You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/connect-microsoft-365-defender.md
+1-3Lines changed: 1 addition & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -29,7 +29,7 @@ Before you begin, you must have the appropriate licensing, access, and configure
29
29
- To make any changes to the connector settings, your user must be a member of the same Microsoft Entra tenant with which your Microsoft Sentinel workspace is associated.
30
30
- Install the solution for **Microsoft Defender XDR** from the **Content Hub** in Microsoft Sentinel. For more information, see [Discover and manage Microsoft Sentinel out-of-the-box content](sentinel-solutions-deploy.md).
31
31
32
-
For Microsoft Entra ID sync via Microsoft Defender for Identity:
32
+
For on-premises Active Directory sync via Microsoft Defender for Identity:
33
33
34
34
- Your tenant must be onboarded to Microsoft Defender for Identity.
35
35
@@ -69,8 +69,6 @@ When you enable the Microsoft Defender XDR connector, all of the Microsoft Defen
69
69
70
70
Use Microsoft Defender for Identity to sync user entities from your on-premises Active Directory to Microsoft Sentinel.
71
71
72
-
Verify that you satisfied the [prerequisites](#prerequisites-for-active-directory-sync-via-mdi) for syncing on-premises Active Directory users through Microsoft Defender for Identity (MDI).
73
-
74
72
1. Select the **Go the UEBA configuration page** link.
75
73
76
74
1. In the **Entity behavior configuration** page, if you didn't enable UEBA, then at the top of the page, move the toggle to **On**.
Copy file name to clipboardExpand all lines: articles/sentinel/microsoft-365-defender-sentinel-integration.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@ title: Microsoft Defender XDR integration with Microsoft Sentinel
3
3
description: Learn how using Microsoft Defender XDR together with Microsoft Sentinel lets you use Microsoft Sentinel as your universal incidents queue.
4
4
author: yelevin
5
5
ms.author: yelevin
6
-
ms.topic: concept
6
+
ms.topic: conceptual
7
7
ms.date: 06/11/2024
8
8
appliesto:
9
9
- Microsoft Sentinel in the Azure portal and the Microsoft Defender portal
@@ -39,7 +39,7 @@ In addition to collecting alerts from these components and other services, Defen
39
39
40
40
Consider integrating Defender XDR with Microsoft Sentinel for the following use cases and scenarios:
41
41
42
-
- Onboard Microsoft Sentinel to the unified security operations platform in the Microsoft Defender portal, of which enabling the Defender XDR integration is a prerequisite. For more information, see [Connect Microsoft Sentinel to Microsoft Defender XDR](/defender-xdr/microsoft-sentinel-onboard?view=o365-worldwide).
42
+
- Onboard Microsoft Sentinel to the unified security operations platform in the Microsoft Defender portal, of which enabling the Defender XDR integration is a prerequisite. For more information, see [Connect Microsoft Sentinel to Microsoft Defender XDR](/defender-xdr/microsoft-sentinel-onboard).
43
43
44
44
- One-click connect of Defender XDR incidents, including all alerts and entities from Defender XDR components, into Microsoft Sentinel.
45
45
@@ -102,7 +102,7 @@ The Defender XDR connector also lets you stream **advanced hunting** events - a
102
102
103
103
In this document, you learned the benefit of using Defender XDR together with Microsoft Sentinel, by enabling the Defender XDR connector in Microsoft Sentinel.
104
104
105
-
-[Connect data from Microsoft Defender XDR to Microsoft Sentinel](connect-microsoft-365-defender)
105
+
-[Connect data from Microsoft Defender XDR to Microsoft Sentinel](connect-microsoft-365-defender.md)
106
106
- To use the unified security operations platform in the Defender portal, see [Connect data from Microsoft Defender XDR to Microsoft Sentinel](connect-microsoft-365-defender.md).
107
107
- Check [availability of different Microsoft Defender XDR data types](microsoft-365-defender-cloud-support.md) in the different Microsoft 365 and Azure clouds.
108
108
- Create [custom alerts](detect-threats-custom.md) and [investigate incidents](investigate-incidents.md).
0 commit comments