You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/mto-advanced-hunting.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Advanced hunting in multitenant management in Microsoft Defender XDR
3
-
description: Learn about advanced hunting in multitenant management in Microsoft Defender XDR
2
+
title: Advanced hunting in Microsoft Defender multitenant management
3
+
description: Learn about advanced hunting in Microsoft Defender multitenant management
4
4
search.appverid: met150
5
5
ms.service: defender-xdr
6
6
ms.author: siosulli
@@ -50,7 +50,7 @@ Likewise, you can manage custom detection rules from multiple tenants in the cus
50
50
51
51
### View custom detection rules by tenant
52
52
53
-
1. To view custom detection rules, go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multitenant management in Microsoft Defender XDR.
53
+
1. To view custom detection rules, go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in Microsoft Defender multitenant management.
54
54
2. View the **Tenant name** column to see which tenant the detection rule comes from:
55
55
56
56
:::image type="content" source="/defender/media/defender/mto-custom-detection-tenant-name.png" alt-text="Screenshot of the Microsoft Defender XDR multi-tenant custom detection page" lightbox="/defender/media/defender/mto-custom-detection-tenant-name.png":::
@@ -61,11 +61,11 @@ To read more about custom detection rules, read [Custom detections overview](cus
61
61
62
62
### Manage custom detection rules
63
63
64
-
You can **Run**, **Turn off**, and **Delete** detection rules from multitenant management in Microsoft Defender XDR.
64
+
You can **Run**, **Turn off**, and **Delete** detection rules from Microsoft Defender multitenant management.
65
65
66
66
To manage detection rules:
67
67
68
-
1. Go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multitenant management in Microsoft Defender XDR
68
+
1. Go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in Microsoft Defender multitenant management
69
69
2. Choose the detection rule you want to manage
70
70
71
71
When you select a single detection rule, a flyout panel opens with the detection rule details:
@@ -76,6 +76,6 @@ Select **Open detection rules** to view this rule in a new tab for the specific
76
76
77
77
## Related content
78
78
79
-
-[Set up multitenant management in Microsoft Defender XDR](mto-requirements.md)
79
+
-[Set up Microsoft Defender multitenant management](mto-requirements.md)
80
80
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
81
81
-[View and manage incidents and alerts](mto-incidents-alerts.md)
Copy file name to clipboardExpand all lines: defender-xdr/mto-incidents-alerts.md
+11-11Lines changed: 11 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: View and manage incidents and alerts in multitenant management for Microsoft Defender XDR
3
-
description: Learn about incidents and alerts in multitenant management for Microsoft Defender XDR
2
+
title: View and manage incidents and alerts in Microsoft Defender multitenant management
3
+
description: Learn about incidents and alerts in Microsoft Defender multitenant management
4
4
search.appverid: met150
5
5
ms.service: defender-xdr
6
6
ms.author: siosulli
@@ -20,7 +20,7 @@ appliesto:
20
20
- Microsoft Sentinel in the Microsoft Defender portal
21
21
---
22
22
23
-
# View and manage incidents and alerts
23
+
# View and manage incidents and alerts in Microsoft Defender multitenant management
24
24
25
25
Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats. Triage incidents and alerts across security information and event management (SIEM) and extended detection and response (XDR) data for tenants that onboarded a Microsoft Sentinel workspace to the unified security operations platform.
26
26
@@ -30,13 +30,13 @@ Manage incidents & alerts originating from multiple tenants under **Incidents &
30
30
31
31
To view or investigate an incident:
32
32
33
-
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multitenant management in Microsoft Defender XDR. The **Tenant name** column shows which tenant the incident originates from:
33
+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in Microsoft Defender multitenant management. The **Tenant name** column shows which tenant the incident originates from:
34
34
35
35
:::image type="content" source="/defender/media/defender/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender multi-tenant incidents page" lightbox="/defender/media/defender/mto-incidents.png":::
36
36
37
37
2. Select the incident you want to view. A flyout panel opens with the incident details page:
38
38
39
-
:::image type="content" source="/defender/media/defender/mto-incident-details.png" alt-text="Screenshot of the Microsoft Defender XDR incidents details page" lightbox="/defender/media/defender/mto-incident-details.png":::
39
+
:::image type="content" source="/defender/media/defender/mto-incident-details.png" alt-text="Screenshot of the Microsoft Defender multi-tenant incidents details page" lightbox="/defender/media/defender/mto-incident-details.png":::
40
40
41
41
3. From the incident details page you can:
42
42
@@ -49,10 +49,10 @@ To learn more, see [Investigate incidents](/defender-endpoint/investigate-incide
49
49
50
50
To manage incidents across multiple tenants:
51
51
52
-
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multitenant management.
52
+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in Microsoft Defender multitenant management.
53
53
2. Choose the incidents you want to manage from the incidents list and select **Manage incidents**.
54
54
55
-
:::image type="content" source="/defender/media/defender/mto-manage-incidents.png" alt-text="Screenshot of the Microsoft Defender XDR incidents page" lightbox="/defender/media/defender/mto-manage-incidents.png":::
55
+
:::image type="content" source="/defender/media/defender/mto-manage-incidents.png" alt-text="Screenshot of the Microsoft Defender multi-tenant incidents page" lightbox="/defender/media/defender/mto-manage-incidents.png":::
56
56
57
57
On the incidents fly-out you can assign incidents, assign incidents tags, set the incident status, and classify multiple incidents for multiple tenants simultaneously.
58
58
@@ -80,10 +80,10 @@ To learn more, see [Investigate alerts](/defender-endpoint/investigate-alerts).
80
80
81
81
To manage alerts across multiple tenants:
82
82
83
-
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multitenant management.
83
+
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in Microsoft Defender multitenant management.
84
84
2. Choose the alerts you want to manage from the alerts list and select **Manage alerts**.
85
85
86
-
:::image type="content" source="/defender/media/defender/mto-manage-alerts.png" alt-text="Screenshot of the Microsoft Defender XDR alerts page" lightbox="/defender/media/defender/mto-manage-alerts.png":::
86
+
:::image type="content" source="/defender/media/defender/mto-manage-alerts.png" alt-text="Screenshot of the Microsoft Defender multitenant alerts page" lightbox="/defender/media/defender/mto-manage-alerts.png":::
87
87
88
88
On the alert fly-out you can assign alerts, set the alert status, and classify the alerts for multiple tenants simultaneously.
89
89
@@ -93,7 +93,7 @@ To learn more about alerts in the Microsoft Defender portal, see [Manage alerts]
93
93
94
94
## Related content
95
95
96
-
-[Set up multitenant management in Microsoft Defender XDR](mto-requirements.md)
96
+
-[Set up Microsoft Defender multitenant management](mto-requirements.md)
97
97
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
98
-
-[Advanced hunting in multitenant management in Microsoft Defender XDR](mto-advanced-hunting.md)
98
+
-[Advanced hunting in Microsoft Defender multitenant management](mto-advanced-hunting.md)
Copy file name to clipboardExpand all lines: defender-xdr/mto-overview.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,5 +1,5 @@
1
1
---
2
-
title: Multitenant management for the Microsoft unified security operations platform
2
+
title: Microsoft Defender multitenant management
3
3
description: Learn about multitenant management for Microsoft Defender XDR and Microsoft Sentinel in the Microsoft unified security operations platform.
4
4
ms.service: defender-xdr
5
5
ms.author: siosulli
@@ -21,7 +21,7 @@ appliesto:
21
21
- Microsoft Defender for Office 365 P2
22
22
---
23
23
24
-
# Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform
24
+
# Microsoft Defender multitenant management
25
25
26
26
Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform provides your security operation teams with a single, unified view of all the tenants you manage. This view enables your teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving your security operations.
27
27
@@ -30,7 +30,7 @@ If you have tenants with a Microsoft Sentinel workspace onboarded to the unified
30
30
- Triage incidents and alerts across security information and event management (SIEM) and extended detection and response (XDR) data.
31
31
- Proactively search for SIEM and XDR data across multiple tenants.
32
32
33
-
Only one Microsoft Sentinel workspace per tenant is currently supported in the unified security operations platform. So in multitenant management, you have SIEM data from one Microsoft Sentinel workspace per tenant.
33
+
Only one Microsoft Sentinel workspace per tenant is currently supported in the unified security operations platform. So in Microsoft Defender multitenant management, you have SIEM data from one Microsoft Sentinel workspace per tenant.
34
34
35
35
For more information, see:
36
36
@@ -67,4 +67,4 @@ The following key capabilities are available for each tenant you have access to
67
67
68
68
## Next steps
69
69
70
-
-[Set up multitenant management in Microsoft Defender XDR](mto-requirements.md)
70
+
-[Set up Microsoft Defender multitenant management](mto-requirements.md)
Copy file name to clipboardExpand all lines: defender-xdr/mto-tenants.md
+11-6Lines changed: 11 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Manage tenants with multitenant management in Microsoft Defender XDR
3
-
description: Learn about the tenant list in multitenant management in Microsoft Defender XDR
2
+
title: Manage tenants with Microsoft Defender multitenant management
3
+
description: Learn about the tenant list in Microsoft Defender multitenant management
4
4
search.appverid: met150
5
5
ms.service: defender-xdr
6
6
ms.author: siosulli
@@ -20,15 +20,15 @@ appliesto:
20
20
- Microsoft Sentinel in the Microsoft Defender portal
21
21
---
22
22
23
-
# Manage tenants in Microsoft Defender XDR
23
+
# Manage tenants with Microsoft Defender multitenant management
24
24
25
-
Add or remove tenants from the settings page in multitenant management from the Microsoft Defender portal.
25
+
Add or remove tenants from the settings page in Microsoft Defender multitenant management.
26
26
27
27
## View the tenants page
28
28
29
-
To view the list of tenants that appear in multitenant management, go to [Settings page](https://mto.security.microsoft.com/mtosettings) in multitenant management in Microsoft Defender XDR:
29
+
To view the list of tenants that appear in multitenant management, go to [Settings page](https://mto.security.microsoft.com/mtosettings) in Microsoft Defender multitenant management:
30
30
31
-
:::image type="content" source="/defender/media/defender/mto-tenant-settings.png" alt-text="Screenshot of multitenant management in Microsoft Defender XDR" lightbox="/defender/media/defender/mto-tenant-settings.png":::
31
+
:::image type="content" source="/defender/media/defender/mto-tenant-settings.png" alt-text="Screenshot of Microsoft Defender multitenant management" lightbox="/defender/media/defender/mto-tenant-settings.png":::
32
32
33
33
From the **Settings** page you can:
34
34
@@ -51,3 +51,8 @@ When an issue exists, the status indicator shows a red warning sign:
51
51
Hovering over the red warning sign displays the issues that occurred and the tenant information. By expanding each section, you see all the tenants with this issue.
52
52
53
53
-
0 commit comments