Skip to content

Commit 15bb90b

Browse files
Merge pull request #5166 from MicrosoftDocs/main
[AutoPublish] main to live - 09/29 15:28 PDT | 09/30 03:58 IST
2 parents 2ff3378 + d0d4fdf commit 15bb90b

File tree

520 files changed

+3398
-3615
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

520 files changed

+3398
-3615
lines changed

defender-endpoint/access-mssp-portal.md

Lines changed: 6 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
---
1+
---
22
title: Access the Microsoft Defender XDR MSSP customer portal
33
description: Access the Microsoft Defender XDR MSSP customer portal
44
ms.service: defender-endpoint
@@ -14,19 +14,16 @@ ms.collection:
1414
ms.topic: how-to
1515
search.appverid: met150
1616
ms.date: 03/21/2025
17-
---
17+
appliesto:
18+
- Microsoft Defender for Endpoint Plan 1
19+
- Microsoft Defender for Endpoint Plan 2
1820

21+
---
1922
# Access the Microsoft Defender XDR MSSP customer portal
2023

21-
**Applies to:**
22-
23-
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
24-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
25-
- [Microsoft Defender XDR](/defender-xdr)
2624

2725
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2826

29-
> Want to experience Microsoft Defender for Endpoint? [Sign up for a free trial.](https://go.microsoft.com/fwlink/p/?linkid=2225630)
3027

3128
> [!IMPORTANT]
3229
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
@@ -54,3 +51,4 @@ Use the following steps to obtain the MSSP customer tenant ID and then use the I
5451
- [Configure alert notifications](configure-mssp-notifications.md)
5552
- [Fetch alerts from customer tenant](api/fetch-alerts-mssp.md)
5653
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]
54+

defender-endpoint/admin-submissions-mde.md

Lines changed: 2 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ title: Submit files in Microsoft Defender for Endpoint
33
description: Learn how to use the unified submissions feature in Microsoft Defender XDR to submit suspicious emails, URLs, email attachments, and files to Microsoft for scanning.
44
search.appverid: met150
55
ms.date: 05/06/2024
6+
appliesto:
7+
- Microsoft Defender for Endpoint
68
ms.service: defender-endpoint
79
ms.author: bagol
810
author: batamig
@@ -20,12 +22,6 @@ ms.custom: FPFN
2022

2123
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2224

23-
**Applies to**
24-
25-
- [Microsoft Defender for Endpoint](https://go.microsoft.com/fwlink/p/?linkid=2146806)
26-
- [Microsoft Defender XDR](/defender-xdr)
27-
28-
> Want to experience Microsoft Defender for Endpoint? [Sign up for a free trial](https://www.microsoft.com/microsoft-365/windows/microsoft-defender-atp?ocid=docs-wdatp-usewdatp-abovefoldlink).
2925

3026
In Microsoft Defender for Endpoint, admins can use the unified submissions feature to submit files and file hashes (SHAs) to Microsoft for review. The unified submissions experience is a one-stop shop for submitting emails, URLs, email attachments, and files in one, easy-to-use submission experience. Admins can use the Microsoft Defender portal or the Microsoft Defender for Endpoint Alert page to submit suspicious files.
3127

defender-endpoint/adv-tech-of-mdav.md

Lines changed: 7 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
---
1+
---
22
title: Advanced technologies at the core of Microsoft Defender Antivirus
33
description: Microsoft Defender Antivirus engines and advanced technologies
44
author: batamig
@@ -13,18 +13,14 @@ ms.localizationpriority: medium
1313
ms.custom: partner-contribution
1414
f1.keyboards: NOSCH
1515
audience: ITPro
16+
appliesto:
17+
- Microsoft Defender for Endpoint Plan 1
18+
- Microsoft Defender for Endpoint Plan 2
19+
- Microsoft Defender for Business
20+
- Microsoft Defender for Individuals
1621
---
17-
1822
# Advanced technologies at the core of Microsoft Defender Antivirus
1923

20-
**Applies to:**
21-
22-
- [Microsoft Defender XDR](/defender-xdr)
23-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
24-
- [Microsoft Defender for Business](https://www.microsoft.com/security/business/endpoint-security/microsoft-defender-business)
25-
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
26-
- Microsoft Defender Antivirus
27-
- [Microsoft Defender for Individuals](https://www.microsoft.com/microsoft-365/microsoft-defender-for-individuals?msockid=0f1c3b9963366db31ba02e78621b6c1e#Overview)
2824

2925
Microsoft Defender Antivirus and the multiple engines that lead to the advanced detection and prevention technologies under the hood to detect and stop a wide range of threats and attacker techniques at multiple points, as depicted in the following diagram:
3026

@@ -101,3 +97,4 @@ We focus on every industry.
10197
When you're pen-testing, you should demand where no human analysts are engaged on detect/protect, to see how the actual antivirus engine (prebreach) efficacy truly is, and a separate one where human analysts are engaged. You can add [Microsoft Defender Experts for XDR](/defender-xdr/dex-xdr-overview) a managed extended detection and response service to augment your SOC.
10298

10399
The ***continuous iterative enhancement*** each of these engines to be increasingly effective at catching the latest strains of malware and attack methods. These enhancements show up in consistent [top scores in industry tests](/defender-xdr/top-scoring-industry-tests), but more importantly, translate to [threats and malware outbreaks](https://www.microsoft.com/security/blog/2018/03/07/behavior-monitoring-combined-with-machine-learning-spoils-a-massive-dofoil-coin-mining-campaign/) stopped and [more customers protected](https://www.microsoft.com/security/blog/2018/03/22/why-windows-defender-antivirus-is-the-most-deployed-in-the-enterprise/).
100+

defender-endpoint/advanced-features.md

Lines changed: 5 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
---
1+
---
22
title: Configure advanced features in Microsoft Defender for Endpoint
33
description: Turn on advanced features such as block file in Microsoft Defender for Endpoint.
44
ms.service: defender-endpoint
@@ -15,19 +15,16 @@ ms.topic: how-to
1515
ms.subservice: onboard
1616
search.appverid: met150
1717
ms.date: 02/25/2025
18-
---
18+
appliesto:
19+
- Microsoft Defender for Endpoint Plan 2
1920

21+
---
2022
# Configure advanced features in Defender for Endpoint
2123

22-
**Applies to:**
23-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
24-
- [Microsoft Defender XDR](/defender-xdr)
2524

2625
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2726

2827

29-
> Want to experience Defender for Endpoint? [Sign up for a free trial.](https://go.microsoft.com/fwlink/p/?linkid=2225630)
30-
3128
Depending on the Microsoft security products that you use, some advanced features might be available for you to integrate Defender for Endpoint with.
3229

3330
## Enable advanced features
@@ -219,3 +216,4 @@ For proactive hunting across the full scope of Microsoft Defender XDR, including
219216
- [Configure alert notifications](/defender-xdr/configure-email-notifications)
220217

221218
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]
219+

defender-endpoint/alerts-queue-endpoint-detection-response.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,9 @@ ms.collection:
1515
- mde-edr
1616
ms.topic: article
1717
ms.date: 03/26/2025
18+
appliesto:
19+
- Microsoft Defender for Endpoint Plan 1
20+
- Microsoft Defender for Endpoint Plan 2
1821
ms.subservice: edr
1922
search.appverid: met150
2023
---
@@ -23,11 +26,7 @@ search.appverid: met150
2326

2427
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2528

26-
**Applies to:**
27-
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
28-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
2929

30-
> Want to experience Defender for Endpoint? [Sign up for a free trial.](https://go.microsoft.com/fwlink/p/?linkid=2225630)
3130

3231
Learn how you can view and manage the queue so that you can effectively investigate threats seen on entities such as devices, files, or user accounts.
3332

@@ -43,4 +42,5 @@ Topic|Description
4342
[Investigate an IP address](investigate-ip.md)|Examine possible communication between devices in your network and external internet protocol (IP) addresses.
4443
[Investigate a domain](investigate-domain.md)|Investigate a domain to see if devices and servers in your network have been communicating with a known malicious domain.
4544
[Investigate a user account](investigate-user.md)|Identify user accounts with the most active alerts and investigate cases of potential compromised credentials.
45+
4646
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

defender-endpoint/alerts-queue.md

Lines changed: 6 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
---
1+
---
22
title: View and organize the Microsoft Defender for Endpoint Alerts queue
33
description: Learn about how the Microsoft Defender for Endpoint alerts queues work, and how to sort and filter lists of alerts.
44
ms.service: defender-endpoint
@@ -15,16 +15,16 @@ ms.topic: article
1515
ms.date: 03/26/2025
1616
ms.subservice: edr
1717
search.appverid: met150
18-
---
18+
appliesto:
19+
- Microsoft Defender for Endpoint Plan 2
1920

21+
---
2022
# View and organize the Microsoft Defender for Endpoint Alerts queue
2123

2224
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2325

24-
**Applies to:**
25-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
2626

27-
> Want to experience Defender for Endpoint? [Sign up for a free trial.](https://go.microsoft.com/fwlink/p/?linkid=2225630)
27+
2828

2929
The **Alerts queue** shows a list of alerts that were flagged from devices in your network. By default, the queue displays alerts seen in the last 7 days in a grouped view. The most recent alerts are shown at the top of the list helping you see the most recent alerts first.
3030

@@ -140,3 +140,4 @@ You can choose to filter the alerts based on their Automated investigation state
140140
- [Investigate a domain associated with a Microsoft Defender for Endpoint alert](investigate-domain.md)
141141
- [Investigate a user account in Microsoft Defender for Endpoint](investigate-user.md)
142142
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]
143+

defender-endpoint/amsi-on-mdav.md

Lines changed: 5 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,11 @@ ms.author: bagol
66
manager: bagol
77
ms.reviewer: yongrhee
88
ms.date: 12/05/2024
9+
appliesto:
10+
- Microsoft Defender for Endpoint Plan 1
11+
- Microsoft Defender for Endpoint Plan 2
12+
- Microsoft Defender for Business
13+
- Microsoft Defender for Individuals
914
ms.topic: concept-article
1015
ms.service: defender-endpoint
1116
ms.subservice: ngp
@@ -23,13 +28,6 @@ ai-usage: ai-assisted
2328

2429
# Anti-malware Scan Interface (AMSI) integration with Microsoft Defender Antivirus
2530

26-
**Applies to**:
27-
28-
- Microsoft Defender XDR
29-
- Microsoft Defender Antivirus
30-
- Microsoft Defender for Endpoint P1 & P2
31-
- Microsoft Defender for Business
32-
- Microsoft Defender for Individuals
3331

3432
**Platforms**:
3533

defender-endpoint/analyzer-feedback.md

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,15 +16,14 @@ ms.collection:
1616
ms.topic: how-to
1717
ms.subservice: ngp
1818
search.appverid: met150
19+
appliesto:
20+
- Microsoft Defender for Endpoint Plan 1
21+
- Microsoft Defender for Endpoint Plan 2
1922
ms.date: 03/26/2025
2023
---
2124

2225
# Provide feedback on the Microsoft Defender for Endpoint client analyzer tool
2326

24-
**Applies to:**
25-
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
26-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
27-
2827
If you have feedback or suggestions that would help us improve the Microsoft Defender for Endpoint client analyzer, use either of these options to submit feedback:
2928

3029
1. Microsoft Defender portal (security.microsoft.com):

defender-endpoint/analyzer-report.md

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,14 +16,13 @@ ms.topic: concept-article
1616
ms.subservice: onboard
1717
search.appverid: met150
1818
ms.date: 03/27/2025
19+
appliesto:
20+
- Microsoft Defender for Endpoint Plan 1
21+
- Microsoft Defender for Endpoint Plan 2
1922
---
2023

2124
# Understand the client analyzer HTML report
2225

23-
**Applies to:**
24-
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
25-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
26-
2726
The client analyzer produces a report in HTML format. Learn how to review the report to identify potential sensor issues so that you can troubleshoot them.
2827

2928
Use the following example to understand the report.

defender-endpoint/android-configure-mam.md

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -15,16 +15,15 @@ ms.collection:
1515
ms.topic: how-to
1616
ms.subservice: android
1717
ms.date: 08/26/2024
18+
appliesto:
19+
- Microsoft Defender for Endpoint Plan 1
20+
- Microsoft Defender for Endpoint Plan 2
1821
---
1922

2023
# Configure Microsoft Defender for Endpoint on Android risk signals using App Protection Policies (MAM)
2124

2225
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2326

24-
**Applies to:**
25-
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
26-
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
27-
- [Microsoft Defender XDR](/defender-xdr)
2827

2928
Microsoft Defender for Endpoint on Android, which already protects enterprise users on Mobile Device Management (MDM) scenarios, now extends support to Mobile App Management (MAM), for devices that aren't enrolled using Intune mobile device management (MDM). It also extends this support to customers who use other enterprise mobility management solutions, while still using Intune for mobile application management (MAM). This capability allows you to manage and protect your organization's data within an application.
3029

0 commit comments

Comments
 (0)