Skip to content

Commit a48ca65

Browse files
committed
pre review comments
1 parent 80cabcc commit a48ca65

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

articles/sentinel/move-to-defender.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ Before you start, note:
3030

3131
### Review planning guidance, complete prerequisites, and onboard
3232

33-
Review all planning guidance and finish all prerequisites before you start onboarding your workspace to the Defender portal. For more information, see the following articles:
33+
Review all planning guidance and finish all prerequisites before you onboard your workspace to the Defender portal. For more information, see the following articles:
3434

3535
- [**Plan for unified security operations in the Defender portal**](/unified-secops-platform/overview-plan)
3636

@@ -40,7 +40,7 @@ Review all planning guidance and finish all prerequisites before you start onboa
4040

4141
### Review differences for data storage and privacy
4242

43-
When working in the Azure portal, the [Microsoft Sentinel policies](geographical-availability-data-residency.md) for data storage, process, retention, and sharing apply. When working in the Defender portal, the [Microsoft Defender XDR policies](/defender-xdr/data-privacy) apply instead, even when you're working with Microsoft Sentinel data.
43+
When you use the Azure portal, the [Microsoft Sentinel policies](geographical-availability-data-residency.md) for data storage, process, retention, and sharing apply. When you use the Defender portal, the [Microsoft Defender XDR policies](/defender-xdr/data-privacy) apply instead, even when you work with Microsoft Sentinel data.
4444

4545
The following table provides additional details and links so that you can compare experiences across the Azure and Defender portals.
4646

@@ -169,7 +169,7 @@ Analysts can also view detection sources and product names in the Defender porta
169169

170170
The unified triage process can help reduce analyst workloads and even potentially combine the roles of tier 1 and tier 2 analysts. However, the unified triage process can also require broader and deeper analyst knowledge. We recommend training on the new portal interface to ensure a smooth transition.
171171

172-
For more information, see [Incidents and alerts in the Microsoft Defender portal](/defender-xdr/incidents-overview?branch=main&branchFallbackFrom=pr-en-us-294911&toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json).
172+
For more information, see [Incidents and alerts in the Microsoft Defender portal](/defender-xdr/incidents-overview&toc=%2Fazure%2Fsentinel%2FTOC.json&bc=%2Fazure%2Fsentinel%2Fbreadcrumb%2Ftoc.json).
173173

174174
### Understand how alerts are correlated and incidents are merged in the Defender portal
175175

@@ -219,7 +219,7 @@ Most functionalities of User and Entity Behavior Analytics (UEBA) remain the sam
219219

220220
- Adding entities to threat intelligence from incidents is supported only in the Azure portal. For more information, see [Add entity to threat indicators](add-entity-to-threat-intelligence.md).
221221

222-
- After onboarding Microsoft Sentinel to the Defender portal, the `IdentityInfo` table used in the Defender portal includes unified fields from both Defender XDR and Microsoft Sentinel. Some fields that existed when used in the Azure portal are either renamed in the Defender portal, or aren't supported at all. We recommend that you check your queries for any references to these fields and update them as needed. For more information, see [IdentityInfo table](/azure/sentinel/ueba-reference?branch=pr-en-us-294911&tabs=unified-table#identityinfo-table).
222+
- After onboarding Microsoft Sentinel to the Defender portal, the `IdentityInfo` table used in the Defender portal includes unified fields from both Defender XDR and Microsoft Sentinel. Some fields that existed when used in the Azure portal are either renamed in the Defender portal, or aren't supported at all. We recommend that you check your queries for any references to these fields and update them as needed. For more information, see [IdentityInfo table](ueba-reference.md?tabs=unified-table#identityinfo-table).
223223

224224
### Update investigation processes to use Microsoft Defender threat intelligence
225225

0 commit comments

Comments
 (0)