You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/advanced-hunting-cloudappevents-table.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -30,13 +30,13 @@ ms.date: 05/15/2025
30
30
31
31
The `CloudAppEvents` table in the [advanced hunting](advanced-hunting-overview.md) schema contains information about events involving accounts and objects in Office 365 and other [cloud apps and services](#apps-and-services-covered). Use this reference to construct queries that return information from this table.
32
32
33
-
## Get access
33
+
## Prerequisites
34
34
35
35
To make sure the `CloudAppEvents` data is populated:
36
36
37
37
1. Go to the Defender portal and select **Settings > Cloud apps > App connectors**.
38
38
39
-
1. In the Microsoft 365 connector portal, select the **Pull activities** checkbox.
39
+
1. In the **Select Microsoft 365 components** page, select the **Microsoft 365 activities** checkbox.
40
40
41
41
For detailed instructions, see: [Connect Microsoft 365 to Microsoft Defender for Cloud Apps](/defender-cloud-apps/protect-office-365#prerequisites)
Copy file name to clipboardExpand all lines: exposure-management/get-started-exposure-management.md
+4Lines changed: 4 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,6 +19,10 @@ On the Exposure Management > **Overview** dashboard, you can review the overall
19
19
20
20
Use the dashboard as a starting point for a snapshot of organizational posture and exposure, and drill down to details as needed.
21
21
22
+
You can filter the list of affected devices based on their scope, ensuring that data presentation is aligned with your specific needs. The filter selection persists even when switching between Exposure Management experiences, allowing you to maintain you preferred view and focus on specific devices without reapplying filters.
23
+
24
+
Initiative scores will reflect the selected scope, whether defined by the admin or adjusted by the end user, ensuring users see accurate and relevant scores based on their access scope.
25
+
22
26
:::image type="content" source="./media/get-started-exposure-management/exposure-management-overview.png" alt-text="Screenshot of the security exposure management overview page." lightbox="./media/get-started-exposure-management/exposure-management-overview.png":::
23
27
24
28
## Connecting your external security and asset management products
Copy file name to clipboardExpand all lines: exposure-management/initiatives.md
+26-11Lines changed: 26 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,12 +1,13 @@
1
1
---
2
-
title: Review security initiatives in Microsoft Security Exposure Management
3
-
description: Learn how to work with security Initiatives in Microsoft Security Exposure Management.
2
+
title: Review security initiatives in Security Exposure Management
3
+
description: Learn how to effectively manage and track security initiatives using Microsoft Security Exposure Management to improve your organization's security posture.
4
+
#customer intent: As a security administrator, I want to understand and manage security initiatives so that I can improve my organization's security posture.
4
5
ms.author: dlanger
5
6
author: dlanger
6
-
manager: rayne-wiselman
7
-
ms.topic: overview
7
+
manager: ornat-spodek
8
+
ms.topic: how-to
8
9
ms.service: exposure-management
9
-
ms.date: 11/04/2024
10
+
ms.date: 05/04/2025
10
11
---
11
12
12
13
# Review security initiatives
@@ -21,24 +22,37 @@ ms.date: 11/04/2024
21
22
22
23
## View initiatives page
23
24
25
+
The initiatives page provides detailed insights into your security initiatives and their progress.
26
+
27
+
> [!NOTE]
28
+
> All information shown on the Initiative pages that is related to Endpoints data is based on the user's scope. This includes, initiative scores, metrics progress, and history reasoning.
29
+
24
30
1. Navigate to the [Microsoft Defender portal](https://security.microsoft.com/).
25
31
26
-
1. From the Exposure management section on the navigation bar, select **Exposure insights -> Initiatives** to open the [initiatives](https://security.microsoft.com/exposure-initiatives) page.
32
+
2. From the Exposure management section on the navigation bar, select **Exposure insights -> Initiatives** to open the [initiatives](https://security.microsoft.com/exposure-initiatives) page.
27
33
28
34
:::image type="content" source="./media/initiatives/initiatives-window.png" alt-text="Screenshot of the Security Exposure Management Initiatives window.":::
29
35
30
-
1. At the top of the initiatives page, review the highlighted key initiatives by scrolling and drilling down per your needs.
36
+
3. Use the **Filter by device groups** positioned at the top right corner to refine the filter.
37
+
38
+
:::image type="content" source="media/initiatives/filter-by-dg.png" alt-text="Screenshot of device group filter":::
39
+
40
+
4. Choose the device groups relevant for you, and the iniatives data will be recalculated (only when related to Endpoints data).
31
41
32
-
1. To set an initiative to appear in the top initiative bar in the dashboard or on the initiatives page, select the **star** icon in the initiatives window or **Mark as favorite** in the individual initiative.
42
+
:::image type="content" source="media/initiatives/filter-by-dg-pane.png" alt-text="Screenshot of the filter by device groups side pane.":::
33
43
34
-
1. You can review the following information for all initiatives:
44
+
5. At the top of the initiatives page, review the highlighted key initiatives by scrolling and drilling down per your needs.
45
+
46
+
6. To set an initiative to appear in the top initiative bar in the dashboard or on the initiatives page, select the **star** icon in the initiatives window or **Mark as favorite** in the individual initiative.
47
+
48
+
7. You can review the following information for all initiatives:
35
49
-**14 day change trend graph** highlighting how the initiative score changes over the past 14 days
36
50
-**Initiative name**
37
51
-**Favorite** indicator (toggle on/off) to display in the key initiatives banner
38
52
-**Current score** of the initiative
39
53
-**Programs** or workloads contributing to or required by this initiative
40
54
41
-
1. Select an initiative to open the small overview and then select **Open initiative page** to review or remediate issues. The initiative page includes additional information including:
55
+
8. Select an initiative to open the small overview and then select **Open initiative page** to review or remediate issues. The initiative page includes additional information including:
42
56
- Your target score for the initiative
43
57
- A means to set a custom target score appropriate to your organization's needs
44
58
- Description
@@ -67,7 +81,7 @@ The changes in your score provide you with useful feedback about how well you're
67
81
68
82
## Check history
69
83
70
-
1. Select an initiative to open the small overview and then select **Open initiative page-> History** to view changes over time.
84
+
1. Select an initiative to open the small overview and then select **Open initiative page-> History** to view changes over time.
71
85
72
86
1. Browse to the time table to choose a specific time point to examine.
73
87
1. If needed, filter for specific time points.
@@ -81,6 +95,7 @@ The changes in your score provide you with useful feedback about how well you're
81
95
82
96
1. To review metrics associated with your initiative, select **Exposure insights -> Initiatives-> Security metrics**.
83
97
1. Sort by heading, as needed.
98
+
84
99
1. Select **Exposure insights -> Initiatives-> Security recommendations** to view recommendations related to your initiative.
85
100
86
101
You only see those recommendations that are *currently* applied to assets and active in Microsoft Secure Score or Microsoft Defender for Cloud.
Copy file name to clipboardExpand all lines: exposure-management/whats-new.md
+13Lines changed: 13 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -24,6 +24,19 @@ Learn more about MSEM by reading the blogs, [here](https://techcommunity.microso
24
24
>
25
25
> `https://aka.ms/msem/rss`
26
26
27
+
## May 2025
28
+
29
+
### Enhanced support for device groups scoping
30
+
31
+
The device groups scoping within Exposure Management has been expanded. This update enhances the existing capability to filter the list of affected devices based on your assigned scope by extending it to security metrics and exposed entities in recommendations. With this enhancement, initiative scores, metric progress, security events, and historical insights will now be calculated and displayed according to your specific user scope. As a result, the data presented, including on the Overview page, will be tailored to align with your designated scope.
32
+
33
+
We will also support the device groups filter, which is already available in Microsoft Defender Vulnerability Management experiences. This filter enables end users to refine their view within their access scope, allowing them to focus on specific devices as needed. Once the filter is adjusted based on the user’s selection, all related data will be refreshed accordingly.
34
+
35
+
> [!NOTE]
36
+
> The device groups scoping capability applies only to data associated with Endpoint devices.
37
+
38
+
For more information, see [Review security initiatives](initiatives.md)
0 commit comments