Skip to content

Commit 0d6c5b4

Browse files
authored
Merge pull request #3837 from MicrosoftDocs/main
[AutoPublish] main to live - 05/20 04:29 PDT | 05/20 16:59 IST
2 parents bd4d98d + 9e3debf commit 0d6c5b4

File tree

9 files changed

+47
-15
lines changed

9 files changed

+47
-15
lines changed

defender-xdr/advanced-hunting-cloudappevents-table.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -30,13 +30,13 @@ ms.date: 05/15/2025
3030

3131
The `CloudAppEvents` table in the [advanced hunting](advanced-hunting-overview.md) schema contains information about events involving accounts and objects in Office 365 and other [cloud apps and services](#apps-and-services-covered). Use this reference to construct queries that return information from this table.
3232

33-
## Get access
33+
## Prerequisites
3434

3535
To make sure the `CloudAppEvents` data is populated:
3636

3737
1. Go to the Defender portal and select **Settings > Cloud apps > App connectors**.
3838

39-
1. In the Microsoft 365 connector portal, select the **Pull activities** checkbox.
39+
1. In the **Select Microsoft 365 components** page, select the **Microsoft 365 activities** checkbox.
4040

4141
For detailed instructions, see: [Connect Microsoft 365 to Microsoft Defender for Cloud Apps](/defender-cloud-apps/protect-office-365#prerequisites)
4242

defender/index.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -185,8 +185,8 @@ conceptualContent:
185185
text: See more
186186
url: /defender-for-iot/
187187

188-
- title: Microsoft's unified security operations platform
189-
summary: End-to-end SecOps with Microsoft Sentinel
188+
- title: Microsoft Sentinel
189+
summary: End-to-end security operations
190190
links:
191191
- url: /unified-secops-platform/overview-unified-security
192192
itemType: overview

exposure-management/get-started-exposure-management.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,10 @@ On the Exposure Management > **Overview** dashboard, you can review the overall
1919

2020
Use the dashboard as a starting point for a snapshot of organizational posture and exposure, and drill down to details as needed.
2121

22+
You can filter the list of affected devices based on their scope, ensuring that data presentation is aligned with your specific needs. The filter selection persists even when switching between Exposure Management experiences, allowing you to maintain you preferred view and focus on specific devices without reapplying filters.
23+
24+
Initiative scores will reflect the selected scope, whether defined by the admin or adjusted by the end user, ensuring users see accurate and relevant scores based on their access scope.
25+
2226
:::image type="content" source="./media/get-started-exposure-management/exposure-management-overview.png" alt-text="Screenshot of the security exposure management overview page." lightbox="./media/get-started-exposure-management/exposure-management-overview.png":::
2327

2428
## Connecting your external security and asset management products

exposure-management/initiatives.md

Lines changed: 26 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,13 @@
11
---
2-
title: Review security initiatives in Microsoft Security Exposure Management
3-
description: Learn how to work with security Initiatives in Microsoft Security Exposure Management.
2+
title: Review security initiatives in Security Exposure Management
3+
description: Learn how to effectively manage and track security initiatives using Microsoft Security Exposure Management to improve your organization's security posture.
4+
#customer intent: As a security administrator, I want to understand and manage security initiatives so that I can improve my organization's security posture.
45
ms.author: dlanger
56
author: dlanger
6-
manager: rayne-wiselman
7-
ms.topic: overview
7+
manager: ornat-spodek
8+
ms.topic: how-to
89
ms.service: exposure-management
9-
ms.date: 11/04/2024
10+
ms.date: 05/04/2025
1011
---
1112

1213
# Review security initiatives
@@ -21,24 +22,37 @@ ms.date: 11/04/2024
2122

2223
## View initiatives page
2324

25+
The initiatives page provides detailed insights into your security initiatives and their progress.
26+
27+
> [!NOTE]
28+
> All information shown on the Initiative pages that is related to Endpoints data is based on the user's scope. This includes, initiative scores, metrics progress, and history reasoning.
29+
2430
1. Navigate to the [Microsoft Defender portal](https://security.microsoft.com/).
2531

26-
1. From the Exposure management section on the navigation bar, select **Exposure insights -> Initiatives** to open the [initiatives](https://security.microsoft.com/exposure-initiatives) page.
32+
2. From the Exposure management section on the navigation bar, select **Exposure insights -> Initiatives** to open the [initiatives](https://security.microsoft.com/exposure-initiatives) page.
2733

2834
:::image type="content" source="./media/initiatives/initiatives-window.png" alt-text="Screenshot of the Security Exposure Management Initiatives window.":::
2935

30-
1. At the top of the initiatives page, review the highlighted key initiatives by scrolling and drilling down per your needs.
36+
3. Use the **Filter by device groups** positioned at the top right corner to refine the filter.
37+
38+
:::image type="content" source="media/initiatives/filter-by-dg.png" alt-text="Screenshot of device group filter":::
39+
40+
4. Choose the device groups relevant for you, and the iniatives data will be recalculated (only when related to Endpoints data).
3141

32-
1. To set an initiative to appear in the top initiative bar in the dashboard or on the initiatives page, select the **star** icon in the initiatives window or **Mark as favorite** in the individual initiative.
42+
:::image type="content" source="media/initiatives/filter-by-dg-pane.png" alt-text="Screenshot of the filter by device groups side pane.":::
3343

34-
1. You can review the following information for all initiatives:
44+
5. At the top of the initiatives page, review the highlighted key initiatives by scrolling and drilling down per your needs.
45+
46+
6. To set an initiative to appear in the top initiative bar in the dashboard or on the initiatives page, select the **star** icon in the initiatives window or **Mark as favorite** in the individual initiative.
47+
48+
7. You can review the following information for all initiatives:
3549
- **14 day change trend graph** highlighting how the initiative score changes over the past 14 days
3650
- **Initiative name**
3751
- **Favorite** indicator (toggle on/off) to display in the key initiatives banner
3852
- **Current score** of the initiative
3953
- **Programs** or workloads contributing to or required by this initiative
4054

41-
1. Select an initiative to open the small overview and then select **Open initiative page** to review or remediate issues. The initiative page includes additional information including:
55+
8. Select an initiative to open the small overview and then select **Open initiative page** to review or remediate issues. The initiative page includes additional information including:
4256
- Your target score for the initiative
4357
- A means to set a custom target score appropriate to your organization's needs
4458
- Description
@@ -67,7 +81,7 @@ The changes in your score provide you with useful feedback about how well you're
6781

6882
## Check history
6983

70-
1. Select an initiative to open the small overview and then select **Open initiative page-> History** to view changes over time.
84+
1. Select an initiative to open the small overview and then select **Open initiative page-> History** to view changes over time.
7185

7286
1. Browse to the time table to choose a specific time point to examine.
7387
1. If needed, filter for specific time points.
@@ -81,6 +95,7 @@ The changes in your score provide you with useful feedback about how well you're
8195

8296
1. To review metrics associated with your initiative, select **Exposure insights -> Initiatives-> Security metrics**.
8397
1. Sort by heading, as needed.
98+
8499
1. Select **Exposure insights -> Initiatives-> Security recommendations** to view recommendations related to your initiative.
85100

86101
You only see those recommendations that are *currently* applied to assets and active in Microsoft Secure Score or Microsoft Defender for Cloud.
-184 KB
Loading
148 KB
Loading
26.9 KB
Loading
65 KB
Loading

exposure-management/whats-new.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,19 @@ Learn more about MSEM by reading the blogs, [here](https://techcommunity.microso
2424
>
2525
> `https://aka.ms/msem/rss`
2626
27+
## May 2025
28+
29+
### Enhanced support for device groups scoping
30+
31+
The device groups scoping within Exposure Management has been expanded. This update enhances the existing capability to filter the list of affected devices based on your assigned scope by extending it to security metrics and exposed entities in recommendations. With this enhancement, initiative scores, metric progress, security events, and historical insights will now be calculated and displayed according to your specific user scope. As a result, the data presented, including on the Overview page, will be tailored to align with your designated scope.
32+
33+
We will also support the device groups filter, which is already available in Microsoft Defender Vulnerability Management experiences. This filter enables end users to refine their view within their access scope, allowing them to focus on specific devices as needed. Once the filter is adjusted based on the user’s selection, all related data will be refreshed accordingly.
34+
35+
> [!NOTE]
36+
> The device groups scoping capability applies only to data associated with Endpoint devices.
37+
38+
For more information, see [Review security initiatives](initiatives.md)
39+
2740
## March 2025
2841

2942
### New predefined classifications

0 commit comments

Comments
 (0)