You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/cas-compliance-trust.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -31,7 +31,7 @@ Defender for Cloud Apps operates in the Microsoft Azure data centers in the foll
31
31
|**Customers whose tenants are provisioned in the European Union or the United Kingdom**| Either the European Union and/or the United Kingdom |
32
32
|**Customers whose tenants are provisioned in any other region**| The United States and/or a data center in the region that's nearest to the location of where the customer's Microsoft Entra tenant has been provisioned |
33
33
34
-
In addition to the locations above, the App Governance features within Defender for Cloud Apps operate in the Microsoft Azure data centers in the following geographical regions:
34
+
In addition to the locations above, the App Governance features within Defender for Cloud Apps operate in the Microsoft Azure data centers in the following geographical regions listed below. Customer with App Governance enabled will have data stored within the data storage location the customer provisions in above, and in a second data storage location as described below:
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/investigate-anomaly-alerts.md
+4-65Lines changed: 4 additions & 65 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,7 +40,6 @@ Following proper investigation, all Defender for Cloud Apps alerts can be classi
40
40
41
41
You should use the following general guidelines when investigating any type of alert to gain a clearer understanding of the potential threat before applying the recommended action.
42
42
43
-
- Review the user's [investigation priority score](tutorial-ueba.md#understand-the-investigation-priority-score) and compare with the rest of the organization. This will help you identify which users in your organization pose the greatest risk.
44
43
- If you identify a **TP**, review all the user's activities to gain an understanding of the impact.
45
44
- Review all user activity for other indicators of compromise and explore the source and scope of impact. For example, review the following user device information and compare with known device information:
46
45
- Operating system and version
@@ -712,74 +711,14 @@ Establishing a new user's activity pattern requires an initial learning period o
712
711
1. Review the deletion activities and create a list of deleted files. If needed, recover the deleted files.
713
712
1. Optionally, create a playbook using Power Automate to contact users and their managers to verify the activity.
Anomalous activities and activities that triggered alerts are given scores based on severity, user impact, and behavioral analysis of the user. The analysis is done based on other users in the tenants.
716
+
Starting November 2024, **Investigate risky users** support for Microsoft Defender for Cloud Apps is retired. If this feature was used in your organization and is needed, we recommend using the Entra risk score feature. Please use the following resources for additional information:
718
717
719
-
When there's a significant and anomalous increase in the investigation priority score of a certain user, the alert will be triggered.
718
+
-[Investigate risk Microsoft Entra ID Protection - Microsoft Entra ID Protection | Microsoft Learn](/entra/id-protection/howto-identity-protection-investigate-risk)
720
719
721
-
This alert enables detecting potential breaches that are characterized by activities that don't necessarily trigger specific alerts but accumulate to a suspicious behavior for the user.
720
+
-[Microsoft Entra ID Protection risk-based access policies - Microsoft Entra ID Protection | Microsoft Learn](/entra/id-protection/concept-identity-protection-policies)
722
721
723
-
**Learning period**
724
-
725
-
Establishing a new user's activity pattern requires an initial learning period of seven days, during which alerts aren't triggered for any score increase.
726
-
727
-
**TP**, **B-TP**, or **FP**?
728
-
729
-
1.**TP**: If you're able to confirm that the activities of the user aren't legitimate.
730
-
731
-
**Recommended action**: Suspend the user, mark the user as compromised, and reset their password.
732
-
733
-
1.**B-TP**: If you're able to confirm that user indeed significantly deviated from usual behavior, but there's no potential breach.
734
-
735
-
1.**FP** (Unusual behavior): If you're able to confirm that the user legitimately performed the unusual activities, or more activities than the established baseline.
736
-
737
-
**Recommended action**: Dismiss the alert.
738
-
739
-
**Understand the scope of the breach**
740
-
741
-
1. Review all user activity and alerts for additional indicators of compromise.
742
-
743
-
#### Deprecation timeline
744
-
745
-
We're gradually retiring the **Investigation priority score increase** alert from Microsoft Defender for Cloud Apps by August 2024.
746
-
747
-
After careful analysis and consideration, we decided to deprecate it due to the high rate of false positives associated with this alert, which we found wasn't contributing effectively to the overall security of your organization.
748
-
749
-
Our research indicated that this feature wasn't adding significant value and wasn't aligned with our strategic focus on delivering high-quality, reliable security solutions.
750
-
751
-
We're committed to continuously improving our services and ensuring that they meet your needs and expectations.
752
-
753
-
For those who wish to continue using this alert, we suggest using the following advanced hunting query instead as a suggested template. Modify the query based on your needs.
754
-
755
-
```kql
756
-
let time_back = 1d;
757
-
let last_seen_threshold = 30;
758
-
// the number of days which the resource is considered to be in use by the user lately, and therefore not indicates anomaly resource usage
759
-
// anomaly score based on LastSeenForUser column in CloudAppEvents table
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/network-requirements.md
+9Lines changed: 9 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,6 +11,15 @@ ms.topic: reference
11
11
12
12
This article provides a list of ports and IP addresses you need to allow and allowlist to work with Microsoft Defender for Cloud Apps.
13
13
14
+
In order to stay up to date on IP ranges, it's recommended to refer to the following Azure service tags for Microsoft Defender for Cloud Apps services. The latest IP ranges are found in the service tag. For more information, see [Azure IP ranges](https://azureipranges.azurewebsites.net/).
15
+
16
+
| Service tag name | Defender for Cloud Apps services included |
17
+
|:---|:---|
18
+
| MicrosoftCloudAppSecurity | Portal access, Access and session controls, SIEM agent connection, App connector, Mail server, Log collector. |
19
+
20
+
The following tables list the current static IP ranges covered by the MicrosoftCloudAppSecurity service tag. For latest list, refer to the [Azure service tags](/azure/virtual-network/service-tags-overview) documentation.
21
+
22
+
14
23
## View your data center
15
24
16
25
Some of the requirements below depend on which data center you're connected to.
Copy file name to clipboardExpand all lines: CloudAppSecurityDocs/tutorial-ueba.md
-6Lines changed: 0 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -46,12 +46,6 @@ Defender for Cloud Apps uses the following to measure risk:
46
46
47
47
Select the investigation priority score for an alert or an activity to view the evidence that explains how Defender for Cloud Apps scored the activity.
48
48
49
-
> [!NOTE]
50
-
> We're gradually retiring the [**Investigation priority score increase**](investigate-anomaly-alerts.md#investigation-priority-score-increase-preview) alert from Microsoft Defender for Cloud Apps by August 2024. The investigation priority score and the procedure described in this article are not affected by this change.
51
-
>
52
-
> For more information, see [Investigation priority score increase deprecation timeline](investigate-anomaly-alerts.md#deprecation-timeline).
53
-
54
-
55
49
## Phase 1: Connect to the apps you want to protect<aname="connect-apps-protect"></a>
56
50
57
51
Connect at least one app to Microsoft Defender for Cloud Apps using the [API connectors](enable-instant-visibility-protection-and-governance-actions-for-your-apps.md). We recommend that you start by connecting [Microsoft 365](./connect-office-365.md).
Copy file name to clipboardExpand all lines: defender-endpoint/android-whatsnew.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ ms.collection:
15
15
ms.topic: reference
16
16
ms.subservice: android
17
17
search.appverid: met150
18
-
ms.date: 01/03/2025
18
+
ms.date: 01/06/2025
19
19
---
20
20
21
21
# What's new in Microsoft Defender for Endpoint on Android
@@ -40,7 +40,7 @@ Recommendation cards prominently display any active alerts, ensuring you stay in
40
40
41
41
The following screenshot is an example of what the user sees in their dashboard:
42
42
43
-
:::image type="content" source="media/android-whatsnew/android-dashboard-screen.png" alt-text="Screenshot showing what the user sees on the device.":::
43
+
:::image type="content" source="media/android-whatsnew/android-dashboard-screen.png" alt-text="Screenshot showing the user's dashboard in the Microsoft Defender app.":::
44
44
45
45
**Recommendation cards for alerts**
46
46
@@ -59,10 +59,10 @@ The current enterprise dashboard experience now features a tile view for your se
59
59
60
60
| Tile | Description |
61
61
|---|---|
62
-
| :::image type="content" source="media/android-whatsnew/android-tile-networkprotection.png" alt-text="Screenshot showing the network protection tile for security administrators."::: |**Network protection** <br/>Your security team can see whether a connection is secured or unsecured. |
63
-
| :::image type="content" source="media/android-whatsnew/android-tile-webprotection.png" alt-text="Screenshot of a tile that shows whether web protection is enabled on a device."::: |**Web protection** <br/>Your security team can see whether web protection is enabled on a user's device. |
64
-
| :::image type="content" source="media/android-whatsnew/android-tile-appsecurity.png" alt-text="Screenshot showing the app security tile."::: |**App security** <br/>Your security team can see whether any threats were found in apps installed on a user's device. |
65
-
| :::image type="content" source="media/android-whatsnew/android-tile-globalsecureaccess.png" alt-text="Screenshot showing Global Secure Access status."::: |**Global secure access** <br/>Your security team can see current connection status. |
62
+
| :::image type="content" source="media/android-whatsnew/android-tile-networkprotection.png" alt-text="Screenshot showing the network protection tile for security administrators."::: |**Network protection** <br/>The user can see whether a connection is secured or unsecured. |
63
+
| :::image type="content" source="media/android-whatsnew/android-tile-webprotection.png" alt-text="Screenshot of a tile that shows whether web protection is enabled on a device."::: |**Web protection** <br/>The user can see whether web protection is enabled on a user's device. |
64
+
| :::image type="content" source="media/android-whatsnew/android-tile-appsecurity.png" alt-text="Screenshot showing the app security tile."::: |**App security** <br/>The user can see whether any threats were found in apps installed on a user's device. |
65
+
| :::image type="content" source="media/android-whatsnew/android-tile-globalsecureaccess.png" alt-text="Screenshot showing Global Secure Access status."::: |**Global secure access** <br/>The user can see current connection status. |
66
66
67
67
## Android low-touch onboarding is now GA
68
68
@@ -125,7 +125,7 @@ Read the announcement [Tech Community Blog: Defender for Endpoint is now availab
125
125
126
126
## Privacy controls
127
127
128
-
Microsoft Defender for Endpoint on Android enables privacy controls for both administrators and end users, and includes controls for enrolled (MDM) and unenrolled (MAM) devices. Administrators can configure the privacy in the alert report while End Users can configure the information shared to their organization. For more information, see [privacy controls(MDM)](android-configure.md#privacy-controls) and [privacy controls (MAM)](android-configure-mam.md#configure-privacy-controls).
128
+
Microsoft Defender for Endpoint on Android enables privacy controls for both administrators and end users, and includes controls for enrolled (MDM) and unenrolled (MAM) devices. Administrators can configure the privacy in the alert report while End Users can configure the information shared to their organization. For more information, see [privacy controls(MDM)](android-configure.md#privacy-controls) and [privacy controls (MAM)](android-configure-mam.md#configure-privacy-controls).
129
129
130
130
## Optional permissions and the ability to disable web protection
0 commit comments