Skip to content

Commit 0d79828

Browse files
authored
Merge branch 'main' into diannegali-xdrmdedeploy
2 parents 87aaf71 + e6b8836 commit 0d79828

File tree

8 files changed

+246
-110
lines changed

8 files changed

+246
-110
lines changed

CloudAppSecurityDocs/activity-filters-queries.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ Below is a list of the activity filters that can be applied. Most filters suppor
3535
- Administrative activity – Search only for administrative activities.
3636

3737
>[!NOTE]
38-
> Defender for Cloud Apps can't mark Google Cloud Platform (GCP) administrative activities as administrative activities.
38+
> Defender for Cloud Apps classifies all GCP activities as administrative activities.
3939
4040
- Alert ID - Search by alert ID.
4141

defender-business/mdb-faq.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ metadata:
1010
ms.topic: faq
1111
ms.service: defender-business
1212
ms.localizationpriority: medium
13-
ms.date: 01/02/2024
13+
ms.date: 03/19/2024
1414
ms.reviewer: efratka, nehabha
1515
f1.keywords: NOCSH
1616
ms.collection:
@@ -157,7 +157,7 @@ sections:
157157
| Cross-platform support <br/>(Mac, iOS, Android)| ✔ | ✔ | ✔ |
158158
| Windows Server and Linux Server <br/>(requires server licenses) | ✔ | ✔ | ✔ |
159159
| Microsoft Threat Experts | | | ✔ |
160-
| Microsoft 365 Lighthouse <br/>(optimized; for CSPs only) | ✔ | | |
160+
| Microsoft 365 Lighthouse <br/>(optimized; for CSPs only) | ✔ | ✔ | ✔ |
161161
| Microsoft Defender multi-tenant management | ✔ | ✔ | ✔ |
162162
| APIs | ✔ | ✔ | ✔ |
163163

defender-endpoint/supported-capabilities-by-platform.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -52,17 +52,17 @@ The following table gives information about the supported Microsoft Defender for
5252
|[Vulnerability management](/defender-vulnerability-management/defender-vulnerability-management)|![Yes.](media/svg/check-yes.svg)|![Yes.](media/svg/check-yes.svg)|![Yes.](media/svg/check-yes.svg)|![Yes.](media/svg/check-yes.svg) <br/>(preview)|
5353
|**Response** | | | ||
5454
|[Automated Investigation & Response (AIR)](automated-investigations.md) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![No](media/svg/check-no.svg) | ![No](media/svg/check-no.svg) |
55-
|[Device response capabilities: collect investigation package ](respond-machine-alerts.md) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) <br/>(preview) | ![Yes.](media/svg/check-yes.svg) <br/>(preview) |
55+
|[Device response capabilities: collect investigation package ](respond-machine-alerts.md) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) |
5656
|[Device response capabilities: run antivirus scan](respond-machine-alerts.md) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) |
5757
|[Device isolation](respond-machine-alerts.md) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) |
58-
|File response capabilities: collect file, deep analysis, block file, stop, and quarantine processes | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) <br/>(preview) | ![Yes.](media/svg/check-yes.svg) <br/>(preview) |
58+
|File response capabilities: collect file, deep analysis | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) |
59+
|File response capabilities: block file, stop, and quarantine processes | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![No](media/svg/check-no.svg) | ![No](media/svg/check-no.svg) |
5960
|[Live Response](live-response.md) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) | ![Yes.](media/svg/check-yes.svg) |
6061

6162
> [!NOTE]
6263
> - For Windows Server 2012 R2 and Windows Server 2016, use the modern, unified solution. See [Onboard Windows Servers to the Defender for Endpoint service](configure-server-endpoints.md).
64+
> - On Linux Server, network protection, web protection, and custom network indicators are currently in preview.
6365
> - On Linux, network protection, web protection, and custom network indicators are currently in preview.
64-
> - On Linux and Mac, [Device response capabilities: collect investigation package ](respond-machine-alerts.md) is currently in preview. You can also use [Live Response](live-response.md).
65-
> - On Linux and Mac, [File response capabilities: collect file, deep analysis, block file, stop, and quarantine processes](respond-file-alerts.md) are currently in preview. You can also use [Live Response](live-response.md).
6666
> - Endpoint & network device discovery is supported on Windows Server 2019 or later, and on Windows 10 and Windows 11.
6767
> - Microsoft Defender Vulnerability Management is not supported on Rocky and Alma currently.
6868
> - For Windows 7, Windows 8.1, and Windows Server 2008 R2, use System Center Endpoint Protection (SCEP) for the EDR sensor and antivirus protection.

0 commit comments

Comments
 (0)