Skip to content

Commit 39fe800

Browse files
Merge pull request #2558 from MicrosoftDocs/main
Publish main to live, 01/27/25, 10:30 AM PT
2 parents 0464d05 + bced233 commit 39fe800

10 files changed

+45
-55
lines changed

CloudAppSecurityDocs/mde-integration.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -65,13 +65,12 @@ To enable Defender for Endpoint integration with Defender for Cloud Apps:
6565

6666
1. In the [Microsoft Defender portal](https://security.microsoft.com), from the navigation pane, select **Settings** > **Endpoints** > **General** > **Advanced features**.
6767
1. Toggle the **Microsoft Defender for Cloud Apps** to **On**.
68-
1. Select **Apply**.
68+
1. Select **Save preferences**.
6969

7070
>[!NOTE]
7171
> It takes up to two hours after you enable the integration for the data to show up in Defender for Cloud Apps.
7272
>
73-
74-
![Screenshot of the Defender for Endpoint settings.](media/mde-settings.png)
73+
![Screenshot of the Defender for Endpoint settings.](media\turn-on-advanced-features-for-microsoft-defender-for-cloud-apps.png)
7574

7675
To configure the severity for alerts sent to Microsoft Defender for Endpoint:
7776

-100 KB
Binary file not shown.
174 KB
Loading

defender-xdr/auditing.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 10/30/2024
20+
ms.date: 01/14/2025
2121
---
2222

2323
# Auditing
@@ -28,7 +28,7 @@ ms.date: 10/30/2024
2828

2929
As a tenant administrator, you can use Microsoft Purview to search the audit logs for the times Microsoft Defender Experts signed into your tenant and the actions they did there to perform their investigations. You can also search the audit logs for the changes done by your tenant administrators to the Defender Experts settings.
3030

31-
[Audit (Standard)](/microsoft-365/compliance/audit-solutions-overview) is turned on by default for all Microsoft Defender Experts for XDR customers when paid licenses are assigned to the tenant. If you have a trial license, work with your service delivery manager to turn on Audit if it isn't yet.
31+
Auditing is automatically turned on in the Microsoft Defender portal. Features that are audited are logged in the audit log automatically. Auditing can also collect audit logs from GCC environments.
3232

3333
> [!NOTE]
3434
> Make sure you have the right [permissions](/microsoft-365/compliance/audit-log-search#before-you-search-the-audit-log) to search for audit logs.

defender-xdr/microsoft-365-defender-portal.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,7 @@ To learn more about the services that are part of the Microsoft Defender portal,
3838
- **[Microsoft Security Copilot embedded experience in the Microsoft Defender portal](security-copilot-in-microsoft-365-defender.md)**
3939
- **[Microsoft Defender for IoT enterprise monitoring in the Microsoft Defender portal](/azure/defender-for-iot/organizations/eiot-defender-for-endpoint)**
4040
- **[Microsoft Sentinel in the Microsoft Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal)**
41+
- **[Microsoft Purview Insider Risk Management alerts in the Microsoft Defender portal](irm-investigate-alerts-defender.md)**
4142

4243
[!INCLUDE [unified-soc-preview](../includes/unified-soc-preview.md)]
4344

defender-xdr/microsoft-365-defender.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,7 @@ Microsoft Defender XDR helps security teams protect and detect their organizatio
4040
- [**Microsoft Entra ID Protection**](/azure/active-directory/identity-protection/overview-identity-protection)
4141
- [**Microsoft Data Loss Prevention**](/microsoft-365/compliance/dlp-learn-about-dlp)
4242
- [**App Governance**](/defender-cloud-apps/app-governance-manage-app-governance)
43+
- [**Microsoft Purview Insider Risk Management**](/purview/insider-risk-management-solution-overview)
4344

4445
With the integrated Microsoft Defender XDR solution, security professionals can stitch together the threat signals that each of these products receive and determine the full scope and impact of the threat; how it entered the environment, what it's affected, and how it's currently impacting the organization. Microsoft Defender XDR takes automatic action to prevent or stop the attack and self-heal affected mailboxes, endpoints, and user identities.
4546

defender-xdr/microsoft-xdr-auditing.md

Lines changed: 22 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Search the audit log for events in Microsoft Defender XDR
3-
description: Learn about the Microsoft Defender XDR activities that are logged in the Microsoft 365 audit log.
3+
description: Learn how to use the audit log to search for Microsoft Defender XDR activities to help with investigation.
44
ms.service: defender-xdr
55
ms.author: diannegali
66
author: diannegali
@@ -10,21 +10,21 @@ audience: ITPro
1010
ms.collection:
1111
- m365-security
1212
- tier3
13-
ms.topic: overview
14-
ms.date: 08/14/2024
13+
ms.topic: how-to
14+
ms.date: 01/14/2025
1515
search.appverid: met150
16+
appliesto:
17+
- Microsoft Defender for Endpoint Plan 2
18+
- Microsoft Defender XDR
19+
20+
#customer intent: As a SOC analyst, I want to learn how to use the audit log to search for Microsoft Defender XDR activities to help with investigation.
1621
---
1722

1823
# Search the audit log for events in Microsoft Defender XDR
1924

2025
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2126

22-
**Applies to:**
23-
24-
- [Microsoft Defender for Endpoint Plan 2](/defender-endpoint/microsoft-defender-endpoint)
25-
- [Microsoft Defender XDR](microsoft-365-defender.md)
26-
27-
The audit log can help you investigate specific activities across Microsoft 365 services. In the Microsoft Defender portal, Microsoft Defender XDR and Microsoft Defender for Endpoint activities are audited. Some of the activities audited are:
27+
The audit log helps you investigate specific activities across Microsoft 365 services. In the Microsoft Defender portal, Microsoft Defender XDR and Microsoft Defender for Endpoint activities are audited. Some of the activities audited are:
2828

2929
- Changes to data retention settings
3030
- Changes to advanced features
@@ -36,33 +36,25 @@ The audit log can help you investigate specific activities across Microsoft 365
3636

3737
For a complete list of Microsoft Defender XDR activities that are audited, see [Microsoft Defender XDR activities](#microsoft-defender-xdr-activities) and [Microsoft Defender for Endpoint activities](#microsoft-defender-for-endpoint-activities).
3838

39-
## Requirements
39+
Auditing is automatically turned on for Microsoft Defender XDR. Features that are audited are logged in the audit log automatically. Auditing can also collect audit logs from GCC environments.
40+
41+
## Prerequisites
4042

4143
To access the audit log, you need to have the **View-Only Audit Logs** or **Audit Logs** role in Exchange Online. By default, those roles are assigned to the Compliance Management and Organization Management role groups.
4244

4345
> [!NOTE]
4446
> Global administrators in Office 365 and Microsoft 365 are automatically added as members of the Organization Management role group in Exchange Online.
4547
46-
## Turn on auditing in Microsoft Defender XDR
47-
48-
Microsoft Defender XDR uses the [Microsoft Purview auditing solution](/purview/audit-solutions-overview), before you can look at the audit data in the Microsoft Defender XDR portal:
49-
50-
- You should confirm that auditing is turned on in the Microsoft Purview compliance portal. For more information, see [Turn auditing on or off](/purview/audit-log-enable-disable).
51-
52-
- Follow the steps below to enable the unified audit log in the Microsoft Defender XDR portal:
53-
1. Log in to [Microsoft Defender XDR](https://security.microsoft.com/homepage) using an account with the Security administrator or Global administrator role assigned.
54-
2. In the navigation pane, select **Settings** \> **Endpoints** \> **Advanced features**.
55-
3. Scroll own to **Unified audit log** and toggle the setting to **On**.
56-
57-
:::image type="content" source="/defender/media/defender/unified-audit-log.png" alt-text="Screenshot of the unified audit log toggle in Microsoft Defender XDR advanced settings" lightbox="/defender/media/defender/unified-audit-log.png":::
58-
4. Select **Save preferences**.
48+
Microsoft Defender XDR uses the [Microsoft Purview auditing solution](/purview/audit-solutions-overview). Before you can look at the audit data in the Microsoft Defender portal, you need to turn on auditing in the Microsoft Purview compliance portal. For more information, see [Turn auditing on or off](/purview/audit-log-enable-disable).
5949

6050
> [!IMPORTANT]
61-
> Global Administrator is a highly privileged role that should be limited to scenarios when you can't use an existing role. Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization.
51+
> Global Administrator is a highly privileged role that should be limited to scenarios when you can't use an existing role. Microsoft recommends that you use roles with the fewest permissions. Using accounts with lower permissions helps improve security for your organization.
6252
63-
## Using the audit search in Microsoft Defender XDR
53+
## Search the audit log
6454

65-
1. To retrieve audit logs for Microsoft Defender XDR activities, navigate to the [Microsoft Defender XDR Audit page](https://security.microsoft.com/auditlogsearch) or go to the [Purview compliance portal](https://compliance.microsoft.com) and select **Audit**.
55+
Follow these steps to search the audit log:
56+
57+
1. Navigate to the [Microsoft Defender portal's Audit page](https://security.microsoft.com/auditlogsearch) or go to the [Purview compliance portal](https://compliance.microsoft.com) and select **Audit**.
6658

6759
:::image type="content" source="/defender/media/defender/unified-audit-log-xdr.png" alt-text="Screenshot of the unified audit log page in Microsoft Defender XDR " lightbox="/defender/media/defender/unified-audit-log-xdr.png":::
6860

@@ -94,7 +86,7 @@ For a list of all events that are logged for user and admin activities in Micros
9486
- [Response action activities in Defender for Endpoint in the audit log](/purview/audit-log-activities#microsoft-defender-for-endpoint-reponse-actions-activities)
9587
- [Roles settings activities in Defender for Endpoint in the audit log](/purview/audit-log-activities#microsoft-defender-for-endpoint-roles-settings-activities)
9688

97-
## Using a PowerShell script
89+
## Search for events using a PowerShell script
9890

9991
You can use the following PowerShell code snippet to query the Office 365 Management API to retrieve information about Microsoft Defender XDR events:
10092

@@ -108,10 +100,10 @@ Search-UnifiedAuditLog -StartDate 2023/03/12 -EndDate 2023/03/20 -RecordType <ID
108100
>[!NOTE]
109101
> See the API column in Audit activities included for the record type values.
110102
111-
## Additional resources
103+
For more information, see [Use a PowerShell script to search the audit log](/purview/audit-log-search-script)
104+
105+
## See also
112106

113-
- [Search the audit log in the compliance center](/purview/audit-new-search)
114-
- [Use a PowerShell script to search the audit log](/purview/audit-log-search-script)
115107
- [Detailed properties in the audit log](/purview/audit-log-detailed-properties)
116108
- [Export, configure, and view audit log records](/purview/audit-log-export-records)
117109
- [Office 365 Management Activity API reference](/office/office-365-management-api/office-365-management-activity-api-reference)

defender-xdr/mto-overview.md

Lines changed: 9 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -8,17 +8,17 @@ ms.localizationpriority: medium
88
manager: dansimp
99
audience: ITPro
1010
ms.collection:
11-
- m365-security
12-
- highpri
13-
- tier1
14-
- usx-security
11+
- m365-security
12+
- highpri
13+
- tier1
14+
- usx-security
1515
ms.topic: conceptual
16-
ms.date: 09/30/2024
16+
ms.date: 01/27/2025
1717
appliesto:
18-
- Microsoft Defender XDR
19-
- Microsoft Sentinel in the Microsoft Defender portal
20-
- Microsoft Defender for Endpoint Plan 2
21-
- Microsoft Defender for Office 365 P2
18+
- Microsoft Defender XDR
19+
- Microsoft Sentinel in the Microsoft Defender portal
20+
- Microsoft Defender for Endpoint Plan 2
21+
- Microsoft Defender for Office 365 P2
2222
---
2323

2424
# Microsoft Defender multitenant management
@@ -71,9 +71,6 @@ The following key capabilities are available for each tenant you have access to
7171
|**Endpoints** > **Vulnerability management** > **Tenants** |For all tenants and at a tenant-specific level, explore vulnerability management information across different values such as exposed devices, security recommendations, weaknesses, and critical CVEs. |
7272
|**Configuration** > **Settings**|Lists the tenants you have access to. Use this page to view and manage your tenants.|
7373

74-
> [!NOTE]
75-
> The content distribution capability is not yet available for all GCC, GCC High, and DoD customers.
76-
7774
## Next steps
7875

7976
- [Set up Microsoft Defender multitenant management](mto-requirements.md)

defender-xdr/portals.md

Lines changed: 6 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Find the right Microsoft admin center or portal for managing variou
44
ms.service: defender-xdr
55
ms.localizationpriority: medium
66
f1.keywords:
7-
- NOCSH
7+
- NOCSH
88
ms.author: dansimp
99
author: dansimp
1010
manager: dansimp
@@ -14,14 +14,14 @@ ms.collection:
1414
- tier3
1515
ms.topic: conceptual
1616
search.appverid: met150
17-
ms.date: 04/03/2024
17+
ms.date: 01/27/2025
1818
---
1919

2020
# Microsoft security portals and admin centers
2121

2222
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2323

24-
While [Microsoft Defender portal](microsoft-365-defender-portal.md) is the new home for monitoring and managing security across your identities, data, devices, and apps, you need to access various portals for certain specialized tasks.
24+
While [Microsoft Defender portal](microsoft-365-defender-portal.md) is the home for monitoring and managing security across your identities, data, devices, and apps, you need to access various portals for certain specialized tasks.
2525

2626
> [!TIP]
2727
> To access various relevant portals from Microsoft Defender portal, select **More resources** in the navigation pane.
@@ -33,8 +33,6 @@ Security operators and admins can go to the following portals to manage security
3333
| Portal name | Description | Link |
3434
|---|---|---|
3535
| Microsoft Defender portal | Monitor and respond to threat activity and strengthen security posture across your identities, email, data, endpoints, and apps with [Microsoft Defender XDR](microsoft-365-defender.md) | [security.microsoft.com](https://security.microsoft.com/) <br/><br/>The Microsoft Defender portal is where you view and manage alerts, incidents, settings, and more. |
36-
| Microsoft Defender Security Center | Monitor and respond to threat activity on your endpoints using capabilities provided with [Microsoft Defender for Endpoint](/defender-endpoint/microsoft-defender-endpoint). Most tenants should now be redirected to the Microsoft Defender portal at [security.microsoft.com](https://security.microsoft.com/). | [securitycenter.windows.com](https://securitycenter.windows.com) |
37-
| Office 365 Security & Compliance Center | Manage [Exchange Online Protection](/defender-office-365/eop-about) and [Microsoft Defender for Office 365](/defender-office-365/mdo-about) to protect your email and collaboration services, and ensure compliance to various data-handling regulations. Most tenants using the security sections of the Office 365 Security & Compliance Center should now be redirected to the Microsoft Defender portal at [security.microsoft.com](https://security.microsoft.com/). | [protection.office.com](https://protection.office.com) |
3836
| Defender for Cloud portal | Use [Microsoft Defender for Cloud](/azure/security-center/security-center-intro) to strengthen the security posture of your data centers and your hybrid workloads in the cloud | [portal.azure.com/#blade/Microsoft_Azure_Security](https://portal.azure.com/#blade/Microsoft_Azure_Security/SecurityMenuBlade/0) |
3937
| Microsoft Security Intelligence portal | Get security intelligence updates for Microsoft Defender for Endpoint, submit samples, and explore the threat encyclopedia | [microsoft.com/wdsi](https://microsoft.com/wdsi) |
4038

@@ -47,10 +45,10 @@ Although these portals aren't specifically for managing security, they support v
4745
| Microsoft Entra admin center | Access and administer the [Microsoft Entra](/entra) family to protect your business with decentralized identity, identity protection, governance, and more, in a multicloud environment | [entra.microsoft.com](https://entra.microsoft.com/) |
4846
| Azure portal | View and manage all your [Azure resources](/azure/azure-resource-manager/management/overview) | [portal.azure.com](https://portal.azure.com/) |
4947
| Microsoft Entra admin center | View and manage [Microsoft Entra ID](/azure/active-directory/fundamentals/active-directory-whatis) | [aad.portal.azure.com](https://aad.portal.azure.com/) |
50-
| Microsoft Purview compliance portal | Manage data handling policies and ensure [compliance with regulations](/compliance/regulatory/offering-home) | [compliance.microsoft.com](https://compliance.microsoft.com/) |
48+
| Microsoft Purview portal | Manage data handling policies and ensure [compliance with regulations](/compliance/regulatory/offering-home) | [purview.microsoft.com](https://purview.microsoft.com/) |
5149
| Microsoft 365 admin center | Configure Microsoft 365 services; manage roles, licenses, and track updates to your Microsoft 365 services | [admin.microsoft.com](https://go.microsoft.com/fwlink/p/?linkid=2166757) |
52-
| Microsoft Intune admin center | Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to manage and secure devices. Can also combine Intune and Configuration Manager capabilities. | [endpoint.microsoft.com](https://endpoint.microsoft.com/) |
53-
| Microsoft Intune portal | Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to deploy device policies and monitor devices for compliance | [endpoint.microsoft.com](https://endpoint.microsoft.com/#blade/Microsoft_Intune_DeviceSettings/DevicesMenu/overview) |
50+
| Microsoft Intune admin center | Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to manage and secure devices. Can also combine Intune and Configuration Manager capabilities. | [intune.microsoft.com](https://intune.microsoft.com/) |
51+
| Microsoft Intune portal | Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to deploy device policies and monitor devices for compliance | [intune.microsoft.com](https://intune.microsoft.com/#blade/Microsoft_Intune_DeviceSettings/DevicesMenu/overview) |
5452

5553

5654
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]

defender-xdr/whats-new.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,9 @@ For more information on what's new with other Microsoft Defender security produc
2626
- [What's new in Microsoft Defender for Endpoint](/defender-endpoint/whats-new-in-microsoft-defender-endpoint)
2727
- [What's new in Microsoft Defender for Identity](/defender-for-identity/whats-new)
2828
- [What's new in Microsoft Defender for Cloud Apps](/cloud-app-security/release-notes)
29+
- [What's new in Microsoft Defender for Cloud](/azure/defender-for-cloud/release-notes)
2930
- [What's new in Microsoft Sentinel](/azure/sentinel/whats-new)
31+
- [What's new in Microsoft Purview](/purview/whats-new)
3032

3133
You can also get product updates and important notifications through the [message center](https://admin.microsoft.com/Adminportal/Home#/MessageCenter).
3234

0 commit comments

Comments
 (0)