Skip to content

Commit 0924339

Browse files
committed
updated msdates
1 parent b6e679e commit 0924339

15 files changed

+106
-65
lines changed

defender-xdr/TOC.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -365,14 +365,14 @@
365365
href: access-den-graph-api.md
366366
- name: Ask Defender Experts
367367
href: experts-on-demand.md
368+
- name: Understand Defender Experts for Hunting reports
369+
href: defender-experts-report.md
368370
- name: Frequently asked questions
369371
items:
370372
- name: General information
371373
href: faq-defender-experts-hunting.md
372374
- name: Server and cloud workload coverage
373375
href: faq-cloud-coverage-defender-experts.md
374-
- name: Understand Defender Experts for Hunting reports
375-
href: defender-experts-report.md
376376
- name: Collaborate with Microsoft Defender Experts for XDR
377377
items:
378378
- name: Overview
@@ -387,7 +387,7 @@
387387
href: managed-detection-and-response-xdr.md
388388
- name: Scoped coverage
389389
href: defender-experts-scoped-coverage.md
390-
- name: Communicate with Defender Experts for XDR
390+
- name: Communicate with Defender Experts
391391
href: communicate-defender-experts-xdr.md
392392
- name: Reports
393393
href: reports-xdr.md

defender-xdr/auditing.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ title: How to search the audit logs for actions performed by Defender Experts
33
ms.reviewer:
44
description: As a tenant administrator, you can use Microsoft Purview to search the audit logs for the actions Microsoft Defender Experts did in your tenant to perform their investigations
55
ms.service: defender-experts-for-xdr
6-
ms.author: vpattnaik
7-
author: vpattnai
6+
ms.author: pauloliveria
7+
author: poliveria
88
ms.localizationpriority: medium
9-
manager: dansimp
9+
manager: orspodek
1010
audience: ITPro
1111
ms.collection:
1212
- m365-security
@@ -17,14 +17,15 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 01/14/2025
20+
ms.date: 08/01/2025
2121
---
2222

2323
# Auditing
2424

2525
**Applies to:**
2626

27-
- [Microsoft Defender XDR](microsoft-365-defender.md)
27+
- [Microsoft Defender Experts for XDR](dex-xdr-overview.md)
28+
- Microsofot Defender Experts for Servers
2829

2930
As a tenant administrator, you can use Microsoft Purview to search the audit logs for the times Microsoft Defender Experts signed into your tenant and the actions they did there to perform their investigations. You can also search the audit logs for the changes done by your tenant administrators to the Defender Experts settings.
3031

defender-xdr/before-you-begin-defender-experts.md

Lines changed: 28 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ title: Before you begin using the Microsoft Defender Experts for Hunting service
33
ms.reviewer:
44
description: To enable us to get started with the defender experts managed service, we require the following prerequisites
55
ms.service: defender-experts-for-hunting
6-
ms.author: vpattnaik
7-
author: vpattnai
6+
ms.author: pauloliveria
7+
author: poliveria
88
ms.localizationpriority: medium
9-
manager: dansimp
9+
manager: orspodek
1010
audience: ITPro
1111
ms.collection:
1212
- m365-security
@@ -18,7 +18,7 @@ ms.custom:
1818
- cx-ti
1919
- cx-ean
2020
search.appverid: met150
21-
ms.date: 04/24/2025
21+
ms.date: 08/01/2025
2222
---
2323

2424
# Before you begin using Defender Experts for Hunting
@@ -28,7 +28,6 @@ ms.date: 04/24/2025
2828
**Applies to:**
2929

3030
- [Microsoft Defender XDR](microsoft-365-defender.md)
31-
- [Microsoft Defender Experts for XDR](dex-xdr-overview.md)
3231

3332
[Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md) is a managed service that provides hunting capabilities for novel emerging threats that aren't yet well known in the industry. The analysts for the hunting service review trends in the threat actor evolution based on world-renowned Microsoft Threat Intelligence and Research. They then apply the insights they gather to hunt for emerging attack vectors within the customer ecosystem.
3433

@@ -38,12 +37,14 @@ With deep product expertise powered by threat intelligence, we're uniquely posit
3837
1. Get detailed, step-by-step, and actionable guidance from our experts so you can respond to these emerging threats.
3938
1. [Seek assistance](#ask-defender-experts) from Defender Experts.
4039

41-
This document outlines the key infrastructure requirements you must meet and important information on data access and compliance you must know before purchasing the Microsoft Defender Experts for Hunting service. Microsoft understands that customers who use our managed services entrust us with their most valued asset, their data.
40+
This document outlines the key infrastructure requirements you must meet and important information on data access and compliance you must know before purchasing the **Microsoft Defender Experts for Hunting - XDR** service and its add-on, **Microsoft Defender Experts for Hunting - Servers**. Microsoft understands that customers who use our managed services entrust us with their most valued asset, their data.
4241

4342
## Eligibility and licensing
4443

4544
Defender Experts for Hunting is a separate service from your existing Microsoft Defender products. Before enrolling in this service, make sure that you have the necessary license and access.
4645

46+
**Microsoft Defender Experts for Hunting – XDR**
47+
4748
We require the following licensing prerequisites to enable us to get started with this threat hunting service:
4849

4950
- Microsoft Defender for Endpoint P2 must be licensed and enabled on eligible devices
@@ -60,20 +61,33 @@ The following product is **not** covered by this service:
6061
- Microsoft Defender for IoT
6162
- Other Microsoft services not mentioned in the previous lists
6263

64+
**Microsoft Defender Experts for Hunting - Servers**
65+
66+
Customers who wish to have Defender Experts hunting coverage for Microsoft Defender for Cloud servers must have the following:
67+
68+
- Defender Experts for Hunting - XDR service enrollment
69+
- Defender for Servers Plan 1 or Plan 2 in Microsoft Defender for Cloud
70+
6371
> [!NOTE]
64-
> Licensing for Microsoft Defender Experts for Hunting is applied at the tenant level and all identities and devices will be included in your license.
72+
> Defender Experts for Hunting coverage is applied at the tenant level and all identities and devices will be included.
6573
6674
### Defender Experts for Hunting coverage
6775

68-
Defender Experts for Hunting relies on event signals from Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Identity. It also relies on proprietary Microsoft Threat Intelligence sources.
76+
**Microsoft Defender Experts for Hunting – XDR**
77+
78+
Defender Experts for Hunting - XDR relies on event signals from Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Identity. It also relies on proprietary Microsoft Threat Intelligence sources.
6979

70-
This service also covers servers—whether on premises or on a hyperscale cloud service provider—that have Defender for Endpoint deployed on them with a Microsoft Defender for Endpoint for Servers license.
80+
This service also covers servers that have Defender for Endpoint deployed on them with a **Microsoft Defender for Endpoint for Servers** license.
7181

7282
Any detection that's not from Microsoft Defender products (for example, detections from other security vendors) isn't within the scope of Defender Experts for Hunting.
7383

84+
**Microsoft Defender Experts for Hunting - Servers**
85+
86+
Defender Experts for Hunting – Servers provides add-on server coverage, including hybrid and multicloud servers from Defender for Servers.
87+
7488
### Ask Defender Experts
7589

76-
[Ask Defender Experts](experts-on-demand.md) is intended to provide a better understanding of complex threats affecting your organization. It focuses on products included in Microsoft Defender XDR (Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, and Defender for Identity). [See sample questions you can ask Defender Experts](experts-on-demand.md#sample-questions-you-can-ask-from-defender-experts).
90+
[Ask Defender Experts](experts-on-demand.md) is intended to provide a better understanding of complex threats affecting your organization. It focuses on products included in Microsoft Defender Experts services. [See sample questions you can ask Defender Experts](experts-on-demand.md#sample-questions-you-can-ask-from-defender-experts).
7791

7892
Defender Experts for Hunting customers are assigned 10 Ask Defender Experts credits, which you can use to submit questions, at the start of each calendar quarter. Unused credits from the current quarter roll up to the next one. You can use up to 20 credits only per quarter. All unused credits expire by the end of the calendar year or at the end of your subscription term, whichever comes first.
7993

@@ -87,7 +101,7 @@ You might need certain roles and permissions to fully access the service capabil
87101

88102
## Service availability and data protection
89103

90-
Defender Experts for Hunting is a managed threat hunting service that proactively hunts for threats across endpoints, email, identity, and cloud apps. To carry out hunting on your behalf, Microsoft experts need access to your Microsoft Defender XDR advanced hunting data. Enrolling in this service means you're granting permission to Microsoft experts to access the said data.
104+
Defender Experts for Hunting - XDR and Defender Experts for Hunting - Servers are managed threat hunting services that proactively hunts for threats across endpoints, email, identity, cloud apps, and servers. To carry out hunting on your behalf, Microsoft experts need access to your Microsoft Defender XDR advanced hunting data. Enrolling in this service means you're granting permission to Microsoft experts to access the said data.
91105

92106
The following sections enumerate additional information about the service's data usage, compliance, and availability. For more information about Microsoft's commitment in valuing and protecting your data, visit the [Trust Center](https://www.microsoft.com/trust-center/product-overview) then scroll down to **Additional products and services** > **Managed Security Services** > **Microsoft Defender Experts**.
93107

@@ -99,6 +113,9 @@ Defender Experts for Hunting operational data, such as case tickets and analyst
99113

100114
Microsoft experts hunt over [advanced hunting logs](advanced-hunting-schema-tables.md) in Microsoft Defender XDR advanced hunting tables. The data in these tables depend on the set of Defender services the customer is enabled for (for example, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID). Experts also use a large set of internal threat intelligence data to inform their hunting and automation.
101115

116+
> [!NOTE]
117+
> Microsoft Defender for Cloud is integrated with Microsoft Defender XDR. This integration allows security teams to access Defender for Cloud alerts and incidents within the Microsoft Defender portal. The Defender Experts for Hunting - Servers add-on service accesses data through the Defender portal, so the same data collection, usage, and retention policies apply to this service.
118+
102119
### Security and compliance
103120

104121
When you purchase and onboard to Defender Experts for Hunting, you're granting permission to Microsoft experts to access your advanced hunting data.

defender-xdr/before-you-begin-xdr.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,8 @@ ms.date: 08/01/2025
2424

2525
**Applies to:**
2626

27-
- [Microsoft Defender XDR](microsoft-365-defender.md)
27+
- [Microsoft Defender Experts for XDR](dex-xdr-overview.md)
28+
- Microsofot Defender Experts for Servers
2829

2930
This document outlines the key prerequisites you must meet and essential information you must know before purchasing the Microsoft Defender Experts for XDR service and its add-on offering, Microsoft Defender Experts for Servers.
3031

@@ -61,7 +62,7 @@ The following product isn't covered by this service:
6162

6263
**Microsoft Defender Experts for Servers**
6364

64-
To enable the Defender Experts for Severs coverage, Defender for Servers Plan 1 or Plan 2 in Defender for Cloud must be enabled. Endpoint protection should also be turned on for both Windows and Linux devices that allow protection powered by Defender for Endpoint, including automatic agent deployment to your servers, and security data integration with Defender for Cloud.
65+
To enable the Defender Experts for Severs coverage, Defender for Servers Plan 1 or Plan 2 in Defender for Cloud must be enabled. [Endpoint protection](/azure/defender-for-cloud/integration-defender-for-endpoint) should also be turned on for Windows and Linux devices that allow protection powered by Defender for Endpoint, including automatic agent deployment to your servers, and security data integration with Defender for Cloud.
6566

6667
Depending on the coverage you're looking for, you can enable the Defender for Servers plan for a Microsoft Azure subscription, Amazon Web Services account, or Google Cloud Platform project.
6768

@@ -78,7 +79,7 @@ We recommend ensuring that at least one product, such as Defender for Endpoint o
7879

7980
For maximum, native coverage, we recommend deploying the full Microsoft Defender XDR suite and enabling all eligible products in active mode.
8081

81-
Defender Experts for XDR also covers servers—whether on premises or on a hyperscale cloud service provider—that have Defender for Endpoint deployed on them with a Microsoft Defender for Endpoint for Server license. For Defender Experts coverage, a server is considered as a user account for billing.
82+
Defender Experts for XDR also covers servers that have Defender for Endpoint deployed on them with a **Microsoft Defender for Endpoint for Server** license. For Defender Experts coverage, a server is considered as a user account for billing.
8283
[Learn more about specific hardware and software requirements](/defender-endpoint/minimum-requirements)
8384

8485
### Ask Defender Experts

defender-xdr/communicate-defender-experts-xdr.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,14 +17,15 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 03/05/2025
20+
ms.date: 08/01/2025
2121
---
2222

2323
# Communicating with experts in the Microsoft Defender Experts for XDR service
2424

2525
**Applies to:**
2626

27-
- [Microsoft Defender XDR](microsoft-365-defender.md)
27+
- [Microsoft Defender Experts for XDR](dex-xdr-overview.md)
28+
- Microsofot Defender Experts for Servers
2829

2930
Microsoft Defender Experts for XDR provides you with multiple channels of communication to discuss incidents with our experts, ask them questions on demand, or get service readiness or operations support from your service delivery managers (SDMs), if included in your service.
3031

defender-xdr/defender-experts-for-hunting.md

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ title: What is Microsoft Defender Experts for Hunting offering
33
ms.reviewer:
44
description: Microsoft Defender Experts for Hunting is a proactive threat hunting service that goes beyond the endpoint to hunt across endpoints
55
ms.service: defender-experts-for-hunting
6-
ms.author: vpattnaik
7-
author: vpattnai
6+
ms.author: pauloliveria
7+
author: poliveria
88
ms.localizationpriority: medium
9-
manager: dansimp
9+
manager: orspodek
1010
audience: ITPro
1111
ms.collection:
1212
- m365-security
@@ -17,7 +17,7 @@ search.appverid: met150
1717
ms.custom:
1818
- cx-ti
1919
- cx-ean
20-
ms.date: 10/30/2024
20+
ms.date: 08/01/2025
2121
---
2222

2323
# Microsoft Defender Experts for Hunting
@@ -29,12 +29,17 @@ ms.date: 10/30/2024
2929
- [Microsoft Defender XDR](microsoft-365-defender.md)
3030

3131
> [!IMPORTANT]
32-
> Microsoft Defender Experts for Hunting is sold separately from other Microsoft Defender XDR products. If you're a Microsoft Defender XDR customer and are interested in purchasing Defender Experts for Hunting, complete a [customer interest form](https://aka.ms/DEX4HuntingCustomerInterestForm).
32+
> Microsoft Defender Experts for Hunting is sold separately from other Microsoft Defender XDR products. If you're a Microsoft Defender XDR customer and are interested in purchasing Microsoft Defender Experts for Hunting - XDR and the Microsoft Defender Experts for Hunting - Servers add-on, complete this [customer interest form](https://aka.ms/DEX4HuntingCustomerInterestForm).
3333
3434
> [!NOTE]
3535
> Any incident response services offered by Defender Experts will be offered under the Defender Experts Service Terms.
3636
37-
Microsoft Defender Experts for Hunting was created for customers who have a robust security operations center but want Microsoft to help them proactively hunt threats using Microsoft Defender data. Defender Experts for Hunting is a proactive threat hunting service that goes beyond the endpoint to hunt across endpoints, Office 365, cloud applications, and identity. Our experts will investigate anything they find, then hand off the contextual alert information along with remediation instructions, so you can quickly respond.
37+
Microsoft Defender Experts for Hunting was created for customers who have a robust security operations center but want Microsoft to help them proactively hunt threats using Microsoft Defender data:
38+
39+
- **Microsoft Defender Experts for Hunting - XDR** is a proactive threat hunting service that goes beyond the endpoint to hunt across endpoints, Microsoft 365, cloud applications, and identity
40+
- **Microsoft Defender Experts for Hunting - Servers** is an add-on to Defender Experts for Hunting - XDR, providing proactive threat hunting for hybrid and multicloud servers
41+
42+
Our experts will investigate anything they find, then hand off the contextual alert information along with remediation instructions, so you can quickly respond.
3843

3944
The following capabilities included in this managed threat hunting service could also help with your daily SecOps work:
4045

defender-xdr/defender-experts-scoped-coverage.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,10 @@ ms.reviewer:
44
description: Defender Experts scoped coverage covers a specific section of the organization where SOC support is limited.
55
ms.service: defender-experts
66
ms.subservice: dex-xdr
7-
ms.author: vpattnaik
8-
author: vpattnai
7+
ms.author: pauloliveria
8+
author: poliveria
99
ms.localizationpriority: medium
10-
manager: dansimp
10+
manager: orspodek
1111
audience: ITPro
1212
ms.collection:
1313
- m365-security
@@ -17,14 +17,15 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 12/24/2024
20+
ms.date: 08/01/2025
2121
---
2222

2323
# Scoped coverage in Microsoft Defender Experts for XDR
2424

2525
**Applies to:**
2626

27-
- [Microsoft Defender XDR](microsoft-365-defender.md)
27+
- [Microsoft Defender Experts for XDR](dex-xdr-overview.md)
28+
- Microsofot Defender Experts for Servers
2829

2930
Microsoft Defender Experts for XDR offers scoped coverage for customers who wish to have Defender Experts cover only a section of their organization (for example, specific geography, subsidiary, or function) that requires security operations center (SOC) support or where their security support is limited.
3031

0 commit comments

Comments
 (0)