Skip to content

Commit 44d18c7

Browse files
authored
Merge pull request #579 from cwatson-cat/5-29-24-usx-prod-def
Sentinel - USX production ready - rmv preview
2 parents 66afd1a + cd32b1d commit 44d18c7

8 files changed

+20
-21
lines changed

defender-xdr/automatic-attack-disruption.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ ms.topic: conceptual
1818
search.appverid:
1919
- MOE150
2020
- MET150
21-
ms.date: 02/21/2024
21+
ms.date: 05/29/2024
2222
---
2323

2424
# Automatic attack disruption in Microsoft Defender XDR
@@ -71,7 +71,7 @@ Automatic attack disruption uses Microsoft-based XDR response actions. Examples
7171

7272
For more information, see [remediation actions](m365d-remediation-actions.md) in Microsoft Defender XDR.
7373

74-
### Automated response actions for SAP with Microsoft Sentinel (Preview)
74+
### Automated response actions for SAP with Microsoft Sentinel
7575

7676
If you're using the [unified security operations platform](microsoft-sentinel-onboard.md) and you deployed the Microsoft Sentinel solution for SAP applications, you can also deploy automatic attack disruption for SAP.
7777

defender-xdr/entity-page-device.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -314,6 +314,6 @@ Response actions run along the top of a specific device page and include:
314314
- [User entity page in Microsoft Defender](investigate-users.md)
315315
- [IP address entity page in Microsoft Defender](entity-page-ip.md)
316316
- [Microsoft Defender XDR integration with Microsoft Sentinel](microsoft-365-defender-integration-with-azure-sentinel.md)
317-
- [Connect Microsoft Sentinel to Microsoft Defender XDR (preview)](microsoft-sentinel-onboard.md)
317+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
318318

319319
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]

defender-xdr/entity-page-ip.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -127,5 +127,5 @@ Response actions run along the top of a specific IP entity page and include:
127127
- [Device entity page in Microsoft Defender](entity-page-device.md)
128128
- [User entity page in Microsoft Defender](investigate-users.md)
129129
- [Microsoft Defender XDR integration with Microsoft Sentinel](microsoft-365-defender-integration-with-azure-sentinel.md)
130-
- [Connect Microsoft Sentinel to Microsoft Defender XDR (preview)](microsoft-sentinel-onboard.md)
130+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
131131
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

defender-xdr/investigate-users.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -265,7 +265,7 @@ As needed for in-process incidents, continue your [investigation](investigate-in
265265
- [Device entity page in Microsoft Defender](entity-page-device.md)
266266
- [IP address entity page in Microsoft Defender](entity-page-ip.md)
267267
- [Microsoft Defender XDR integration with Microsoft Sentinel](microsoft-365-defender-integration-with-azure-sentinel.md)
268-
- [Connect Microsoft Sentinel to Microsoft Defender XDR (preview)](microsoft-sentinel-onboard.md)
268+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
269269

270270

271271
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]

defender-xdr/microsoft-365-defender-portal.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -204,7 +204,7 @@ Keep exploring the features and capabilities in the Defender portal:
204204
- [Email & collaboration alerts](/Microsoft-365/compliance/alert-policies#default-alert-policies)
205205
- [Create a phishing attack simulation](/defender-office-365/attack-simulation-training-simulations) and [create a payload for training your teams](/defender-office-365/attack-simulation-training-payloads)
206206

207-
To explore capabilities related to the Microsoft Sentinel integration with Microsoft Defender XDR in the unified security operations platform (preview), see [Microsoft Sentinel in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2263690).
207+
To explore capabilities related to the Microsoft Sentinel integration with Microsoft Defender XDR in the unified security operations platform, see [Microsoft Sentinel in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2263690).
208208

209209
## Training for security analysts
210210

defender-xdr/microsoft-sentinel-onboard.md

Lines changed: 10 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: Connect Microsoft Sentinel to Microsoft Defender XDR (preview)
2+
title: Connect Microsoft Sentinel to Microsoft Defender XDR
33
description: Learn how to connect your Microsoft Sentinel environment to Microsoft Defender XDR to unify your security operations.
44
ms.service: defender-xdr
55
f1.keywords:
@@ -22,25 +22,23 @@ search.appverid:
2222
appliesto:
2323
- Microsoft Defender XDR
2424
- Microsoft Sentinel in the Microsoft Defender portal
25-
ms.date: 04/03/2024
25+
ms.date: 05/29/2024
2626
---
2727

28-
# Connect Microsoft Sentinel to Microsoft Defender XDR (preview)
28+
# Connect Microsoft Sentinel to Microsoft Defender XDR
2929

30-
Microsoft Sentinel is available as part of the public preview for the unified security operations platform in the Microsoft Defender portal. When you onboard Microsoft Sentinel to the Microsoft Defender portal, you unify capabilities with Microsoft Defender XDR like incident management and advanced hunting. Reduce tool switching and build a more context-focused investigation that expedites incident response and stops breaches faster. For more information, see:
30+
Microsoft Sentinel is available as part of the unified security operations platform in the Microsoft Defender portal. Microsoft Sentinel in the Defender portal is now supported for production use. When you onboard Microsoft Sentinel to the Microsoft Defender portal, you unify capabilities with Microsoft Defender XDR like incident management and advanced hunting. Reduce tool switching and build a more context-focused investigation that expedites incident response and stops breaches faster. For more information, see:
3131

3232
- [Microsoft Sentinel in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2263690)
3333
- [Unified security operations platform with Microsoft Sentinel and Defender XDR](https://aka.ms/unified-soc-announcement)
3434

35-
> [!IMPORTANT]
36-
> Information in this article relates to a prerelease product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
37-
3835
## Prerequisites
3936

40-
Before you begin, review the feature documentation to understand the product changes and limitations:
41-
- [Microsoft Sentinel in the Microsoft Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal)
42-
- [Advanced hunting in the Microsoft Defender portal](advanced-hunting-microsoft-defender.md)
43-
- [Automation with the unified security operations platform](/azure/sentinel/automation#automation-with-the-unified-security-operations-platform)
37+
Before you begin, review the feature documentation to understand the product changes and limitations:
38+
39+
- [Microsoft Sentinel in the Microsoft Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal)
40+
- [Advanced hunting in the Microsoft Defender portal](advanced-hunting-microsoft-defender.md)
41+
- [Automation with the unified security operations platform](/azure/sentinel/automation#automation-with-the-unified-security-operations-platform)
4442

4543
The Microsoft Defender portal supports a single Microsoft Entra tenant and the connection to one workspace at a time. In the context of this article, a workspace is a Log Analytics workspace with Microsoft Sentinel enabled.
4644

@@ -133,3 +131,4 @@ If you want to connect to a different workspace, from the **Workspaces** page, s
133131
- [Advanced hunting in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2264410)
134132
- [Automatic attack disruption in Microsoft Defender XDR](automatic-attack-disruption.md)
135133
- [Investigate incidents in Microsoft Defender XDR](investigate-incidents.md)
134+
- [Optimize your security operations](/azure/sentinel/soc-optimization/soc-optimization-access?tabs=defender-portal)
Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: "include file"
33
description: "include file"
4-
ms.date: 03/27/2024
4+
ms.date: 05/29/2024
55
manager: dansimp
66
ms.author: cwatson
77
author: cwatson-cat
@@ -10,4 +10,4 @@ ms.topic: include
1010
ms.custom: "include file"
1111
---
1212

13-
Microsoft Sentinel is available as part of the public preview for the unified security operations platform in the Microsoft Defender portal. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2263690).
13+
Microsoft Sentinel is available as part of the unified security operations platform in the Microsoft Defender portal. Microsoft Sentinel in the Defender portal is now supported for production use. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2263690).

includes/unified-soc-preview.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: "include file"
33
description: "include file"
4-
ms.date: 03/27/2024
4+
ms.date: 05/29/2024
55
manager: dansimp
66
ms.author: cwatson
77
author: cwatson-cat
@@ -11,4 +11,4 @@ ms.custom: "include file"
1111
---
1212

1313
> [!IMPORTANT]
14-
> Microsoft Sentinel is available as part of the public preview for the unified security operations platform in the Microsoft Defender portal. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2263690).
14+
> Microsoft Sentinel is available as part of the unified security operations platform in the Microsoft Defender portal. Microsoft Sentinel in the Defender portal is now supported for production use. For more information, see [Microsoft Sentinel in the Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2263690).

0 commit comments

Comments
 (0)