You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
-[Microsoft Defender for Endpoint](/defender-endpoint/microsoft-defender-endpoint)
28
+
29
+
-[Microsoft Defender Vulnerability Management](/defender-vulnerability-management/defender-vulnerability-management-capabilities#vulnerability-management-capabilities-for-endpoints) (add-on for Defender for Endpoint Plan 2 or the standalone version)
30
+
-[Microsoft Defender for Cloud Plan 2](/azure/defender-for-cloud/defender-for-cloud-introduction)
31
31
32
32
> Want to experience Microsoft Defender for Endpoint? [Sign up for a free trial.](https://go.microsoft.com/fwlink/p/?linkid=2225630&clcid=0x409&culture=en-us&country=us).
Copy file name to clipboardExpand all lines: defender-office-365/submissions-users-report-message-add-in-configure.md
+47-41Lines changed: 47 additions & 41 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ manager: deniseb
8
8
audience: Admin
9
9
ms.reviewer: dhagarwal
10
10
ms.topic: how-to
11
-
ms.date: 02/24/2025
11
+
ms.date: 03/05/2025
12
12
ms.localizationpriority: medium
13
13
search.appverid:
14
14
- MET150
@@ -75,67 +75,73 @@ The rest of this article describes how to remove the Report Message and Report P
75
75
## Remove the Report Message or Report Phishing add-ins
76
76
77
77
> [!TIP]
78
-
> It might take up to 24 hours for the add-in to disappear from your organization.
79
-
>
80
78
> If you delete the app registration for the add-in in Microsoft Entra ID, the add-in is also deleted from the organization.
81
79
82
80
1. In the Microsoft 365 admin center at <https://admin.microsoft.com>, expand **Show all** if necessary, and then go to **Settings**\>**Integrated apps**. Or, to go directly to the **Integrated apps** page, use <https://admin.microsoft.com/Adminportal/Home#/Settings/IntegratedApps>.
83
81
84
82
> [!TIP]
85
-
> Admins in Microsoft 365 Government Community Cloud (GCC) or GCC High or DoD need to use the Microsoft 365 admin center at https://portal.office365.us/adminportal/home#/Settings/AddIns and than select Settings > Add-ins
83
+
> Admins in Microsoft 365 Government Community Cloud (GCC), GCC High, or DoD need to use the Microsoft 365 admin center at <https://portal.office365.us/adminportal/home#/Settings/AddIns> and then select **Settings**\>**Add-ins**.
86
84
>
87
-
> Although the screenshots in the remaining steps show the **Report Phishing** add-in, the steps are identical for the **Report Message** add-in.
85
+
> Although the screenshots in the following steps show the **Report Phishing** add-in, the steps are identical for the **Report Message** add-in.
88
86
89
-
2. On the **Deployed apps** tab of the **Integrated apps** page, select the **Report Message** add-in or the **Report Phishing** add-in by doing one of the following steps:
87
+
2. On the **Deployed apps** tab of the **Integrated apps** page, select the **Report Message** add-in or the **Report Phishing** add-in by clicking anywhere in the row.
88
+
89
+
> [!div class="mx-imgBorder"]
90
+
> :::image type="content" source="media/microsoft-365-admin-center-select-report-phish-add-in.png" alt-text="Screenshot of selecting the Report Phishing add-in on the Integrated apps page in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-select-report-phish-add-in.png":::
90
91
91
-
- In the **Name** column, select the icon or text for the add-in. This selection takes you to the **Overview** tab in the details flyout as described in the next steps.
92
-
- In the **Name** column, select **⋮****Edit row**, and then select :::image type="icon" source="media/m365-cc-sc-add-internal-icon.png" border="false"::: **Edit users** to go to the **Users** tab in the details flyout as described in the next step.
93
-
- In the **Name** column, select **⋮****Edit row**, and then select :::image type="icon" source="media/m365-cc-sc-show-trends-icon.png" border="false"::: **Check usage data** to go to the **Usage** tab in the details flyout as described in the next step.
92
+
3. On the **Overview** tab of the details flyout that opens, select **Remove app** from the **Actions** section.
94
93
95
94
> [!div class="mx-imgBorder"]
96
-
> :::image type="content" source="media/microsoft-365-admin-center-select-report-phish-add-in.png" alt-text="Select the Report Phishing add-in on the Integrated apps page in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-select-report-phish-add-in.png":::
95
+
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-details-overview-tab.png" alt-text="Screenshot of the Overview tab on the details flyout of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-details-overview-tab.png":::
97
96
98
-
3. The details flyout that opens contains the following tabs:
97
+
4. In the **Remove apps** confirmation flyout that opens, select **Yes, I'm sure I want to remove the app and associated data**, and then select **Remove**.
98
+
99
+
> [!div class="mx-imgBorder"]
100
+
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-remove-overview-tab.png" alt-text="Screenshot of the tab on the removal flyout of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-remove-overview-tab.png":::
99
101
100
-
-**Overview** tab:
101
-
-**Basic info** section:
102
-
-**Status**
103
-
-**Type**: Add-in
104
-
-**Test deployment**: **Yes** or **No**, depending on the option you selected when you or the selection you change on the **Users** tab.
105
-
-**Description**
106
-
-**Host product**: Outlook
107
-
-**Actions** section: Select **Remove app** to remove the app.
108
-
-**Assigned users** section: Select **Edit users** to go to the **Users** tab. Use this setting to limit the users who have the add-in.
109
-
-**Usage** section: Select **Check usage data** to got to the **Usage** tab.
102
+
5. After a few moments, **Successfully removed** flyout appears. It might take up to 24 hours for the add-in to disappear from your organization.
110
103
111
-
> [!div class="mx-imgBorder"]
112
-
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-details-overview-tab.png" alt-text="The Overview tab on the details flyout of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-details-overview-tab.png":::
104
+
> [!div class="mx-imgBorder"]
105
+
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-addin-remove-complete-tab.png" alt-text="Screenshot of the flyout showing the removal of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-addin-remove-complete-tab.png":::
113
106
114
-
> [!div class="mx-imgBorder"]
115
-
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-remove-overview-tab.png" alt-text="The tab on the removal flyout of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-remove-overview-tab.png":::
107
+
Select **Done** to return to the **Integrated apps** page where the add-in is no longer listed.
116
108
117
-
> [!div class="mx-imgBorder"]
118
-
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-addin-remove-complete-tab.png" alt-text="The flyout showcasing the removal of the Report Phishing add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-addin-remove-complete-tab.png":::
109
+
## Scope the Report Message or Report Phishing add-ins to a set of users
119
110
120
-
-**Users** tab:
121
-
-**Is this a test deployment?**: Leave the toggle at :::image type="icon" source="media/scc-toggle-off.png" border="false"::: **No**, or set the toggle to :::image type="icon" source="media/scc-toggle-on.png" border="false"::: **Yes**.
122
-
-**Assign users** section: Select one of the following values:
123
-
-**Just me**
124
-
-**Entire organization**
125
-
-**Specific users/groups**: Find and select users and groups in the search box. After each selection, the user or group appears in the **Added users** section that appears below the search box. To remove a selection, select :::image type="icon" source="media/m365-cc-sc-remove-icon.png" border="false"::: on the entry.
111
+
1. In the Microsoft 365 admin center at <https://admin.microsoft.com>, expand **Show all** if necessary, and then go to **Settings**\>**Integrated apps**. Or, to go directly to the **Integrated apps** page, use <https://admin.microsoft.com/Adminportal/Home#/Settings/IntegratedApps>.
126
112
127
-
-**Email notification** section: **Send email notification to assigned users** and **View email sample** aren't selectable.
113
+
> [!TIP]
114
+
> Admins in Microsoft 365 Government Community Cloud (GCC), GCC High, or DoD need to use the Microsoft 365 admin center at <https://portal.office365.us/adminportal/home#/Settings/AddIns> and then select **Settings**\>**Add-ins**.
115
+
>
116
+
> Although the screenshots in the following steps show the **Report Phishing** add-in, the steps are identical for the **Report Message** add-in.
128
117
129
-
If you made any updates on this tab, select **Update** to save your changes.
118
+
2. On the **Deployed apps** tab of the **Integrated apps** page, select the **Report Message** add-in or the **Report Phishing** add-in by doing one of the following steps:
119
+
- Select the add-in by clicking anywhere in the row. In the details flyout that opens, select the **Users** tab.
120
+
- In the **Name** column, select **⋮**\>**Edit users**.
121
+
122
+
> [!div class="mx-imgBorder"]
123
+
> :::image type="content" source="media/microsoft-365-admin-center-select-report-phish-add-in.png" alt-text="Screenshot of selecting the Report Phishing add-in on the Integrated apps page in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-select-report-phish-add-in.png":::
124
+
125
+
3. On the **Users** tab of the details flyout, verify **Specific users/groups** is selected in the **Assign users** section.
130
126
131
-
> [!div class="mx-imgBorder"]
132
-
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-details-users-tab.png" alt-text="The Users tab on the details flyout of the Report Message add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-details-users-tab.png":::
127
+
Any existing users or groups are shown in the **Added users** section.
133
128
134
-
-**Usage** tab: The chart and details table shows the number of active users over time.
135
-
- Filter the **Date range** to **7 days**, **30 days** (default), or **90 days**.
136
-
- In the **Report** column, select :::image type="icon" source="media/m365-cc-sc-download-icon.png" border="false"::: **Download** to download the information filtered by **Date range** to the file named **UsageData.csv**.
129
+
Click in the search box to find and select users or groups. New selections are added to the **To be added** section that appears.
130
+
131
+
To remove a user or group, select :::image type="icon" source="media/m365-cc-sc-remove-icon.png" border="false"::: on the entry:
132
+
133
+
- From the **Added users** section: The user or group is added to the **To be removed** section that appears.
134
+
- From the **To be added** section: The user or group is removed from this section and won't be added.
135
+
- From the **To be removed** section: The user or group is removed from this section and won't be removed.
136
+
137
+
When you're finished on the **Users** tab of the details flyout, select **Update** to save your changes.
138
+
139
+
> [!div class="mx-imgBorder"]
140
+
> :::image type="content" source="media/microsoft-365-admin-center-report-phish-add-in-details-users-tab.png" alt-text="Screenshot of the Users tab on the details flyout of the Report Message add-in in the Microsoft 365 admin center." lightbox="media/microsoft-365-admin-center-report-phish-add-in-details-users-tab.png":::
137
141
138
-
When you're finished viewing the information on the tabs, select :::image type="icon" source="media/m365-cc-sc-close-icon.png" border="false"::: **Close** to close the details flyout.
142
+
After a few moments, the **Updating users completed** flyout appears. Select **Done** to return to the **Users** tab of the add-in details flyout where your updates are shown in the **Added users** section.
143
+
144
+
Select :::image type="icon" source="media/m365-cc-sc-remove-icon.png" border="false"::: **Close flyout** to return to the **Integrated apps** page.
Copy file name to clipboardExpand all lines: defender-xdr/additional-information-xdr.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,7 +19,7 @@ ms.custom:
19
19
- cx-ti
20
20
- cx-dex
21
21
search.appverid: met150
22
-
ms.date: 10/30/2024
22
+
ms.date: 03/05/2025
23
23
appliesto:
24
24
- Microsoft Defender XDR
25
25
---
@@ -34,7 +34,7 @@ To realize the benefits of Microsoft Defender Experts for XDR, you and your secu
34
34
35
35
-**Engage actively through the readiness assessment process** – The [readiness assessment](get-started-xdr.md#prepare-your-environment-for-the-defender-experts-service) when onboarding for Defender Experts for XDR is an integral part of the offering. Completing it successfully ensures prompt service coverage and protects your organization against known threats.
36
36
-**Act on managed responses in a timely manner** – For any suspicious incidents and alerts, our experts provide a detailed investigation summary and managed responses for remediation. We expect your SOC team to act on these managed responses in a timely manner to prevent further impact from any malicious attempts.
37
-
-**Configure recommended settings and follow best practices to improve security posture** – As part of our service, your service delivery manager and security analyst team share ongoing recommendations to strengthen your security posture. These recommendations are based on incidents investigated in your organization. Your SOC team should review these recommendations and implement them as soon as possible to protect your organization against future threats.
37
+
-**Configure recommended settings and follow best practices to improve security posture** – As part of our service, we will share ongoing recommendations to strengthen your security posture. These recommendations are based on incidents investigated in your organization. Your SOC team should review these recommendations and implement them as soon as possible to protect your organization against future threats.
Microsoft Defender Experts for XDR provides you with multiple channels of communication to discuss incidents with our experts, ask them questions on demand, or get service readiness or operations support from your service delivery managers (SDMs).
26
+
Microsoft Defender Experts for XDR provides you with multiple channels of communication to discuss incidents with our experts, ask them questions on demand, or get service readiness or operations support from your service delivery managers (SDMs), if included in your service.
27
27
28
28
## Incident and managed response notifications
29
29
@@ -79,6 +79,9 @@ While the previous scenarios involve our experts initiating communication with y
79
79
80
80
The service delivery manager (SDM) is responsible for managing the overall relationship for your organization with the Defender Experts for XDR service. They are your trusted advisor working along with XDR experts' team to help you protect your organization.
81
81
82
+
> [!NOTE]
83
+
> Service delivery managers are included if your Defender Experts for XDR service is licensed for 500 or more seats.
Copy file name to clipboardExpand all lines: defender-xdr/dex-xdr-overview.md
+6-2Lines changed: 6 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -17,7 +17,7 @@ ms.custom:
17
17
- cx-ti
18
18
- cx-dex
19
19
search.appverid: met150
20
-
ms.date: 02/05/2025
20
+
ms.date: 03/05/2025
21
21
---
22
22
23
23
# Microsoft Defender Experts for XDR
@@ -40,18 +40,22 @@ Defender Experts for XDR augments your SOC by combining automation and Microsoft
40
40
-**Access expertise when you need it** - Extend your team's capacity with access to Defender Experts for assistance on an investigation
41
41
-**Stay ahead of emerging threats** - Our experts proactively hunt for emerging threats in your environment, informed by unparalleled threat intelligence and visibility
42
42
43
-
Apart from the constantly updated research and intelligence tailored for the threats currently seen across the various Microsoft Defender XDR signals, you also receive managed response from our security analysts andsupport from Microsoft's security-focused service delivery managers (SDMs). This service lets you enjoy the following capabilities:
43
+
Apart from the constantly updated research and intelligence tailored for the threats currently seen across the various Microsoft Defender XDR signals, you also receive managed response from our security analysts and, if your service includes it, support from Microsoft's security-focused service delivery managers (SDMs)*. This service lets you enjoy the following capabilities:
44
44
45
45
-**Managed detection and response** - Expert analysts manage your Microsoft Defender XDR incident queue and handle triage and investigation on your behalf; they partner with you and your team to take action or guide you to respond to incidents
46
46
-**Proactive threat hunting** - [Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md) is built in to extend your team's threat hunting capabilities and prioritize significant threats
47
47
-**Ask Defender Experts** - Select [Ask Defender Experts](experts-on-demand.md) in the Microsoft Defender portal to get expert advice about threats your organization is facing. You can ask for help on a specific incident, nation-state actor, or attack vector-related notifications
48
48
-**Live dashboards and reports** - Transparent view of our operations on your behalf and noise free, actionable view into what matters for you coupled with detailed analytics
49
49
-**Proactive check-ins for continuous security improvements** - Periodic check-ins with your named service delivery team to guide your Defender Experts for XDR experience and improve your security posture
50
50
51
+
> [!NOTE]
52
+
> Service delivery managers are included if your Defender Experts for XDR service is licensed for 500 or more seats.
53
+
51
54
[Read the Defender Experts for XDR ebook](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Defender-Experts-for-XDR-eBook-Final.pdf) and maximize the benefits of this product suite.
0 commit comments