Public preview |Public preview |Public preview |Public preview |
71+
| Microsoft Defender for Identity Alerts (standalone connector):<br>SecurityAlert (AATP) |Public preview |Unsupported |Unsupported |Unsupported |
72+
| Microsoft Defender for Cloud Apps Alerts (standalone connector):<br>SecurityAlert (MCAS), |Public preview |Unsupported |Unsupported |Unsupported |
73+
| Microsoft Defender for Cloud Apps Alerts (standalone connector):<br>McasShadowItReporting |Public preview |Unsupported |Unsupported |Unsupported |
6174

6275
## Azure Active Directory Identity Protection
6376

6477
|Data type |Commercial |GCC |GCC-High |DoD |
6578
|---------|---------|---------|---------|---------|
66-
|SecurityAlert (IPC) |Public Preview/GA |Supported |Supported |Supported |
67-
|AlertEvidence |Public Preview |Unsupported |Unsupported |Unsupported |
79+
|SecurityAlert (IPC) |Public preview/GA |Supported |Supported |Supported |
80+
|AlertEvidence |Public preview |Unsupported |Unsupported |Unsupported |
6881

6982
## Next steps
7083

0 commit comments

Comments
 (0)