Skip to content

Commit e3d3265

Browse files
committed
Cnt MDC - Add prerq 4 CH
1 parent 8805d09 commit e3d3265

File tree

1 file changed

+7
-9
lines changed

1 file changed

+7
-9
lines changed

articles/sentinel/connect-defender-for-cloud.md

Lines changed: 7 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -10,29 +10,26 @@ ms.custom: ignite-fall-2021
1010

1111
# Connect Microsoft Defender for Cloud alerts to Microsoft Sentinel
1212

13-
## Background
14-
15-
> [!NOTE]
16-
> - Microsoft Defender for Cloud was formerly known as Azure Security Center.
17-
> - Defender for Cloud's enhanced security features were formerly known collectively as Azure Defender.
18-
1913
[Microsoft Defender for Cloud](../defender-for-cloud/index.yml)'s integrated cloud workload protections allow you to detect and quickly respond to threats across hybrid and multi-cloud workloads.
2014

2115
This connector allows you to stream [security alerts from Defender for Cloud](../defender-for-cloud/alerts-reference.md) into Microsoft Sentinel, so you can view, analyze, and respond to Defender alerts, and the incidents they generate, in a broader organizational threat context.
2216

2317
As [Microsoft Defender for Cloud Defender plans](../defender-for-cloud/defender-for-cloud-introduction.md#protect-cloud-workloads) are enabled per subscription, this data connector is also enabled or disabled separately for each subscription.
2418

19+
Microsoft Defender for Cloud was formerly known as Azure Security Center. Defender for Cloud's enhanced security features were formerly known collectively as Azure Defender.
20+
21+
2522
[!INCLUDE [reference-to-feature-availability](includes/reference-to-feature-availability.md)]
2623

27-
### Alert synchronization
24+
## Alert synchronization
2825

2926
- When you connect Microsoft Defender for Cloud to Microsoft Sentinel, the status of security alerts that get ingested into Microsoft Sentinel is synchronized between the two services. So, for example, when an alert is closed in Defender for Cloud, that alert will display as closed in Microsoft Sentinel as well.
3027

3128
- Changing the status of an alert in Defender for Cloud will *not* affect the status of any Microsoft Sentinel **incidents** that contain the Microsoft Sentinel alert, only that of the alert itself.
3229

33-
### Bi-directional alert synchronization
30+
## Bi-directional alert synchronization
3431

35-
- Enabling **bi-directional sync** will automatically sync the status of original security alerts with that of the Microsoft Sentinel incidents that contain those alerts. So, for example, when a Microsoft Sentinel incident containing a security alerts is closed, the corresponding original alert will be closed in Microsoft Defender for Cloud automatically.
32+
Enabling **bi-directional sync** will automatically sync the status of original security alerts with that of the Microsoft Sentinel incidents that contain those alerts. So, for example, when a Microsoft Sentinel incident containing a security alerts is closed, the corresponding original alert will be closed in Microsoft Defender for Cloud automatically.
3633

3734
## Prerequisites
3835

@@ -45,6 +42,7 @@ As [Microsoft Defender for Cloud Defender plans](../defender-for-cloud/defender-
4542
- You will need the `SecurityInsights` resource provider to be registered for each subscription where you want to enable the connector. Review the guidance on the [resource provider registration status](../azure-resource-manager/management/resource-providers-and-types.md#register-resource-provider) and the ways to register it.
4643

4744
- To enable bi-directional sync, you must have the **Contributor** or **Security Admin** role on the relevant subscription.
45+
- Install the solution for **Microsoft Defender for Cloud** from the **Content Hub** in Microsoft Sentinel. For more information, see [Discover and manage Microsoft Sentinel out-of-the-box content](sentinel-solutions-deploy.md).
4846

4947
## Connect to Microsoft Defender for Cloud
5048

0 commit comments

Comments
 (0)