Skip to content

Commit 5ea7790

Browse files
committed
updating for unified secops
1 parent 3ddfb03 commit 5ea7790

File tree

5 files changed

+12
-11
lines changed

5 files changed

+12
-11
lines changed

articles/sentinel/microsoft-365-defender-sentinel-integration.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@ In addition to collecting alerts from these components and other services, Defen
8888

8989
Consider integrating Defender XDR with Microsoft Sentinel for the following use cases and scenarios:
9090

91-
- Onboard Microsoft Sentinel to Microsoft's unified SecOps platform in the Microsoft Defender portal. Enabling the Defender XDR connector is a prerequisite.
91+
- Onboard Microsoft Sentinel to the Microsoft Defender portal.
9292

9393
- Enable one-click connect of Defender XDR incidents, including all alerts and entities from Defender XDR components, into Microsoft Sentinel.
9494

@@ -98,7 +98,7 @@ Consider integrating Defender XDR with Microsoft Sentinel for the following use
9898

9999
- Facilitate investigations across both portals with in-context deep links between a Microsoft Sentinel incident and its parallel Defender XDR incident.
100100

101-
For more information about the capabilities of the Microsoft Sentinel integration with Defender XDR in Microsoft's unified SecOps platform, see [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md).
101+
For more information, see [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md).
102102

103103
## Connecting to Microsoft Defender XDR <a name="microsoft-defender-xdr-incidents-and-microsoft-incident-creation-rules"></a>
104104

articles/sentinel/microsoft-sentinel-defender-portal.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ Microsoft Defender provides a unified cybersecurity solution that integrates end
2020

2121
Microsoft Sentinel is generally available in the Microsoft Defender portal, either with [Microsoft Defender XDR](/microsoft-365/security/defender), or on its own, delivering a unified experience across SIEM and XDR for faster and more accurate threat detection and response, simplified workflows, and enhanced operational efficiency.
2222

23-
This article describes the Microsoft Sentinel experience in the Defender portal. We recommend that customers using Microsoft Sentinel in the Azure portal move into Microsoft Defender to take advantage of the unified SecOps experience and the latest capabilities. For more information, see [Transition your Microsoft Sentinel environment to the Defender portal](move-to-defender.md).
23+
This article describes the Microsoft Sentinel experience in the Defender portal. We recommend that customers using Microsoft Sentinel in the Azure portal move into Microsoft Defender to take advantage of the unified security operations available and the latest capabilities. For more information, see [Transition your Microsoft Sentinel environment to the Defender portal](move-to-defender.md).
2424

2525

2626
## New and improved capabilities

articles/sentinel/move-to-defender.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.collection: usx-security
1414

1515
Microsoft Sentinel is available in the Microsoft Defender portal with [Microsoft Defender XDR](/microsoft-365/security/defender) or on its own. It delivers a unified experience across SIEM and XDR for faster, more accurate threat detection and response, simpler workflows, and better operational efficiency.
1616

17-
This article explains how to transition your Microsoft Sentinel experience from the Azure portal to the Defender portal. If you use Microsoft Sentinel in the Azure portal, transition to Microsoft Defender to get the unified SecOps experience and the latest features. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md).
17+
This article explains how to transition your Microsoft Sentinel experience from the Azure portal to the Defender portal. If you use Microsoft Sentinel in the Azure portal, transition to Microsoft Defender for unified security operations and the latest features. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](microsoft-sentinel-defender-portal.md).
1818

1919
## Prerequisites
2020

articles/sentinel/understand-threat-intelligence.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -126,7 +126,7 @@ For more information, see [Connect Microsoft Sentinel to STIX/TAXII threat intel
126126

127127
## Create and manage threat intelligence
128128

129-
Threat intelligence powered by Microsoft Sentinel is managed next to Microsoft Defender Threat Intelligence (MDTI) and Threat Analytics in Microsoft's unified SecOps platform.
129+
Threat intelligence powered by Microsoft Sentinel is managed next to Microsoft Defender Threat Intelligence (MDTI) and Threat Analytics in in the Microsoft Defender portal
130130

131131
:::image type="content" source="media/understand-threat-intelligence/intel-management-defender-portal.png" alt-text="Screenshot showing intel management page in the Defender portal." lightbox="media/understand-threat-intelligence/intel-management-defender-portal.png":::
132132

@@ -265,5 +265,5 @@ For more information on using and customizing the **Threat Intelligence** workbo
265265
In this article, you learned about threat intelligence capabilities powered by Microsoft Sentinel. For more information, see the following articles:
266266

267267
- [New STIX objects in Microsoft Sentinel](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/announcing-public-preview-new-stix-objects-in-microsoft-sentinel/4369164)
268-
- [Uncover adversaries with threat intelligence in Microsoft's unified SecOps platform](/unified-secops-platform/threat-intelligence-overview)
269-
- [Hunting in Microsoft's unified SecOps platform](/unified-secops-platform/hunting-overview)
268+
- [Uncover adversaries with threat intelligence in the Defender portal](/unified-secops-platform/threat-intelligence-overview)
269+
- [Hunting in the Defender portal](/unified-secops-platform/hunting-overview)

articles/sentinel/whats-new.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.date: 05/06/2025
1212

1313
# What's new in Microsoft Sentinel
1414

15-
This article lists recent features added for Microsoft Sentinel, and new features in related services that provide an enhanced user experience in Microsoft Sentinel. For new features related unified security operations in the Defender portal, see the [unified SecOps documentation](/unified-secops-platform/whats-new).
15+
This article lists recent features added for Microsoft Sentinel, and new features in related services that provide an enhanced user experience in Microsoft Sentinel. For new features related unified security operations in the Defender portal, see the [What's new for unified security operations?](/unified-secops-platform/whats-new)
1616

1717
The listed features were released in the last six months. For information about earlier features delivered, see our [Tech Community blogs](https://techcommunity.microsoft.com/t5/azure-sentinel/bg-p/AzureSentinelBlog/label-name/What's%20New).
1818

@@ -25,7 +25,7 @@ The listed features were released in the last six months. For information about
2525

2626
### Unified *IdentityInfo* table
2727

28-
Customers of Microsoft Sentinel in the Defender portal who have enabled UEBA can now take advantage of a new version of the IdentityInfo table, located in the Defender portal's *Advanced hunting* section, that includes the largest possible set of fields common to both the Defender and Azure portals. This unified table helps enrich your security investigations across the entire unified SecOps experience.
28+
Customers of Microsoft Sentinel in the Defender portal who have enabled UEBA can now take advantage of a new version of the **IdentityInfo** table, located in the Defender portal's *Advanced hunting* section, that includes the largest possible set of fields common to both the Defender and Azure portals. This unified table helps enrich your security investigations across the entire Defender portal.
2929

3030
For more information, see [IdentityInfo table](ueba-reference.md#identityinfo-table).
3131

@@ -80,6 +80,7 @@ For more information, see the following articles:
8080

8181

8282
### SOC optimization support for unused columns (Preview)
83+
8384
To optimize your cost/security value ratio, SOC optimization surfaces hardly used data connectors or tables. SOC optimization now surfaces unused columns in your tables. For more information, see [SOC optimization reference of recommendations](soc-optimization/soc-optimization-reference.md#unused-columns-preview).
8485

8586
## March 2025
@@ -139,7 +140,7 @@ Enhancements to threat intelligence capabilities are available for customers usi
139140
For more information, see the following articles:
140141
- [New STIX objects in Microsoft Sentinel](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/announcing-public-preview-new-stix-objects-in-microsoft-sentinel/4369164)
141142
- [Understand threat intelligence](understand-threat-intelligence.md#create-and-manage-threat-intelligence)
142-
- [Uncover adversaries with threat intelligence in Microsoft's unified SecOps platform](/unified-secops-platform/threat-intelligence-overview)
143+
- [Uncover adversaries with threat intelligence in the Defender portal](/unified-secops-platform/threat-intelligence-overview)
143144

144145
### Unlock advanced hunting with new STIX objects by opting in to new threat intelligence tables
145146

@@ -178,7 +179,7 @@ For more information, see [Plan your repository content](ci-cd-custom-content.md
178179

179180
### SOC optimization updates for unified coverage management
180181

181-
In workspaces enabled for unified security operations, SOC optimizations now support both SIEM and XDR data, with detection coverage from across Microsoft Defender services.
182+
In workspaces onboarded to the Defender portal, SOC optimizations now support both SIEM and XDR data, with detection coverage from across Microsoft Defender services.
182183

183184
In the Defender portal, the **SOC optimizations** and **MITRE ATT&CK** pages also now provide extra functionality for threat-based coverage optimizations to help you understand the impact of the recommendations on your environment and help you prioritize which to implement first.
184185

0 commit comments

Comments
 (0)