Skip to content

Commit 18bf72d

Browse files
authored
Merge pull request #1551 from cwatson-cat/10-8-24-fx-toc-path
USX - Move USX back so staging works + upd TOC + chg ms.service
2 parents 2cfc58d + 4890fd0 commit 18bf72d

File tree

9 files changed

+34
-32
lines changed

9 files changed

+34
-32
lines changed

unified-secops-platform/TOC.yml renamed to defender-xdr/unified-secops-platform/TOC.yml

Lines changed: 10 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -88,11 +88,7 @@
8888
href: /defender-xdr/advanced-hunting-shared-queries
8989
- name: Investigate incidents ## could be incidents, threats, posture findings. Need an overview article for USX. Current overviews (XDR/Sentinel) don't appear to be updated for USX.
9090
items:
91-
- name: Incident response overview
92-
href: incident-response-overview.md
93-
- name: Incident response planning
94-
href: incident-response-planning.md
95-
- name: Incident investigation overview
91+
- name: Overview
9692
href: /defender-xdr/investigate-incidents ## Would need update to apply to USX. Per Dianne, this isn't XDR specific.
9793
- name: Alerts, incidents, and correlation
9894
href: /defender-xdr/alerts-incidents-correlation
@@ -193,4 +189,12 @@
193189
- name: Microsoft virus initiative
194190
href: /defender-xdr/virus-initiative-criteria
195191
- name: Microsoft security portals
196-
href: /defender-xdr/portals
192+
href: /defender-xdr/portals
193+
- name: Operation guides
194+
items:
195+
- name: Incident response
196+
items:
197+
- name: Overview
198+
href: incident-response-overview.md
199+
- name: Incident response
200+
href: incident-response-planning.md

unified-secops-platform/breadcrumb/toc.yml renamed to defender-xdr/unified-secops-platform/breadcrumb/toc.yml

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
topicHref: /defender/index
44
items:
55
- name: 'Microsoft unified security operations platform'
6-
tocHref: /unified-soc-platform/
7-
topicHref: /unified-soc-platform/index
6+
tocHref: /unified-secops-platform/
7+
topicHref: /defender-xdr/unified-secops-platform/index
88
- name: 'Microsoft unified security operations platform'
99
tocHref: /security/zero-trust/
10-
topicHref: /defender-xdr/unified-soc-platform/index
10+
topicHref: /defender-xdr/unified-secops-platform/index
1111
- name: Unified security operations platform
1212
tocHref: /defender-for-identity/
13-
topicHref: /unified-soc-platform/index
13+
topicHref: /defender-xdr/unified-secops-platform/index
1414

1515
## Microsoft Sentinel override
1616
- name: 'Microsoft Defender'
@@ -19,4 +19,4 @@
1919
items:
2020
- name: 'Unified security operations platform'
2121
tocHref: /azure/sentinel/
22-
topicHref: /unified-soc-platform/index
22+
topicHref: /defender-xdr/unified-secops-platform/index

unified-secops-platform/defender-xdr-portal.md renamed to defender-xdr/unified-secops-platform/defender-xdr-portal.md

Lines changed: 7 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -2,11 +2,11 @@
22
title: Microsoft Defender XDR in the Defender portal
33
description: Learn about Microsoft Defender XDR in the Defender portal
44
search.appverid: met150
5-
ms.service: defender-xdr
5+
ms.service: unified-secops-platform
66
ms.author: cwatson
77
author: cwatson-cat
88
ms.localizationpriority: medium
9-
ms.date: 07/16/2024
9+
ms.date: 10/08/2024
1010
audience: ITPro
1111
ms.collection:
1212
- M365-security-compliance
@@ -22,12 +22,10 @@ Microsoft's unified security platform combines services in the [Microsoft Defend
2222
Defender XDR in the Defender portal combines protection, detection, investigation, and response to threats across your entire organization and all its components, in a central place. Defender XDR combines a number of Microsoft's security services into a single location.
2323

2424

25-
**[Defender for Office 365](/defender-office-365/mdo-sec-ops-guid)** | Helps secure organizations with a set of prevention, detection, investigation and hunting features to protect email, and Office 365 resources.
26-
**[Defender for Endpoint](/defender-endpoint/mde-sec-ops-guide)** | Delivers preventative protection, post-breach detection, automated investigation, and response for devices in the organization.
27-
**[Defender for Identity](/defender-xdr/microsoft-365-security-center-mdi)** | Provides a cloud-based security solution that uses on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.
28-
**[Defender for Cloud Apps](/defender-xdr/microsoft-365-security-center-defender-cloud-app)** | Provides a comprehensive cross-SaaS and PaaS solution that brings deep visibility, strong data controls, and enhanced threat protection to your cloud apps.
29-
**[Microsoft Sentinel](/azure/sentinel/microsoft-365-defender-sentinel-integration)** Microsoft Sentinel is a cloud services that enables security information and event management (SIEM) and Provides in the Defender portal, Microsoft Sentinel integrates with Defender XDR to provide threat protection in the unified security operations platform. Microsoft Sentinel is a a cloud-native security information and event management (SIEM) solution and security orchestration automation response. Sentinel integrates with Defender XDR to provided a unified security platform for threat detection, investigation, hunting, and response.
30-
25+
**[Defender for Office 365](/defender-office-365/mdo-about)** | Helps secure organizations with a set of prevention, detection, investigation and hunting features to protect email, and Office 365 resources.
26+
**[Defender for Endpoint](/defender-endpoint/)** | Delivers preventative protection, post-breach detection, automated investigation, and response for devices in the organization.
27+
**[Defender for Identity](/defender-for-identity/what-is)** | Provides a cloud-based security solution that uses on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.
28+
**[Defender for Cloud Apps](/cloud-app-security/)** | Provides a comprehensive cross-SaaS and PaaS solution that brings deep visibility, strong data controls, and enhanced threat protection to your cloud apps.
3129

3230
> [!NOTE]
3331
> When you open the portal, you see only the security services included in your subscriptions. For example, if you have Defender for Office 365 but not Defender for Endpoint, you see features and capabilities for Defender for Office 365, but not for device protection.
@@ -54,7 +52,7 @@ A primary example is **Incidents** under **Incidents & alerts**.
5452

5553
Selecting an incident name displays a page that demonstrates the value of centralizing security information as you get better insights into the full extend of a threat, from email, to identity, to endpoints.
5654

57-
:::image type="content" source="../../defender/media/incidents-overview/incidents-ss-incident-summary.png" alt-text="Screenshot that shows the attack story page for an incident in the Microsoft Defender portal." lightbox="../../defender/media/incidents-overview/incidents-ss-incident-summary.png":::
55+
<!-- commenting this out as the file path will move soon and I don't want to fight with this broken link anymore. File path is changing anyway. :::image type="content" source="../../media/incidents-overview/incidents-ss-incident-summary.png" alt-text="Screenshot that shows the attack story page for an incident in the Microsoft Defender portal." lightbox="../../media/incidents-overview/incidents-ss-incident-summary.png"::: -->
5856

5957
Take the time to review the incidents in your environment, drill down into each alert, and practice building an understanding of how to access the information and determine next steps in your analysis.
6058

unified-secops-platform/incident-response-overview.md renamed to defender-xdr/unified-secops-platform/incident-response-overview.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,11 +2,11 @@
22
title: Incident response overview
33
description: Get an overview of incident response processes and best practices
44
search.appverid: met150
5-
ms.service: defender-xdr
6-
ms.author: cwatson
7-
author: cwatson-cat
5+
ms.service: unified-secops-platform
6+
author: yelevin
7+
ms.author: yelevin
88
ms.localizationpriority: medium
9-
ms.date: 07/16/2024
9+
ms.date: 10/08/2024
1010
audience: ITPro
1111
ms.collection:
1212
- M365-security-compliance

unified-secops-platform/incident-response-planning.md renamed to defender-xdr/unified-secops-platform/incident-response-planning.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,11 +2,11 @@
22
title: Incident response planning
33
description: Start planning for incident handling
44
search.appverid: met150
5-
ms.service: defender-xdr
6-
ms.author: cwatson
7-
author: cwatson-cat
5+
ms.service: unified-secops-platform
6+
author: yelevin
7+
ms.author: yelevin
88
ms.localizationpriority: medium
9-
ms.date: 07/16/2024
9+
ms.date: 10/08/2024
1010
audience: ITPro
1111
ms.collection:
1212
- M365-security-compliance
File renamed without changes.

unified-secops-platform/overview-defender-portal.md renamed to defender-xdr/unified-secops-platform/overview-defender-portal.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Microsoft Defender portal overview
33
description: Learn about the Microsoft Defender portal
44
search.appverid: met150
5-
ms.service: defender-xdr
5+
ms.service: unified-secops-platform
66
ms.author: cwatson
77
author: cwatson-cat
88
ms.localizationpriority: medium
@@ -33,8 +33,8 @@ The Defender portal combines a number of Microsoft security services in a single
3333
**Service** | **Details**
3434
--- | ---
3535
**[Microsoft Defender XDR](defender-xdr-portal.md)** | In the Defender portal, protect against security threats to assets and resources across the organization, including devices, email and collaboration tools, SaaS cloud apps, Entra ID threats, cloud and on-premises workloads, and OT/IT resources. Get integrated incidents and alerts, threat hunting, and threat protection services and capabilities included in Defender XDR.
36-
**[Microsoft Defender Threat Intelligence](../../defender/threat-intelligence/what-is-microsoft-defender-threat-intelligence-defender-ti.md)** | From the Defender portal, conduct threat infrastructure analysis, and gather threat intelligence.
37-
**[Microsoft Security Exposure Management](../../exposure-management/microsoft-security-exposure-management)** | In the Defender portal, get a unified view of security posture across organizational assets. Assess the security state of assets, and identify and remediate security risk to reduce attack surfaces.
36+
**[Microsoft Defender Threat Intelligence](/defender/threat-intelligence/what-is-microsoft-defender-threat-intelligence-defender-ti)** | From the Defender portal, conduct threat infrastructure analysis, and gather threat intelligence.
37+
**[Microsoft Security Exposure Management](/security-exposure-management/microsoft-security-exposure-management)** | In the Defender portal, get a unified view of security posture across organizational assets. Assess the security state of assets, and identify and remediate security risk to reduce attack surfaces.
3838
**[Microsoft Defender for Cloud](/defender-xdr/microsoft-365-security-center-defender-cloud)** | Defender for Cloud improves multicloud and on-premises security posture, and protect cloud workloads against security threats. It integrates into the Defender portal so that security teams can access Defender for Cloud alerts in the portal, providing a single location with added rich context for security investigations.
3939
**[Microsoft Defender for IoT](/defender-for-iot/microsoft-defender-iot)** | Defender for IoT integrates into the Defender portal to identify and protect OT/IT resources by extending Defender XDR protection to OT environments.
4040

unified-secops-platform/overview-unified-security.md renamed to defender-xdr/unified-secops-platform/overview-unified-security.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: What is the Microsoft unified security operations platform?
33
description: Provides an overview of features and functionality in the Microsoft unified security operations platform
44
search.appverid: met150
5-
ms.service: defender-xdr
5+
ms.service: unified-secops-platform
66
ms.author: cwatson
77
author: cwatson-cat
88
ms.localizationpriority: medium
File renamed without changes.

0 commit comments

Comments
 (0)