Skip to content

Commit 2cfc58d

Browse files
Merge pull request #1319 from rayne-wiselman/rayne-unified-september11
Rayne unified september11 - DO NOT MERGE, WORK IN PROGRESS
2 parents d3bac53 + 4e86e2e commit 2cfc58d

File tree

9 files changed

+672
-20
lines changed

9 files changed

+672
-20
lines changed

defender-xdr/unified-secops-platform/TOC.yml renamed to unified-secops-platform/TOC.yml

Lines changed: 12 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -4,26 +4,18 @@
44
items:
55
- name: Overview
66
items:
7-
- name: What is the Microsoft unified security operations platform?
8-
href: /defender-xdr/microsoft-365-defender ## PLACEHOLDER LINK
7+
- name: What's the Microsoft unified security operations platform?
8+
href: overview-unified-security.md
99
- name: What's new
1010
href: /defender-xdr/unified-soc-platform/whats-new.md
1111
- name: Defender portal service integration
1212
items:
13-
- name: Microsoft Defender XDR
14-
href: /defender-xdr/microsoft-365-defender-portal ## Placeholder article
15-
- name: Microsoft Security Exposure Management
13+
- name: Overview
14+
href: overview-defender-portal.md
15+
- name: Defender XDR
16+
href: /defender-xdr/microsoft-365-defender
17+
- name: Security Exposure Management
1618
href: /security-exposure-management/get-started-exposure-management
17-
- name: Microsoft Sentinel
18-
items:
19-
- name: Microsoft Sentinel integration
20-
href: /azure/sentinel/microsoft-365-defender-sentinel-integration?toc=/unified-soc-platform/toc.json&bc=/unified-soc-platform/breadcrumb/toc.json&tabs=defender-portal
21-
- name: Experience in the Defender portal
22-
href: /azure/sentinel/microsoft-sentinel-defender-portal?toc=/unified-soc-platform/toc.json&bc=/unified-soc-platform/breadcrumb/toc.json
23-
- name: Microsoft Defender for Cloud
24-
href: /defender-xdr/microsoft-365-security-center-defender-cloud
25-
- name: Microsoft Defender for IoT
26-
href: /defender-for-iot/microsoft-defender-iot
2719
- name: Microsoft Copilot for Security in the Defender portal
2820
href: /defender-xdr/security-copilot-in-microsoft-365-defender
2921
- name: Plan ## Leverage existing zero trust articles? One article for USX all up planning (like guide that links out).
@@ -96,7 +88,11 @@
9688
href: /defender-xdr/advanced-hunting-shared-queries
9789
- name: Investigate incidents ## could be incidents, threats, posture findings. Need an overview article for USX. Current overviews (XDR/Sentinel) don't appear to be updated for USX.
9890
items:
99-
- name: Overview
91+
- name: Incident response overview
92+
href: incident-response-overview.md
93+
- name: Incident response planning
94+
href: incident-response-planning.md
95+
- name: Incident investigation overview
10096
href: /defender-xdr/investigate-incidents ## Would need update to apply to USX. Per Dianne, this isn't XDR specific.
10197
- name: Alerts, incidents, and correlation
10298
href: /defender-xdr/alerts-incidents-correlation

defender-xdr/unified-secops-platform/breadcrumb/toc.yml renamed to unified-secops-platform/breadcrumb/toc.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
topicHref: /defender/index
44
items:
55
- name: 'Microsoft unified security operations platform'
6-
tocHref: /defender-xdr/unified-soc-platform/
7-
topicHref: /defender-xdr/unified-soc-platform/index
6+
tocHref: /unified-soc-platform/
7+
topicHref: /unified-soc-platform/index
88
- name: 'Microsoft unified security operations platform'
99
tocHref: /security/zero-trust/
1010
topicHref: /defender-xdr/unified-soc-platform/index
1111
- name: Unified security operations platform
1212
tocHref: /defender-for-identity/
13-
topicHref: /defender-xdr/unified-soc-platform/index
13+
topicHref: /unified-soc-platform/index
1414

1515
## Microsoft Sentinel override
1616
- name: 'Microsoft Defender'
@@ -19,4 +19,4 @@
1919
items:
2020
- name: 'Unified security operations platform'
2121
tocHref: /azure/sentinel/
22-
topicHref: /defender-xdr/unified-soc-platform/index
22+
topicHref: /unified-soc-platform/index
Lines changed: 81 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,81 @@
1+
---
2+
title: Microsoft Defender XDR in the Defender portal
3+
description: Learn about Microsoft Defender XDR in the Defender portal
4+
search.appverid: met150
5+
ms.service: defender-xdr
6+
ms.author: cwatson
7+
author: cwatson-cat
8+
ms.localizationpriority: medium
9+
ms.date: 07/16/2024
10+
audience: ITPro
11+
ms.collection:
12+
- M365-security-compliance
13+
- tier1
14+
- usx-security
15+
ms.topic: conceptual
16+
---
17+
18+
# Defender XDR in the Defender portal
19+
20+
Microsoft's unified security platform combines services in the [Microsoft Defender portal](https://security.microsoft.com). In the Defender portal, you can monitor and manage pre-breach and post-breach security across your organization's on-premises and multicloud assets and workloads.
21+
22+
Defender XDR in the Defender portal combines protection, detection, investigation, and response to threats across your entire organization and all its components, in a central place. Defender XDR combines a number of Microsoft's security services into a single location.
23+
24+
25+
**[Defender for Office 365](/defender-office-365/mdo-sec-ops-guid)** | Helps secure organizations with a set of prevention, detection, investigation and hunting features to protect email, and Office 365 resources.
26+
**[Defender for Endpoint](/defender-endpoint/mde-sec-ops-guide)** | Delivers preventative protection, post-breach detection, automated investigation, and response for devices in the organization.
27+
**[Defender for Identity](/defender-xdr/microsoft-365-security-center-mdi)** | Provides a cloud-based security solution that uses on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization.
28+
**[Defender for Cloud Apps](/defender-xdr/microsoft-365-security-center-defender-cloud-app)** | Provides a comprehensive cross-SaaS and PaaS solution that brings deep visibility, strong data controls, and enhanced threat protection to your cloud apps.
29+
**[Microsoft Sentinel](/azure/sentinel/microsoft-365-defender-sentinel-integration)** Microsoft Sentinel is a cloud services that enables security information and event management (SIEM) and Provides in the Defender portal, Microsoft Sentinel integrates with Defender XDR to provide threat protection in the unified security operations platform. Microsoft Sentinel is a a cloud-native security information and event management (SIEM) solution and security orchestration automation response. Sentinel integrates with Defender XDR to provided a unified security platform for threat detection, investigation, hunting, and response.
30+
31+
32+
> [!NOTE]
33+
> When you open the portal, you see only the security services included in your subscriptions. For example, if you have Defender for Office 365 but not Defender for Endpoint, you see features and capabilities for Defender for Office 365, but not for device protection.
34+
35+
36+
## Investigate incidents and alerts
37+
38+
Centralizing security information creates a single place to investigate security incidents across your entire organization and all its components including:
39+
40+
- Hybrid identities
41+
- Endpoints
42+
- Cloud apps
43+
- Business apps
44+
- Email and docs
45+
- IoT
46+
- Network
47+
- Business applications
48+
- Operational technology (OT)
49+
- Infrastructure and cloud workloads
50+
51+
A primary example is **Incidents** under **Incidents & alerts**.
52+
53+
:::image type="content" source="/defender/media/incidents-queue/incidents-ss-incidents.png" alt-text="The Incidents page in the Microsoft Defender portal." lightbox="/defender/media/incidents-queue/incidents-ss-incidents.png":::
54+
55+
Selecting an incident name displays a page that demonstrates the value of centralizing security information as you get better insights into the full extend of a threat, from email, to identity, to endpoints.
56+
57+
:::image type="content" source="../../defender/media/incidents-overview/incidents-ss-incident-summary.png" alt-text="Screenshot that shows the attack story page for an incident in the Microsoft Defender portal." lightbox="../../defender/media/incidents-overview/incidents-ss-incident-summary.png":::
58+
59+
Take the time to review the incidents in your environment, drill down into each alert, and practice building an understanding of how to access the information and determine next steps in your analysis.
60+
61+
Learn more about [incidents in the Defender portal](../incidents-overview.md), and [managing incidents and alerts](../manage-incidents.md).
62+
63+
## Hunt for threats
64+
65+
You can build custom detection rules and hunt for specific threats in your environment. **Hunting** uses a query-based threat hunting tool that lets you proactively inspect events in your organization to locate threat indicators and entities. These rules run automatically to check for, and then respond to, suspected breach activity, misconfigured machines, and other findings.
66+
67+
Learn about [proactive threat hunting](../advanced-hunting-overview.md), and [hunting for threats across devices, emails, apps, and identities](../advanced-hunting-query-emails-devices.md).
68+
69+
70+
## Respond to emerging threats
71+
72+
Threat analytics is the Microsoft threat intelligence solution from expert Microsoft security researchers.In the portal, track and respond to emerging threats with these threat analytics:
73+
74+
- Active threat actors and their campaigns
75+
- Popular and new attack techniques
76+
- Critical vulnerabilities
77+
- Common attack surfaces
78+
- Prevalent malware
79+
80+
Learn about [tracking and responding to emerging threats with threat analytics](../threat-analytics.md).
81+

0 commit comments

Comments
 (0)