Skip to content

Commit 026d9db

Browse files
authored
Merge branch 'main' into diannegali-mtonewsecuritypolicies
2 parents 5fd59d0 + 4ce134c commit 026d9db

File tree

107 files changed

+602
-408
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

107 files changed

+602
-408
lines changed

.acrolinx-config.edn

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{:changed-files-limit 30
22
:allowed-branchname-matches ["main" "release-.*"]
3-
:allowed-filename-matches ["defender-xdr/" "exposure-management/"] ;; Can be overridden in repo-specific edn file. This is an allow list that identifies which folders contain the files Acrolinx will check. Separate multiple folders as follows ["folder/" "folder2"]
3+
:allowed-filename-matches ["defender-xdr/" "exposure-management/" "defender/" "defender-business/" "defender-vulnerability-management/" "defender-office-365/"] ;; Can be overridden in repo-specific edn file. This is an allow list that identifies which folders contain the files Acrolinx will check. Separate multiple folders as follows ["folder/" "folder2"]
44

55
:use-gh-statuses true
66

defender-business/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@
102102
- name: Troubleshooting
103103
href: mdb-troubleshooting.yml
104104
- name: API reference information
105-
href: /defender-endpoint/api/exposed-apis-create-app-partners.md?bc=%2Fmicrosoft-365%2Fsecurity%2Fdefender-business%2Fbreadcrumb%2Ftoc.json&toc=%2Fmicrosoft-365%2Fsecurity%2Fdefender-business%2Ftoc.json
105+
href: /defender-endpoint/api/exposed-apis-create-app-partners?bc=%2Fmicrosoft-365%2Fsecurity%2Fdefender-business%2Fbreadcrumb%2Ftoc.json&toc=%2Fmicrosoft-365%2Fsecurity%2Fdefender-business%2Ftoc.json
106106
- name: Microsoft 365 Business Premium
107107
href: /microsoft-365/business-premium/
108108
- name: Microsoft 365 Lighthouse

defender-business/get-defender-business.md

Lines changed: 22 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -4,15 +4,18 @@ description: Find out how to get Microsoft Defender for Business, endpoint prote
44
search.appverid: MET150
55
author: siosulli
66
ms.author: siosulli
7-
manager: deniseb
7+
manager: deniseb
8+
89
audience: Admin
910
ms.topic: overview
1011
ms.service: defender-business
1112
ms.localizationpriority: medium
1213
ms.date: 09/07/2023
1314
ms.reviewer: efratka
14-
f1.keywords: NOCSH
15-
ms.collection:
15+
f1.keywords: NOCSH
16+
17+
ms.collection:
18+
1619
- SMB
1720
- m365-security
1821
- tier1
@@ -52,7 +55,7 @@ Defender for Business provides advanced security protection for your company's d
5255

5356
If you're starting a trial, look for your acceptance email, which contains your promo code and a link to sign in. And be sure to see the [Trial user guide for Defender for Business](trial-playbook-defender-business.md).
5457

55-
2. Go to the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)), and either sign in using your existing work or school account, or follow the prompts to create a new account.
58+
2. Go to the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)), and either sign in using your existing work or school account, or follow the prompts to create a new account.
5659

5760
3. In the [Microsoft Defender portal](https://security.microsoft.com), in the navigation bar, go to **Assets** > **Devices**. This action initiates the provisioning of Defender for Business for your tenant. You know this process has started when you see a message like what's displayed in the following screenshot:
5861

@@ -73,7 +76,7 @@ Microsoft 365 Business Premium includes Defender for Business, Microsoft Defende
7376

7477
3. After you've signed up for Microsoft 365 Business Premium, you'll receive an email with a link to sign in and get started. Proceed to [Set up Microsoft 365 Business Premium](/Microsoft-365/business-premium/m365-business-premium-setup).
7578

76-
4. Go to the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)), where you view and manage security settings and devices for your organization. In the navigation bar, go to **Assets** > **Devices**. This action initiates the provisioning of Defender for Business for your tenant.
79+
4. Go to the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)), where you view and manage security settings and devices for your organization. In the navigation bar, go to **Assets** > **Devices**. This action initiates the provisioning of Defender for Business for your tenant.
7780

7881
5. Follow the guidance in [Boost your security protection](/Microsoft-365/business-premium/m365bp-security-overview) to set up your security capabilities.
7982

@@ -84,13 +87,14 @@ Microsoft 365 Business Premium includes Defender for Business, Microsoft Defende
8487

8588
Microsoft has a list of solution providers who are authorized to sell offerings, including Microsoft 365 Business Premium and Microsoft Defender for Business. If you'd prefer to work with a Microsoft partner, you can follow these steps to find a solution provider in your area:
8689

87-
1. Go to the [Browse Partners](https:/appsource.microsoft.com/marketplace/partner-dir).
90+
1. Go to the [Browse Partners](https://appsource.microsoft.com/marketplace/partner-dir).
8891

8992
2. In the **Filters** pane, specify search criteria, such as:
9093

9194
- Your location
9295
- Your organization's size
93-
- **Focus areas**, such as **Security** and/or **Threat Protection**
96+
- **Focus areas**, such as **Security** and/or **Threat Protection**
97+
9498
- **Services**, such as **Licensing** or **Managed Services (MSP)**
9599

96100
As soon as you select one or more criteria, the list of partners updates.
@@ -101,38 +105,38 @@ Microsoft has a list of solution providers who are authorized to sell offerings,
101105

102106
## How to get Microsoft Defender for Business servers
103107

104-
Microsoft Defender for Business servers is an add-on to Defender for Business that enables you to secure your server operating systems with the same protection that you get for client devices in Defender for Business.
108+
Microsoft Defender for Business servers is an add-on to Defender for Business that enables you to secure your server operating systems with the same protection that you get for client devices in Defender for Business.
105109

106110
1. Go to the Microsoft 365 admin center ([https://admin.microsoft.com/](https://admin.microsoft.com/)), and sign in.
107111

108112
2. In the navigation pane, choose **Billing** > **Purchase services**.
109113

110114
3. In the list of results, select the **Details** box for **Microsoft Defender for Business servers**.
111115

112-
4. Review the information, and complete the purchase process. You need one Microsoft Defender for Business servers license for each instance of Windows Server or Linux, and you don't assign that license to users or devices.
116+
4. Review the information, and complete the purchase process. You need one Microsoft Defender for Business servers license for each instance of Windows Server or Linux, and you don't assign that license to users or devices.
113117

114118
> [!IMPORTANT]
115-
> - In order to add on Microsoft Defender for Business servers, you'll need at least one paid license for [Defender for Business](mdb-overview.md) (standalone) or [Microsoft 365 Business Premium](/Microsoft-365/business-premium/m365bp-overview).
119+
>
120+
> - In order to add on Microsoft Defender for Business servers, you'll need at least one paid license for [Defender for Business](mdb-overview.md) (standalone) or [Microsoft 365 Business Premium](/Microsoft-365/business-premium/m365bp-overview).
121+
>
116122
> - There's a limit of 60 Microsoft Defender for Business servers licenses per subscription to Microsoft 365 Business Premium or Defender for Business.
117123
> - If preferred, you could use [Microsoft Defender for Servers Plan 1 or Plan 2](/azure/defender-for-cloud/plan-defender-for-servers) instead to onboard your servers. To learn more, see [What happens if I have a mix of Microsoft endpoint security subscriptions](mdb-faq.yml#what-happens-if-i-have-a-mix-of-microsoft-endpoint-security-subscriptions)?
118-
119124
120125
## Portals you use for setup and management
121126

122-
When you use Defender for Business, you work with two main portals:
127+
When you use Defender for Business, you work with two main portals:
123128

124129
- The Microsoft 365 admin center ([https://admin.microsoft.com](https://admin.microsoft.com))
125130
- The Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com))
126131

127132
If your subscription also includes Microsoft Intune, you use the Intune admin center ([https://intune.microsoft.com](https://intune.microsoft.com)) as well. The following table summarizes these portals and how you use them.
128133

129-
|Portal |Description |
130-
|---------|---------|
131-
| The Microsoft 365 admin center ([https://admin.microsoft.com/](https://admin.microsoft.com/)) | Use the Microsoft 365 admin center to activate your trial and sign in for the first time. You can also use the Microsoft 365 admin center to: <br/>- Add or remove users.<br/>- Assign user licenses.<br/>- View your products and services.<br/>- Complete setup tasks for your Microsoft 365 subscription.<br/><br/>To learn more, see [Overview of the Microsoft 365 admin center](/Microsoft-365/admin/admin-overview/admin-center-overview). |
132-
| The Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)) | Use the Microsoft Defender portal to set up and configure Defender for Business, and to monitor your devices and threat detections. You use the Microsoft Defender portal to: <br/>- View your devices and device protection policies.<br/>- View detected threats and take action.<br/>- View security recommendations and manage your security settings.<br/><br/>To learn more, see [Get started using the Microsoft Defender portal](mdb-get-started.md). |
133-
| The Intune admin center ([https://intune.microsoft.com/](https://intune.microsoft.com/)) | Use the Intune admin center to set up multifactor authentication (MFA), onboard iOS and Android devices, and configure certain capabilities, such as [attack surface reduction rules](mdb-asr.md).<br/><br/>To learn more about Intune, see [Microsoft Intune is an MDM and MAM provider for your devices](/mem/intune/fundamentals/what-is-intune). |
134+
|Portal|Description|
135+
|---|---|
136+
|The Microsoft 365 admin center ([https://admin.microsoft.com/](https://admin.microsoft.com/))|Use the Microsoft 365 admin center to activate your trial and sign in for the first time. You can also use the Microsoft 365 admin center to: <br/>- Add or remove users.<br/>- Assign user licenses.<br/>- View your products and services.<br/>- Complete setup tasks for your Microsoft 365 subscription.<br/><br/>To learn more, see [Overview of the Microsoft 365 admin center](/Microsoft-365/admin/admin-overview/admin-center-overview).|
137+
|The Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com))|Use the Microsoft Defender portal to set up and configure Defender for Business, and to monitor your devices and threat detections. You use the Microsoft Defender portal to: <br/>- View your devices and device protection policies.<br/>- View detected threats and take action.<br/>- View security recommendations and manage your security settings.<br/><br/>To learn more, see [Get started using the Microsoft Defender portal](mdb-get-started.md).|
138+
|The Intune admin center ([https://intune.microsoft.com/](https://intune.microsoft.com/))|Use the Intune admin center to set up multifactor authentication (MFA), onboard iOS and Android devices, and configure certain capabilities, such as [attack surface reduction rules](mdb-asr.md).<br/><br/>To learn more about Intune, see [Microsoft Intune is an MDM and MAM provider for your devices](/mem/intune/fundamentals/what-is-intune).|
134139

135140
## Next step
136141

137142
- Proceed to [Step 2: Add users and assign licenses in Microsoft Defender for Business](mdb-add-users.md).
138-

defender-endpoint/TOC.yml

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -694,6 +694,11 @@
694694
items:
695695
- name: Use Microsoft Intune to manage Microsoft Defender Antivirus
696696
href: use-intune-config-manager-microsoft-defender-antivirus.md
697+
- name: Use Microsoft Defender for Endpoint Security Settings Management to manage
698+
Microsoft Defender Antivirus
699+
href: mde-security-settings-management.md
700+
displayName: Use Microsoft Defender for Endpoint Security Settings Management to
701+
manage Microsoft Defender Antivirus MDE Attach MDE Attach v2
697702
- name: Use Group Policy settings to manage Microsoft Defender Antivirus
698703
href: use-group-policy-microsoft-defender-antivirus.md
699704
- name: Use PowerShell cmdlets to manage Microsoft Defender Antivirus
@@ -970,7 +975,7 @@
970975
- name: How Microsoft identifies malware and PUA
971976
href: /defender/criteria
972977
- name: Submit files for analysis
973-
href: /defender/submission-guide
978+
href: /defender-xdr/submission-guide
974979
- name: Troubleshoot MSI portal errors caused by admin block
975980
href: /defender/portal-submission-troubleshooting
976981
- name: Microsoft virus initiative

defender-endpoint/api/api-power-bi.md

Lines changed: 29 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Microsoft Defender for Endpoint APIs connection to Power BI
3-
ms.reviewer:
3+
ms.reviewer: yongrhee
44
description: Create a Power Business Intelligence (BI) report on top of Microsoft Defender for Endpoint APIs.
55
ms.service: defender-endpoint
66
ms.author: siosulli
@@ -16,14 +16,15 @@ ms.topic: conceptual
1616
ms.subservice: reference
1717
ms.custom: api
1818
search.appverid: met150
19-
ms.date: 12/18/2020
19+
ms.date: 04/24/2024
2020
---
2121

2222
# Create custom reports using Power BI
2323

2424
[!INCLUDE [Microsoft Defender XDR rebranding](../../includes/microsoft-defender.md)]
2525

2626
**Applies to:**
27+
2728
- ../microsoft-defender-endpoint.md
2829
- [Microsoft Defender XDR](/defender-xdr)
2930

@@ -42,12 +43,14 @@ The first example demonstrates how to connect Power BI to Advanced Hunting API,
4243
1. Open Microsoft Power BI.
4344

4445
2. Select **Get Data** \> **Blank Query**.
46+
4547
:::image type="content" source="../media/power-bi-create-blank-query.png" alt-text="The Blank Query option under the Get Data menu item" lightbox="../media/power-bi-create-blank-query.png":::
4648

4749
3. Select **Advanced Editor**.
50+
4851
:::image type="content" source="../media/power-bi-open-advanced-editor.png" alt-text="The Advanced Editor menu item" lightbox="../media/power-bi-open-advanced-editor.png":::
4952

50-
4. Copy the below and paste it in the editor:
53+
4. Copy the code snippet below and paste it in the editor:
5154

5255
```
5356
let
@@ -103,36 +106,43 @@ The first example demonstrates how to connect Power BI to Advanced Hunting API,
103106

104107
:::image type="content" source="../media/power-bi-set-credentials-organizational-cont.png" alt-text="The sign-in confirmation message in the Organizational account menu item" lightbox="../media/power-bi-set-credentials-organizational-cont.png":::
105108

106-
Now the results of your query appear as a table and you can start to build visualizations on top of it!
107-
108-
You can duplicate this table, rename it, and edit the Advanced Hunting query inside to get any data you would like.
109+
Now the results of your query appear as a table and you can start to build visualizations on top of it! You can duplicate this table, rename it, and edit the Advanced Hunting query inside to get any data you would like.
109110

110111
## Connect Power BI to OData APIs
111112

112-
The only difference from the previous example is the query inside the editor. Follow steps 1-3 above.
113+
The only difference from the previous example and this example is the query inside the editor.
113114

114-
At step 4, instead of the code in that example, copy the following code, and paste it in the editor to pull all **Machine Actions** from your organization:
115+
1. Open Microsoft Power BI.
115116

116-
```
117-
let
117+
2. Select **Get Data** \> **Blank Query**.
118+
119+
:::image type="content" source="../media/power-bi-create-blank-query.png" alt-text="The Blank Query option under the Get Data menu item" lightbox="../media/power-bi-create-blank-query.png":::
118120

119-
Query = "MachineActions",
121+
3. Select **Advanced Editor**.
120122

121-
Source = OData.Feed("https://api.securitycenter.microsoft.com/api/" & Query, null, [Implementation="2.0", MoreColumns=true])
122-
in
123-
Source
124-
```
123+
:::image type="content" source="../media/power-bi-open-advanced-editor.png" alt-text="The Advanced Editor menu item" lightbox="../media/power-bi-open-advanced-editor.png":::
124+
125+
4. Copy the following code, and paste it in the editor to pull all **Machine Actions** from your organization:
126+
127+
```
128+
let
129+
130+
Query = "MachineActions",
131+
132+
Source = OData.Feed("https://api.securitycenter.microsoft.com/api/" & Query, null, [Implementation="2.0", MoreColumns=true])
133+
in
134+
Source
135+
```
125136

126-
You can do the same for **Alerts** and **Machines**.
127-
You also can use OData queries for queries filters. See [Using OData Queries](exposed-apis-odata-samples.md).
137+
You can do the same for **Alerts** and **Machines**. You also can use OData queries for queries filters. See [Using OData Queries](exposed-apis-odata-samples.md).
128138

129139
## Power BI dashboard samples in GitHub
130140

131-
For more information, see the [Power BI report templates](https://github.com/microsoft/MicrosoftDefenderATP-PowerBI).
141+
See the [Power BI report templates](https://github.com/microsoft/MicrosoftDefenderATP-PowerBI).
132142

133143
## Sample reports
134144

135-
View the Microsoft Defender for Endpoint Power BI report samples. For more information, see [Browse code samples](/samples/browse/?products=mdatp).
145+
View the [Microsoft Defender for Endpoint Power BI report samples](/samples/browse/?products=mdatp).
136146

137147
## Related articles
138148

defender-endpoint/configure-server-endpoints.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -281,7 +281,7 @@ The following steps are only applicable if you're using a third-party anti-malwa
281281
- An operating system update can introduce an installation issue on machines with slower disks due to a timeout with service installation. Installation fails with the message "Could not find c:\program files\windows defender\mpasdesc.dll, - 310 WinDefend". Use the latest installation package, and the latest [install.ps1](https://github.com/microsoft/mdefordownlevelserver) script to help clear the failed installation if necessary.
282282
- We've identified an issue with Windows Server 2012 R2 connectivity to cloud when static TelemetryProxyServer is used **and** the certificate revocation list (CRL) URLs aren't reachable from the SYSTEM account context. Ensure the EDR sensor is updated to version 10.8210.* or later (using [KB5005292](https://support.microsoft.com/topic/microsoft-defender-for-endpoint-update-for-edr-sensor-f8f69773-f17f-420f-91f4-a8e5167284ac)) to resolve the issue. Alternatively, use a different proxy option ("system-wide") that provides such connectivity, or configure the same proxy via the WinInet setting on the SYSTEM account context.
283283
- On Windows Server 2012 R2, there's no user interface for Microsoft Defender Antivirus. In addition, the user interface on Windows Server 2016 only allows for basic operations. To perform operations on a device locally, refer to [Manage Microsoft Defender for Endpoint with PowerShell, WMI, and MPCmdRun.exe](preferences-setup.md). As a result, features that specifically rely on user interaction, such as where the user is prompted to make a decision or perform a specific task, may not work as expected. It's recommended to disable or not enable the user interface nor require user interaction on any managed server as it may impact protection capability.
284-
- Not all Attack Surface Reduction rules are applicable to all operating systems. See [Attack surface reduction rules](/defender-endpoint/attack-surface-reduction-rules).
284+
- Not all Attack Surface Reduction rules are applicable to all operating systems. See [Attack surface reduction rules](attack-surface-reduction-rules-reference.md).
285285
- Operating system upgrades aren't supported. Offboard then uninstall before upgrading. The installer package can only be used to upgrade installations that have not yet been updated with new antimalware platform or EDR sensor update packages.
286286
- Automatic exclusions for **server roles** aren't supported on Windows Server 2012 R2; however, built-in exclusions for operating system files are. For more information about adding exclusions, see [Configure Microsoft Defender Antivirus exclusions on Windows Server](configure-server-exclusions-microsoft-defender-antivirus.md).
287287
- To automatically deploy and onboard the new solution using Microsoft Endpoint Configuration Manager (MECM) you need to be on [version 2207 or later](/mem/configmgr/core/plan-design/changes/whats-new-in-version-2207#improved-microsoft-defender-for-endpoint-mde-onboarding-for-windows-server-2012-r2-and-windows-server-2016). You can still configure and deploy using version 2107 with the hotfix rollup, but this requires additional deployment steps. See [Microsoft Endpoint Configuration Manager migration scenarios](/defender-endpoint/server-migration#microsoft-endpoint-configuration-manager-migration-scenarios) for more information.

0 commit comments

Comments
 (0)