Skip to content

Commit 339037c

Browse files
committed
Merge branch 'main' into diannegali-tvmappliesto
2 parents d33eee3 + 215ff41 commit 339037c

File tree

9 files changed

+77
-63
lines changed

9 files changed

+77
-63
lines changed

defender-endpoint/TOC.yml

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1078,13 +1078,14 @@
10781078
href: information-protection-investigation.md
10791079

10801080
- name: Advanced hunting
1081-
href: /defender-xdr/advanced-hunting-overview
1081+
href: /defender-xdr/advanced-hunting-overview?toc=/defender-endpoint/toc.json&bc=/defender-endpoint/breadcrumb/toc.json
10821082

1083-
- name: Threat analytics overview
1084-
href: /defender-xdr/threat-analytics
1083+
- name: Threat analytics
10851084
items:
1085+
- name: Overview
1086+
href: /defender-xdr/threat-analytics?toc=/defender-endpoint/toc.json&bc=/defender-endpoint/breadcrumb/toc.json
10861087
- name: Read the analyst report
1087-
href: /defender-xdr/threat-analytics-analyst-reports
1088+
href: /defender-xdr/threat-analytics-analyst-reports?toc=/defender-endpoint/toc.json&bc=/defender-endpoint/breadcrumb/toc.json
10881089

10891090
- name: EDR in block mode
10901091
href: edr-in-block-mode.md

defender-endpoint/api/get-browser-extensions-permission-info.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.topic: reference
1515
ms.subservice: reference
1616
ms.custom: api
1717
search.appverid: met150
18-
ms.date: 06/01/2022
18+
ms.date: 03/05/2025
1919
---
2020

2121
# Get browser extensions permission information
@@ -24,10 +24,10 @@ ms.date: 06/01/2022
2424

2525
**Applies to:**
2626

27-
- [Microsoft Defender for Endpoint Plan 1](../microsoft-defender-endpoint.md)
28-
- [Microsoft Defender for Endpoint Plan 2](../microsoft-defender-endpoint.md)
29-
- [Microsoft Defender Vulnerability Management](/defender-vulnerability-management)
30-
- [Microsoft Defender XDR](/defender-xdr)
27+
- [Microsoft Defender for Endpoint](/defender-endpoint/microsoft-defender-endpoint)
28+
29+
- [Microsoft Defender Vulnerability Management](/defender-vulnerability-management/defender-vulnerability-management-capabilities#vulnerability-management-capabilities-for-endpoints) (add-on for Defender for Endpoint Plan 2 or the standalone version)
30+
- [Microsoft Defender for Cloud Plan 2](/azure/defender-for-cloud/defender-for-cloud-introduction)
3131

3232
> Want to experience Microsoft Defender for Endpoint? [Sign up for a free trial.](https://go.microsoft.com/fwlink/p/?linkid=2225630&clcid=0x409&culture=en-us&country=us).
3333

defender-office-365/submissions-users-report-message-add-in-configure.md

Lines changed: 47 additions & 41 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ manager: deniseb
88
audience: Admin
99
ms.reviewer: dhagarwal
1010
ms.topic: how-to
11-
ms.date: 02/24/2025
11+
ms.date: 03/05/2025
1212
ms.localizationpriority: medium
1313
search.appverid:
1414
- MET150
@@ -75,67 +75,73 @@ The rest of this article describes how to remove the Report Message and Report P
7575
## Remove the Report Message or Report Phishing add-ins
7676

7777
> [!TIP]
78-
> It might take up to 24 hours for the add-in to disappear from your organization.
79-
>
8078
> If you delete the app registration for the add-in in Microsoft Entra ID, the add-in is also deleted from the organization.
8179
8280
1. In the Microsoft 365 admin center at <https://admin.microsoft.com>, expand **Show all** if necessary, and then go to **Settings** \> **Integrated apps**. Or, to go directly to the **Integrated apps** page, use <https://admin.microsoft.com/Adminportal/Home#/Settings/IntegratedApps>.
8381

8482
> [!TIP]
85-
> Admins in Microsoft 365 Government Community Cloud (GCC) or GCC High or DoD need to use the Microsoft 365 admin center at https://portal.office365.us/adminportal/home#/Settings/AddIns and than select Settings > Add-ins
83+
> Admins in Microsoft 365 Government Community Cloud (GCC), GCC High, or DoD need to use the Microsoft 365 admin center at <https://portal.office365.us/adminportal/home#/Settings/AddIns> and then select **Settings** \> **Add-ins**.
8684
>
87-
> Although the screenshots in the remaining steps show the **Report Phishing** add-in, the steps are identical for the **Report Message** add-in.
85+
> Although the screenshots in the following steps show the **Report Phishing** add-in, the steps are identical for the **Report Message** add-in.
8886
89-
2. On the **Deployed apps** tab of the **Integrated apps** page, select the **Report Message** add-in or the **Report Phishing** add-in by doing one of the following steps:
87+
2. On the **Deployed apps** tab of the **Integrated apps** page, select the **Report Message** add-in or the **Report Phishing** add-in by clicking anywhere in the row.
88+
89+
> [!div class="mx-imgBorder"]
90+
> :::image type="content" source="media/microsoft-365-admin-center-select-report-phish-add-in.png" alt-text="Screenshot of selecting the Report Phishing add-in on the Integrated apps page in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-select-report-phish-add-in.png":::
9091
91-
- In the **Name** column, select the icon or text for the add-in. This selection takes you to the **Overview** tab in the details flyout as described in the next steps.
92-
- In the **Name** column, select **** **Edit row**, and then select :::image type="icon" source="media/m365-cc-sc-add-internal-icon.png" border="false"::: **Edit users** to go to the **Users** tab in the details flyout as described in the next step.
93-
- In the **Name** column, select **** **Edit row**, and then select :::image type="icon" source="media/m365-cc-sc-show-trends-icon.png" border="false"::: **Check usage data** to go to the **Usage** tab in the details flyout as described in the next step.
92+
3. On the **Overview** tab of the details flyout that opens, select **Remove app** from the **Actions** section.
9493

9594
> [!div class="mx-imgBorder"]
96-
> :::image type="content" source="media/microsoft-365-admin-center-select-report-phish-add-in.png" alt-text="Select the Report Phishing add-in on the Integrated apps page in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-select-report-phish-add-in.png":::
95+
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-details-overview-tab.png" alt-text="Screenshot of the Overview tab on the details flyout of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-details-overview-tab.png":::
9796
98-
3. The details flyout that opens contains the following tabs:
97+
4. In the **Remove apps** confirmation flyout that opens, select **Yes, I'm sure I want to remove the app and associated data**, and then select **Remove**.
98+
99+
> [!div class="mx-imgBorder"]
100+
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-remove-overview-tab.png" alt-text="Screenshot of the tab on the removal flyout of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-remove-overview-tab.png":::
99101
100-
- **Overview** tab:
101-
- **Basic info** section:
102-
- **Status**
103-
- **Type**: Add-in
104-
- **Test deployment**: **Yes** or **No**, depending on the option you selected when you or the selection you change on the **Users** tab.
105-
- **Description**
106-
- **Host product**: Outlook
107-
- **Actions** section: Select **Remove app** to remove the app.
108-
- **Assigned users** section: Select **Edit users** to go to the **Users** tab. Use this setting to limit the users who have the add-in.
109-
- **Usage** section: Select **Check usage data** to got to the **Usage** tab.
102+
5. After a few moments, **Successfully removed** flyout appears. It might take up to 24 hours for the add-in to disappear from your organization.
110103

111-
> [!div class="mx-imgBorder"]
112-
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-details-overview-tab.png" alt-text="The Overview tab on the details flyout of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-details-overview-tab.png":::
104+
> [!div class="mx-imgBorder"]
105+
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-addin-remove-complete-tab.png" alt-text="Screenshot of the flyout showing the removal of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-addin-remove-complete-tab.png":::
113106
114-
> [!div class="mx-imgBorder"]
115-
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-remove-overview-tab.png" alt-text="The tab on the removal flyout of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-remove-overview-tab.png":::
107+
Select **Done** to return to the **Integrated apps** page where the add-in is no longer listed.
116108

117-
> [!div class="mx-imgBorder"]
118-
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-addin-remove-complete-tab.png" alt-text="The flyout showcasing the removal of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-addin-remove-complete-tab.png":::
109+
## Scope the Report Message or Report Phishing add-ins to a set of users
119110

120-
- **Users** tab:
121-
- **Is this a test deployment?**: Leave the toggle at :::image type="icon" source="media/scc-toggle-off.png" border="false"::: **No**, or set the toggle to :::image type="icon" source="media/scc-toggle-on.png" border="false"::: **Yes**.
122-
- **Assign users** section: Select one of the following values:
123-
- **Just me**
124-
- **Entire organization**
125-
- **Specific users/groups**: Find and select users and groups in the search box. After each selection, the user or group appears in the **Added users** section that appears below the search box. To remove a selection, select :::image type="icon" source="media/m365-cc-sc-remove-icon.png" border="false"::: on the entry.
111+
1. In the Microsoft 365 admin center at <https://admin.microsoft.com>, expand **Show all** if necessary, and then go to **Settings** \> **Integrated apps**. Or, to go directly to the **Integrated apps** page, use <https://admin.microsoft.com/Adminportal/Home#/Settings/IntegratedApps>.
126112

127-
- **Email notification** section: **Send email notification to assigned users** and **View email sample** aren't selectable.
113+
> [!TIP]
114+
> Admins in Microsoft 365 Government Community Cloud (GCC), GCC High, or DoD need to use the Microsoft 365 admin center at <https://portal.office365.us/adminportal/home#/Settings/AddIns> and then select **Settings** \> **Add-ins**.
115+
>
116+
> Although the screenshots in the following steps show the **Report Phishing** add-in, the steps are identical for the **Report Message** add-in.
128117
129-
If you made any updates on this tab, select **Update** to save your changes.
118+
2. On the **Deployed apps** tab of the **Integrated apps** page, select the **Report Message** add-in or the **Report Phishing** add-in by doing one of the following steps:
119+
- Select the add-in by clicking anywhere in the row. In the details flyout that opens, select the **Users** tab.
120+
- In the **Name** column, select **** \> **Edit users**.
121+
122+
> [!div class="mx-imgBorder"]
123+
> :::image type="content" source="media/microsoft-365-admin-center-select-report-phish-add-in.png" alt-text="Screenshot of selecting the Report Phishing add-in on the Integrated apps page in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-select-report-phish-add-in.png":::
124+
125+
3. On the **Users** tab of the details flyout, verify **Specific users/groups** is selected in the **Assign users** section.
130126

131-
> [!div class="mx-imgBorder"]
132-
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-details-users-tab.png" alt-text="The Users tab on the details flyout of the Report Message add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-details-users-tab.png":::
127+
Any existing users or groups are shown in the **Added users** section.
133128

134-
- **Usage** tab: The chart and details table shows the number of active users over time.
135-
- Filter the **Date range** to **7 days**, **30 days** (default), or **90 days**.
136-
- In the **Report** column, select :::image type="icon" source="media/m365-cc-sc-download-icon.png" border="false"::: **Download** to download the information filtered by **Date range** to the file named **UsageData.csv**.
129+
Click in the search box to find and select users or groups. New selections are added to the **To be added** section that appears.
130+
131+
To remove a user or group, select :::image type="icon" source="media/m365-cc-sc-remove-icon.png" border="false"::: on the entry:
132+
133+
- From the **Added users** section: The user or group is added to the **To be removed** section that appears.
134+
- From the **To be added** section: The user or group is removed from this section and won't be added.
135+
- From the **To be removed** section: The user or group is removed from this section and won't be removed.
136+
137+
When you're finished on the **Users** tab of the details flyout, select **Update** to save your changes.
138+
139+
> [!div class="mx-imgBorder"]
140+
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-details-users-tab.png" alt-text="Screenshot of the Users tab on the details flyout of the Report Message add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-details-users-tab.png":::
137141
138-
When you're finished viewing the information on the tabs, select :::image type="icon" source="media/m365-cc-sc-close-icon.png" border="false"::: **Close** to close the details flyout.
142+
After a few moments, the **Updating users completed** flyout appears. Select **Done** to return to the **Users** tab of the add-in details flyout where your updates are shown in the **Added users** section.
143+
144+
Select :::image type="icon" source="media/m365-cc-sc-remove-icon.png" border="false"::: **Close flyout** to return to the **Integrated apps** page.
139145

140146
## Frequently asked questions
141147

defender-xdr/additional-information-xdr.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.custom:
1919
- cx-ti
2020
- cx-dex
2121
search.appverid: met150
22-
ms.date: 10/30/2024
22+
ms.date: 03/05/2025
2323
appliesto:
2424
- Microsoft Defender XDR
2525
---
@@ -34,7 +34,7 @@ To realize the benefits of Microsoft Defender Experts for XDR, you and your secu
3434

3535
- **Engage actively through the readiness assessment process** – The [readiness assessment](get-started-xdr.md#prepare-your-environment-for-the-defender-experts-service) when onboarding for Defender Experts for XDR is an integral part of the offering. Completing it successfully ensures prompt service coverage and protects your organization against known threats.
3636
- **Act on managed responses in a timely manner** – For any suspicious incidents and alerts, our experts provide a detailed investigation summary and managed responses for remediation. We expect your SOC team to act on these managed responses in a timely manner to prevent further impact from any malicious attempts.
37-
- **Configure recommended settings and follow best practices to improve security posture** – As part of our service, your service delivery manager and security analyst team share ongoing recommendations to strengthen your security posture. These recommendations are based on incidents investigated in your organization. Your SOC team should review these recommendations and implement them as soon as possible to protect your organization against future threats.
37+
- **Configure recommended settings and follow best practices to improve security posture** – As part of our service, we will share ongoing recommendations to strengthen your security posture. These recommendations are based on incidents investigated in your organization. Your SOC team should review these recommendations and implement them as soon as possible to protect your organization against future threats.
3838

3939
### Note about incident response
4040

defender-xdr/communicate-defender-experts-xdr.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.collection:
1414
- essentials-manage
1515
ms.topic: conceptual
1616
search.appverid: met150
17-
ms.date: 05/01/2024
17+
ms.date: 03/05/2025
1818
---
1919

2020
# Communicating with experts in the Microsoft Defender Experts for XDR service
@@ -23,7 +23,7 @@ ms.date: 05/01/2024
2323

2424
- [Microsoft Defender XDR](microsoft-365-defender.md)
2525

26-
Microsoft Defender Experts for XDR provides you with multiple channels of communication to discuss incidents with our experts, ask them questions on demand, or get service readiness or operations support from your service delivery managers (SDMs).
26+
Microsoft Defender Experts for XDR provides you with multiple channels of communication to discuss incidents with our experts, ask them questions on demand, or get service readiness or operations support from your service delivery managers (SDMs), if included in your service.
2727

2828
## Incident and managed response notifications
2929

@@ -79,6 +79,9 @@ While the previous scenarios involve our experts initiating communication with y
7979

8080
The service delivery manager (SDM) is responsible for managing the overall relationship for your organization with the Defender Experts for XDR service. They are your trusted advisor working along with XDR experts' team to help you protect your organization.
8181

82+
> [!NOTE]
83+
> Service delivery managers are included if your Defender Experts for XDR service is licensed for 500 or more seats.
84+
8285
The SDM provides the following services:
8386

8487
- Service readiness support

defender-xdr/dex-xdr-overview.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 02/05/2025
20+
ms.date: 03/05/2025
2121
---
2222

2323
# Microsoft Defender Experts for XDR
@@ -40,18 +40,22 @@ Defender Experts for XDR augments your SOC by combining automation and Microsoft
4040
- **Access expertise when you need it** - Extend your team's capacity with access to Defender Experts for assistance on an investigation
4141
- **Stay ahead of emerging threats** - Our experts proactively hunt for emerging threats in your environment, informed by unparalleled threat intelligence and visibility
4242

43-
Apart from the constantly updated research and intelligence tailored for the threats currently seen across the various Microsoft Defender XDR signals, you also receive managed response from our security analysts and support from Microsoft's security-focused service delivery managers (SDMs). This service lets you enjoy the following capabilities:
43+
Apart from the constantly updated research and intelligence tailored for the threats currently seen across the various Microsoft Defender XDR signals, you also receive managed response from our security analysts and, if your service includes it, support from Microsoft's security-focused service delivery managers (SDMs)*. This service lets you enjoy the following capabilities:
4444

4545
- **Managed detection and response** - Expert analysts manage your Microsoft Defender XDR incident queue and handle triage and investigation on your behalf; they partner with you and your team to take action or guide you to respond to incidents
4646
- **Proactive threat hunting** - [Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md) is built in to extend your team's threat hunting capabilities and prioritize significant threats
4747
- **Ask Defender Experts** - Select [Ask Defender Experts](experts-on-demand.md) in the Microsoft Defender portal to get expert advice about threats your organization is facing. You can ask for help on a specific incident, nation-state actor, or attack vector-related notifications
4848
- **Live dashboards and reports** - Transparent view of our operations on your behalf and noise free, actionable view into what matters for you coupled with detailed analytics
4949
- **Proactive check-ins for continuous security improvements** - Periodic check-ins with your named service delivery team to guide your Defender Experts for XDR experience and improve your security posture
5050

51+
> [!NOTE]
52+
> Service delivery managers are included if your Defender Experts for XDR service is licensed for 500 or more seats.
53+
5154
[Read the Defender Experts for XDR ebook](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Defender-Experts-for-XDR-eBook-Final.pdf) and maximize the benefits of this product suite.
5255

5356
### Next step
5457

5558
[Before you begin](before-you-begin-xdr.md)
5659

5760
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]
61+

0 commit comments

Comments
 (0)