Skip to content

Commit 071f8b5

Browse files
authored
Merge pull request #861 from MicrosoftDocs/deniseb-global-admin
Global Admin
2 parents 23ffd68 + 5535dc0 commit 071f8b5

File tree

2 files changed

+46
-82
lines changed

2 files changed

+46
-82
lines changed

defender-xdr/portal-submission-troubleshooting.md

Lines changed: 18 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ ms.collection:
1313
- tier2
1414
ms.topic: conceptual
1515
search.appverid: met150
16-
ms.date: 03/18/2022
16+
ms.date: 06/28/2024
1717
---
1818

1919
# Troubleshooting Microsoft Security intelligence malware submission errors caused by administrator block
@@ -24,16 +24,21 @@ In some instances, an administrator block might cause submission issues when you
2424

2525
Open your Azure [Enterprise application settings](https://portal.azure.com/#blade/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/UserSettings/menuId/). Under **Enterprise Applications** > **Users can consent to apps accessing company data on their behalf**, check whether Yes or No is selected.
2626

27-
- If **No** is selected, a Microsoft Entra administrator for the customer tenant will need to provide consent for the organization. Depending on the configuration with Microsoft Entra ID, users might be able to submit a request right from the same dialog box. If there's no option to ask for admin consent, users need to request for these permissions to be added to their Microsoft Entra admin. Go to the following section for more information.
27+
- If **No** is selected, a Microsoft Entra administrator for the customer tenant needs to provide consent for the organization. Depending on the configuration with Microsoft Entra ID, users might be able to submit a request right from the same dialog box. If there's no option to ask for admin consent, users need to request for these permissions to be added to their Microsoft Entra admin. Go to the following section for more information.
2828

29-
- If **Yes** is selected, ensure the Windows Defender Security Intelligence app setting **Enabled for users to sign in?** is set to **Yes** [in Azure](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ManagedAppMenuBlade/Properties/appId/f0cf43e5-8a9b-451c-b2d5-7285c785684d/objectId/4a918a14-4069-4108-9b7d-76486212d75d). If **No** is selected, you'll need to request a Microsoft Entra admin enable it.
29+
- If **Yes** is selected, ensure the Windows Defender Security Intelligence app setting **Enabled for users to sign in?** is set to **Yes** [in Azure](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ManagedAppMenuBlade/Properties/appId/f0cf43e5-8a9b-451c-b2d5-7285c785684d/objectId/4a918a14-4069-4108-9b7d-76486212d75d). If **No** is selected, you need to request a Microsoft Entra admin enable it.
3030

3131
## Implement Required Enterprise Application permissions
3232

33-
This process requires a global or application admin in the tenant.
33+
> [!IMPORTANT]
34+
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
35+
36+
This process requires a Global Administrator or Application Administrator in the tenant.
3437

3538
1. Open [Enterprise Application settings](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ManagedAppMenuBlade/Permissions/appId/f0cf43e5-8a9b-451c-b2d5-7285c785684d/objectId/4a918a14-4069-4108-9b7d-76486212d75d).
39+
3640
2. Select **Grant admin consent for organization**.
41+
3742
3. If you're able to do so, review the API permissions required for this application, as the following image shows. Provide consent for the tenant.
3843

3944
![grant consent image.](/defender/media/security-intelligence-images/msi-grant-admin-consent.jpg)
@@ -42,10 +47,7 @@ This process requires a global or application admin in the tenant.
4247

4348
## Option 1 Approve enterprise application permissions by user request
4449

45-
> [!NOTE]
46-
> This is currently a preview feature.
47-
48-
Microsoft Entra admins will need to allow for users to request admin consent to apps. Verify the setting is configured to **Yes** in [Enterprise applications](https://portal.azure.com/#blade/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/UserSettings/menuId/).
50+
Microsoft Entra Administrators need to allow for users to request admin consent to apps. Verify the setting is configured to **Yes** in [Enterprise applications](https://portal.azure.com/#blade/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/UserSettings/menuId/).
4951

5052
![Enterprise applications user settings.](/defender/media/security-intelligence-images/msi-enterprise-app-user-setting.jpg)
5153

@@ -55,19 +57,19 @@ Once this setting is verified, users can go through the enterprise customer sign
5557

5658
![Contoso sign in flow.](/defender/media/security-intelligence-images/msi-contoso-approval-required.png)
5759

58-
Admin will be able to review and approve the application permissions [Azure admin consent requests](https://portal.azure.com/#blade/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/AccessRequests/menuId/).
60+
Administrators can review and approve the application permissions [Azure admin consent requests](https://portal.azure.com/#blade/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/AccessRequests/menuId/).
5961

6062
After providing consent, all users in the tenant will be able to use the application.
6163

6264
## Option 2 Provide admin consent by authenticating the application as an admin
6365

64-
This process requires that global admins go through the Enterprise customer sign-in flow at [Microsoft security intelligence](https://www.microsoft.com/wdsi/filesubmission).
66+
This process requires that Global Administrators go through the Enterprise customer sign-in flow at [Microsoft security intelligence](https://www.microsoft.com/wdsi/filesubmission).
6567

6668
![Consent sign in flow.](/defender/media/security-intelligence-images/msi-microsoft-permission-required.jpg)
6769

6870
Then, admins review the permissions and make sure to select **Consent on behalf of your organization**, and then select **Accept**.
6971

70-
All users in the tenant will now be able to use this application.
72+
All users in the tenant can now use this application.
7173

7274
## Option 3: Delete and readd app permissions
7375

@@ -78,10 +80,11 @@ and select **delete**.
7880

7981
![Delete app permissions.](/defender/media/security-intelligence-images/msi-properties.png)
8082

81-
2. Capture TenantID from [Properties](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/Properties).
83+
2. Capture `TenantID` from [Properties](https://portal.azure.com/#blade/Microsoft_AAD_IAM/ActiveDirectoryMenuBlade/Properties).
84+
85+
3. Replace `{tenant-id}` with the specific tenant that needs to grant consent to this application in the URL below. Copy the following URL into browser: `https://login.microsoftonline.com/{tenant-id}/v2.0/adminconsent?client_id=f0cf43e5-8a9b-451c-b2d5-7285c785684d&state=12345&redirect_uri=https%3a%2f%2fwww.microsoft.com%2fwdsi%2ffilesubmission&scope=openid+profile+email+offline_access`
8286

83-
3. Replace {tenant-id} with the specific tenant that needs to grant consent to this application in the URL below. Copy this URL into browser. The rest of the parameters are already completed.
84-
``https://login.microsoftonline.com/{tenant-id}/v2.0/adminconsent?client_id=f0cf43e5-8a9b-451c-b2d5-7285c785684d&state=12345&redirect_uri=https%3a%2f%2fwww.microsoft.com%2fwdsi%2ffilesubmission&scope=openid+profile+email+offline_access``
87+
The rest of the parameters are already completed.
8588

8689
![Permissions needed.](/defender/media/security-intelligence-images/msi-microsoft-permission-requested-your-organization.png)
8790

@@ -93,4 +96,4 @@ and select **delete**.
9396

9497
6. Sign in to [Microsoft security intelligence](https://www.microsoft.com/wdsi/filesubmission) as an enterprise user with a non-admin account to see if you have access.
9598

96-
If the warning is not resolved after following these troubleshooting steps, call Microsoft support.
99+
If the warning isn't resolved after following these troubleshooting steps, call Microsoft support.

defender-xdr/setup-m365deval.md

Lines changed: 28 additions & 67 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
- highpri
1616
- tier1
1717
ms.topic: conceptual
18-
ms.date: 02/17/2021
18+
ms.date: 06/28/2024
1919
---
2020

2121
# Set up your Microsoft Defender XDR trial in a lab environment
@@ -25,113 +25,74 @@ ms.date: 02/17/2021
2525
**Applies to:**
2626
- Microsoft Defender XDR
2727

28-
This topic guides you to set up a dedicated lab environment. For information on setting up a trial in production, see the new [Pilot and deploy Microsoft Defender XDR](pilot-deploy-overview.md) guide.
28+
This article guides you to set up a dedicated lab environment. For information on setting up a trial in production, see the new [Pilot and deploy Microsoft Defender XDR](pilot-deploy-overview.md) guide.
2929

30-
## Create an Office 365 E5 trial tenant
30+
> [!IMPORTANT]
31+
> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
3132
32-
> [!NOTE]
33-
> If you already have an existing Office 365 or Microsoft Entra subscription, you can skip the Office 365 E5 trial tenant creation steps.
34-
35-
1. Go to the [Office 365 E5 product portal](https://www.microsoft.com/microsoft-365/business/office-365-enterprise-e5-business-software?activetab=pivot%3aoverviewtab) and select **Free trial**.
33+
## Create a Microsoft 365 E5 trial tenant
3634

37-
:::image type="content" source="/defender/media/mtp-eval-9.png" alt-text="The Office 365 E5 free trial page" lightbox="/defender/media/mtp-eval-9.png":::
35+
> [!NOTE]
36+
> If you already have an existing Microsoft 365 or Microsoft Entra subscription, you can skip the Microsoft 365 E5 trial tenant creation steps.
3837
39-
2. Complete the trial registration by entering your email address (personal or corporate). Click **Set up account**.
38+
1. Go to the [Microsoft 365 E5 product portal](https://www.microsoft.com/microsoft-365/business/office-365-enterprise-e5-business-software?activetab=pivot%3aoverviewtab) and select **Free trial**.
4039

41-
:::image type="content" source="/defender/media/mtp-eval-10.png" alt-text="The Office 365 E5 trial registration setup page" lightbox="/defender/media/mtp-eval-10.png":::
40+
2. Complete the trial registration by entering your email address (personal or corporate). Select **Set up account**.
4241

4342
3. Fill in your first name, last name, business phone number, company name, company size, and country or region.
4443

45-
:::image type="content" source="/defender/media/mtp-eval-11.png" alt-text="The Office 365 E5 trial registration setup page asking for name, phone, and company details" lightbox="/defender/media/mtp-eval-11.png":::
46-
4744
> [!NOTE]
48-
> The country or region you set here determines the data center region your Office 365 will be hosted.
49-
50-
4. Choose your verification preference: through a text message or call. Click **Send Verification Code**.
51-
52-
:::image type="content" source="/defender/media/mtp-eval-12.png" alt-text="The Office 365 E5 trial registration setup page asking for verification preference" lightbox="/defender/media/mtp-eval-12.png":::
53-
54-
5. Set the custom domain name for your tenant, then click **Next**.
45+
> The country or region you set here determines the data center region your Microsoft 365 will be hosted.
5546
56-
:::image type="content" source="/defender/media/mtp-eval-13.png" alt-text="The Office 365 E5 trial registration setup page where you can set up your custom domain name" lightbox="/defender/media/mtp-eval-13.png":::
47+
4. Choose your verification preference: through a text message or call. Select **Send Verification Code**.
5748

58-
6. Set up the first identity, which will be a Global Administrator for the tenant. Fill in **Name** and **Password**. Click **Sign up**.
49+
5. Set the custom domain name for your tenant, then select **Next**.
5950

60-
:::image type="content" source="/defender/media/mtp-eval-14.png" alt-text="The Office 365 E5 trial registration setup page where you can set your business identity" lightbox="/defender/media/mtp-eval-14.png":::
51+
6. Set up the first identity, which is a Global Administrator for the tenant. Fill in **Name** and **Password**. Select **Sign up**.
6152

62-
7. Click **Go to Setup** to complete the Office 365 E5 trial tenant provisioning.
53+
7. Select **Go to Setup** to complete the Microsoft 365 E5 trial tenant provisioning.
6354

64-
:::image type="content" source="/defender/media/mtp-eval-15.png" alt-text="The Office 365 E5 trial registration setup page prompting to click Go to Setup button" lightbox="/defender/media/mtp-eval-15.png":::
65-
66-
8. Connect your corporate domain to the Office 365 tenant. [Optional] Choose **Connect a domain you already own** and type in your domain name. Click **Next**.
67-
68-
:::image type="content" source="/defender/media/mtp-eval-16.png" alt-text="The Office 365 E5 Setup page where you should personalize your sign-in and email" lightbox="/defender/media/mtp-eval-16.png":::
55+
8. Connect your corporate domain to the Microsoft 365 tenant. [Optional] Choose **Connect a domain you already own** and type in your domain name. Select **Next**.
6956

7057
9. Add a TXT or MX record to validate the domain ownership. Once you've added the TXT or MX record to your domain, select **Verify**.
7158

72-
:::image type="content" source="/defender/media/mtp-eval-17.png" alt-text="The Office 365 E5 setup page where you should add a TXT of MX record to verify your domain" lightbox="/defender/media/mtp-eval-17.png":::
73-
7459
10. [Optional] Create more user accounts for your tenant. You can skip this step by clicking **Next**.
7560

76-
:::image type="content" source="/defender/media/mtp-eval-18.png" alt-text="The Office 365 E5 setup page where you can add more users" lightbox="/defender/media/mtp-eval-18.png":::
77-
78-
11. [Optional] Download Office apps. Click **Next** to skip this step.
79-
80-
:::image type="content" source="/defender/media/mtp-eval-19.png" alt-text="The Office 365 E5 page where you can install your Office apps" lightbox="/defender/media/mtp-eval-19.png":::
61+
11. [Optional] Download Office apps. Select **Next** to skip this step.
8162

8263
12. [Optional] Migrate email messages. Again, you can skip this step.
8364

84-
:::image type="content" source="/defender/media/mtp-eval-20.png" alt-text="The Office 365 E5 where you can set whether to migrate email messages or not" lightbox="/defender/media/mtp-eval-20.png":::
85-
86-
13. Choose online services. Select **Exchange** and click **Next**.
87-
88-
:::image type="content" source="/defender/media/mtp-eval-21.png" alt-text="The Office 365 E5 where you can choose your online services" lightbox="/defender/media/mtp-eval-21.png":::
65+
13. Choose online services. Select **Exchange** and select **Next**.
8966

9067
14. Add MX, CNAME, and TXT records to your domain. When completed, select **Verify**.
9168

92-
:::image type="content" source="/defender/media/mtp-eval-22.png" alt-text="The Office 365 E5 here you can add your DNS records" lightbox="/defender/media/mtp-eval-22.png":::
93-
94-
15. Congratulations, you have completed the provisioning of your Office 365 tenant.
95-
96-
:::image type="content" source="/defender/media/mtp-eval-23.png" alt-text="The Office 365 E5 setup completion confirmation page" lightbox="/defender/media/mtp-eval-23.png":::
69+
Congratulations! You have completed the provisioning of your Microsoft 365 tenant.
9770

98-
## Enable Microsoft 365 trial subscription
71+
## Enable your Microsoft 365 trial subscription
9972

10073
> [!NOTE]
10174
> Signing up for a trial gives you 25 user licenses to use for a month. See [Try or buy a Microsoft 365 subscription](/microsoft-365/commerce/try-or-buy-microsoft-365) for details.
10275
103-
1. From [Microsoft 365 Admin Center](https://admin.microsoft.com/), click **Billing** and then navigate to **Purchase services**.
76+
1. From [Microsoft 365 Admin Center](https://admin.microsoft.com/), select **Billing** and then navigate to **Purchase services**.
10477

105-
2. Select **Microsoft 365 E5** and click **Start free trial**.
106-
107-
:::image type="content" source="/defender/media/mtp-eval-24.png" alt-text="The Microsoft 365 E5 Start free trial page" lightbox="/defender/media/mtp-eval-24.png":::
78+
2. Select **Microsoft 365 E5** and select **Start free trial**.
10879

10980
3. Choose your verification preference: through a text message or call. Once you have decided, enter the phone number, select **Text me** or **Call me** depending on your selection.
11081

111-
:::image type="content" source="/defender/media/mtp-eval-25.png" alt-text="The Microsoft 365 E5 Start free trial page asking for contact details to send code to prove you are not a robot" lightbox="/defender/media/mtp-eval-25.png":::
112-
113-
4. Enter the verification code and click **Start your free trial**.
114-
115-
:::image type="content" source="/defender/media/mtp-eval-26.png" alt-text="The Microsoft 365 E5 Start free trial page where you can fill out verification code the system sent to prove you are not a robot" lightbox="/defender/media/mtp-eval-26.png":::
82+
4. Enter the verification code and select **Start your free trial**.
11683

117-
5. Click **Try now** to confirm your Microsoft 365 E5 trial.
84+
5. Select **Try now** to confirm your Microsoft 365 E5 trial.
11885

119-
:::image type="content" source="/defender/media/mtp-eval-27.png" alt-text="The Microsoft 365 E5 Start free trial page where you should clock the Try now button to start" lightbox="/defender/media/mtp-eval-27.png":::
86+
6. Go to the **Microsoft 365 Admin Center** > **Users** > **Active users**. Select your user account, select **Manage product licenses**, and then assign the Microsoft 365 E5 license. Then select **Save**.
12087

121-
6. Go to the **Microsoft 365 Admin Center** > **Users** > **Active users**. Select your user account, select **Manage product licenses**, then swap the license from Office 365 E5 to **Microsoft 365 E5**. Click **Save**.
88+
7. Select the Global Administrator account again then select **Manage username**.
12289

123-
:::image type="content" source="/defender/media/mtp-eval-28.png" alt-text="The Microsoft 365 Admin Center page where you can select the Microsoft 365 E5 license" lightbox="/defender/media/mtp-eval-28.png":::
124-
125-
7. Select the global administrator account again then click **Manage username**.
126-
127-
:::image type="content" source="/defender/media/mtp-eval-29.png" alt-text="The Microsoft 365 Admin Center page where you can select Account and Manage username" lightbox="/defender/media/mtp-eval-29.png":::
128-
129-
8. [Optional] Change the domain from *onmicrosoft.com* to your own domain—depending on what you chose on the previous steps. Click **Save changes**.
130-
131-
:::image type="content" source="/defender/media/mtp-eval-30.png" alt-text="The Microsoft 365 Admin Center page where you can change your domain preference" lightbox="/defender/media/mtp-eval-30.png":::
90+
8. [Optional] Change the domain from *onmicrosoft.com* to your own domain—depending on what you chose on the previous steps. Select **Save changes**.
13291

13392
## Next step
13493

13594
|[Phase 3: Configure & Onboard](pilot-deploy-overview.md) | Configure each Microsoft Defender XDR pillar for your Microsoft Defender XDR trial lab or pilot environment and onboard your endpoints.
13695
|:-------|:-----|
96+
97+
13798
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]

0 commit comments

Comments
 (0)