Skip to content

Commit 36b0035

Browse files
authored
Merge pull request #1279 from MicrosoftDocs/vivek-eod-9sept
OOB publish- Sept 5- 9AM PST
2 parents 36f9555 + 869d881 commit 36b0035

File tree

4 files changed

+30
-8
lines changed

4 files changed

+30
-8
lines changed

defender-xdr/experts-on-demand.md

Lines changed: 30 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.collection:
1919
- essentials-get-started
2020
ms.topic: conceptual
2121
search.appverid: met150
22-
ms.date: 08/14/2024
22+
ms.date: 09/05/2024
2323
---
2424

2525
# Collaborate with experts on demand
@@ -31,24 +31,29 @@ ms.date: 08/14/2024
3131
- [Microsoft Defender XDR](microsoft-365-defender.md)
3232

3333
> [!NOTE]
34-
> Ask Defender Experts is included in your Defender Experts for Hunting subscription with [monthly allocations](before-you-begin-defender-experts.md#eligibility-and-licensing). However, it's not a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
34+
> Ask Defender Experts is included in your Defender Experts for Hunting subscription with [quarterly allocations](before-you-begin-defender-experts.md#eligibility-and-licensing). However, it's not a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
3535
3636
Select **Ask Defender Experts** directly inside the Microsoft 365 security portal to get swift and accurate responses to all your threat hunting questions. Experts can provide insight to better understand the complex threats your organization might face. Ask Defender Experts can help:
3737

3838
- Gather additional information on alerts and incidents, including root causes and scope
3939
- Gain clarity into suspicious devices, alerts, or incidents and take next steps if faced with an advanced attacker
4040
- Determine risks and available protections related to threat actors, campaigns, or emerging attacker techniques
4141

42-
### Required permissions for submitting inquiries in the Ask Defender Experts panel
42+
:::image type="content" source="media/ask-defender-expert-dialog.png" alt-text="Screenshot of the Ask Defender Experts dialog box." lightbox="media/ask-defender-expert-dialog.png":::
4343

44-
You need to select one of the following permissions before submitting inquires to our Defender experts. For more details about role-based access control (RBAC) permissions, see: [Microsoft Defender for Endpoint and Microsoft Defender XDR RBAC permissions](compare-rbac-roles.md#map-defender-for-endpoint-and-defender-vulnerability-management-permissions-to-the-microsoft-defender-xdr-rbac-permissions).
44+
### Required permissions for using Ask Defender Experts
4545

46-
|Product name|Product RBAC permission|
46+
You need to select one of the following Microsoft Defender XDR Unified RBAC permissions before submitting inquiries to our Defender experts.
47+
48+
|Permission name|Level|
4749
|---|---|---|
48-
| Microsoft Defender for Endpoint RBAC | Manage security settings in the Security Center|
49-
| Microsoft Defender XDR Unified RBAC | Authorization and settings \ Security settings \ Core security settings (manage)</br>Authorization and settings \ Security settings \ Detection tuning (manage) |
50+
| Security data basics | Read|
51+
| Alerts | Manage |
52+
| Response | Manage |
53+
54+
To learn more about Unified RBAC permissions, see: [Microsoft Defender XDR Unified RBAC permission details](custom-permissions-details.md#microsoft-defender-xdr-unified-rbac-permission-details).
5055

51-
### Where to find Ask Defender Experts
56+
### Where to submit inquiries to Ask Defender Experts
5257

5358
The option to **Ask Defender Experts** is available in several places throughout the portal:
5459

@@ -68,6 +73,23 @@ The option to **Ask Defender Experts** is available in several places throughout
6873

6974
:::image type="content" source="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png" alt-text="Screenshot of the Ask Defender Experts menu option in the Incidents page actions menu in the Microsoft Defender portal.." lightbox="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png":::
7075

76+
### Where to view responses from Defender Experts
77+
78+
#### In portal
79+
80+
You can view responses to inquiries submitted to Ask Defender Experts from up to six months ago by navigating to **Reports** > **Defender Experts messages**. You will also be able to ask follow-up questions or reply with more information to Defender Experts from this page.
81+
82+
:::image type="content" source="media/inportal-managed-response.png" alt-text="Screenshot of in-portal managed response." lightbox="media/inportal-managed-response.png":::
83+
84+
#### Email
85+
86+
If you included contact email addresses when submitting your inquiry, they will receive an email notification when a response from Defender Experts is posted.
87+
88+
:::image type="content" source="media/email-based-managed-response.png" alt-text="Screenshot of email based managed response." lightbox="media/email-based-managed-response.png":::
89+
90+
> [!NOTE]
91+
> Defender Experts will not be able to assist you with inquiries regarding bugs or issues in your product experience in the Microsoft Defender XDR portal. You can reach out to Microsoft Support via the [Services Hub](https://serviceshub.microsoft.com/home) regarding such inquiries.
92+
7193
### Sample questions you can ask from Defender Experts
7294

7395
#### Alert information
574 KB
Loading
40.4 KB
Loading
377 KB
Loading

0 commit comments

Comments
 (0)