Skip to content

Commit 4e1fa9b

Browse files
Merge pull request #2237 from MicrosoftDocs/vivek-eod-update
updated to eod experience
2 parents a2249ce + 7fb7a22 commit 4e1fa9b

File tree

1 file changed

+36
-20
lines changed

1 file changed

+36
-20
lines changed

defender-xdr/experts-on-demand.md

Lines changed: 36 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ ms.collection:
2121
- essentials-manage
2222
ms.topic: conceptual
2323
search.appverid: met150
24-
ms.date: 10/31/2024
24+
ms.date: 12/20/2024
2525
---
2626

2727
# Collaborate with experts on demand
@@ -33,7 +33,7 @@ ms.date: 10/31/2024
3333
- [Microsoft Defender XDR](microsoft-365-defender.md)
3434

3535
> [!NOTE]
36-
> Ask Defender Experts is included in your Defender Experts for Hunting subscription with [quarterly allocations](before-you-begin-defender-experts.md#eligibility-and-licensing). However, it's not a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
36+
> Ask Defender Experts is included in your Defender Experts for Hunting subscription with [quarterly allocations](before-you-begin-defender-experts.md#eligibility-and-licensing).
3737
3838
Select **Ask Defender Experts** directly inside the Microsoft 365 security portal to get swift and accurate responses to all your threat hunting questions. Experts can provide insight to better understand the complex threats your organization might face. Ask Defender Experts can help:
3939

@@ -43,7 +43,7 @@ Select **Ask Defender Experts** directly inside the Microsoft 365 security porta
4343

4444
:::image type="content" source="media/ask-defender-expert-dialog.png" alt-text="Screenshot of the Ask Defender Experts dialog box." lightbox="media/ask-defender-expert-dialog.png":::
4545

46-
### Required permissions for using Ask Defender Experts
46+
## Required permissions for using Ask Defender Experts
4747

4848
You need to select one of the following Microsoft Entra ID roles to view and submit inquiries to our Defender experts.
4949

@@ -61,7 +61,7 @@ Microsoft Threat Experts customers using Ask Defender Experts capability will al
6161
| Security data basics | Read |
6262
| Alerts, Response | Read and submit |
6363

64-
### Where to submit inquiries to Ask Defender Experts
64+
## Where to submit inquiries to Ask Defender Experts
6565

6666
The option to **Ask Defender Experts** is available in several places throughout the portal:
6767

@@ -71,60 +71,76 @@ The option to **Ask Defender Experts** is available in several places throughout
7171

7272
- **Device inventory page flyout menu**:
7373

74-
:::image type="content" source="/defender/media/mte/defenderexperts/device-inventory-flyout-menu.png" alt-text="Screenshot of the Ask Defender Experts menu option in the Device inventory page flyout menu in the Microsoft Defender portal.." lightbox="/defender/media/mte/defenderexperts/device-inventory-flyout-menu.png":::
74+
:::image type="content" source="/defender/media/mte/defenderexperts/device-inventory-flyout-menu.png" alt-text="Screenshot of the Ask Defender Experts menu option in the Device inventory page flyout menu in the Microsoft Defender portal." lightbox="/defender/media/mte/defenderexperts/device-inventory-flyout-menu.png":::
7575

7676
- **Alerts page flyout menu**:
7777

78-
:::image type="content" source="/defender/media/mte/defenderexperts/alerts-flyout-menu.png" alt-text="Screenshot of the Ask Defender Experts menu option in the Alerts page flyout menu in the Microsoft Defender portal.." lightbox="/defender/media/mte/defenderexperts/alerts-flyout-menu.png":::
78+
:::image type="content" source="/defender/media/mte/defenderexperts/alerts-flyout-menu.png" alt-text="Screenshot of the Ask Defender Experts menu option in the Alerts page flyout menu in the Microsoft Defender portal." lightbox="/defender/media/mte/defenderexperts/alerts-flyout-menu.png":::
7979

8080
- **Incidents page actions menu**:
8181

82-
:::image type="content" source="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png" alt-text="Screenshot of the Ask Defender Experts menu option in the Incidents page actions menu in the Microsoft Defender portal.." lightbox="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png":::
82+
:::image type="content" source="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png" alt-text="Screenshot of the Ask Defender Experts menu option in the Incidents page actions menu in the Microsoft Defender portal." lightbox="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png":::
8383

84-
### Where to view responses from Defender Experts
84+
## Where to view responses from Defender Experts
8585

86-
#### In portal
86+
### In portal
8787

88-
You can view responses to inquiries submitted to Ask Defender Experts from up to six months ago by navigating to **Reports** > **Defender Experts messages**. You will also be able to ask follow-up questions or reply with more information to Defender Experts from this page.
88+
You can view responses to inquiries submitted to Ask Defender Experts from up to six months ago by navigating to **Reports** > **Defender Experts messages**. You'll also be able to ask follow-up questions or reply with more information to Defender Experts from this page.
8989

9090
:::image type="content" source="media/inportal-managed-response.png" alt-text="Screenshot of in-portal managed response." lightbox="media/inportal-managed-response.png":::
9191

92-
#### Email
92+
### Email
9393

94-
If you included contact email addresses when submitting your inquiry, they will receive an email notification when a response from Defender Experts is posted.
94+
If you included contact email addresses when submitting your inquiry, they'll receive an email notification when a response from Defender Experts is posted.
9595

9696
:::image type="content" source="media/email-based-managed-response.png" alt-text="Screenshot of email based managed response." lightbox="media/email-based-managed-response.png":::
9797

98-
> [!NOTE]
99-
> Defender Experts will not be able to assist you with inquiries regarding bugs or issues in your product experience in the Microsoft Defender XDR portal. You can reach out to Microsoft Support via the [Services Hub](https://serviceshub.microsoft.com/home) regarding such inquiries.
100-
101-
### Sample questions you can ask from Defender Experts
98+
## Sample questions you can ask from Defender Experts
10299

103-
#### Alert information
100+
### Alert information
104101

105102
- We saw a new type of alert for a living-off-the-land binary. We can provide the alert ID. Can you tell us more about this alert and if it's related to any incident and how we can investigate it further?
106103
- We've observed two similar attacks, which both try to execute malicious PowerShell scripts but generate different alerts. One is "Suspicious PowerShell command line" and the other is "A malicious file was detected based on indication provided by Office 365." What is the difference?
107104
- We received an odd alert today about an abnormal number of failed logins from a high profile user's device. We can't find any further evidence for these attempts. How can Microsoft Defender XDR see these attempts? What type of logins are being monitored?
108105
- Can you give more context or insight about the alert and any related incidents, "Suspicious behavior by a system utility was observed"?
109106
- I observed an alert titled "Creation of forwarding/redirect rule". I believe the activity is benign. Can you tell me why I received an alert?
110107

111-
#### Possible device compromise
108+
### Possible device compromise
112109

113110
- Can you help explain why we see a message or alert for "Unknown process observed" on many devices in our organization? We appreciate any input to clarify whether this message or alert is related to malicious activity or incidents.
114111
- Can you help validate a possible compromise on the following system, dating from last week? It's behaving similarly as a previous malware detection on the same system six months ago.
115112

116-
#### Threat intelligence details
113+
### Threat intelligence details
117114

118115
- We detected a phishing email that delivered a malicious Word document to a user. The document caused a series of suspicious events, which triggered multiple alerts for a particular malware family. Do you have any information on this malware? If yes, can you send us a link?
119116
- We recently saw a blog post about a threat that is targeting our industry. Can you help us understand what protection Microsoft Defender XDR provides against this threat actor?
120117
- We recently observed a phishing campaign conducted against our organization. Can you tell us if this was targeted specifically to our company or vertical?
121118

122-
#### Microsoft Defender Experts for Hunting alert communications
119+
### Microsoft Defender Experts for Hunting alert communications
123120

124121
- Can your incident response team help us address the Defender Experts Notification that we got?
125122
- We received this Defender Experts Notification from Microsoft Defender Experts for Hunting. We don't have our own incident response team. What can we do now, and how can we contain the incident?
126123
- We received a Defender Experts Notification from Microsoft Defender Experts for Hunting. What data can you provide to us that we can pass on to our incident response team?
127124

125+
## Services that aren't in scope for Defender Experts
126+
127+
Ask Defender Experts is focused on products that are only included in Microsoft Defender XDR, i.e., Microsoft Defender for Endpoint, Microsoft Defender for Office, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity.
128+
129+
The service doesn't cover the following scenarios:
130+
131+
- Inquiries related to custom detections in the above products can't be handled in Ask Defender Experts because our experts typically don't have access to such telemetry or visibility into how these custom policies were set up. Examples of such policies include:
132+
133+
- **Alerts with policy source** = **Custom**
134+
- **Detection source** = **Custom TI**
135+
- **Alert title** = **Anomaly Indicator**
136+
- **Threat family** = **Custom Enterprise Block Only**
137+
138+
- Defender Experts won't be able to handle inquiries on non-Defender XDR products such as Microsoft Defender for Cloud, Microsoft Defender for IoT, Microsoft Sentinel, Microsoft Purview, Microsoft Priva, and other third-party cybersecurity products.
139+
140+
- Defender Experts won't be able to assist you with inquiries regarding bugs in your product experience in the Defender XDR portal, such as, missing data on the alert or incident page or a recommended action not completing when you action it. You can reach out to Microsoft Support via the [Services Hub](https://serviceshub.microsoft.com/home) regarding such issues.
141+
142+
- Ask Defender Experts isn't a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
143+
128144
### Next step
129145

130146
- [Understand the Defender Experts for Hunting report in Microsoft Defender XDR](defender-experts-report.md)

0 commit comments

Comments
 (0)