Skip to content

Commit 588b98c

Browse files
committed
Merge branch 'main' into maccruz-identityinfo
2 parents 0d33643 + ab66416 commit 588b98c

File tree

179 files changed

+1346
-1128
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

179 files changed

+1346
-1128
lines changed

.openpublishing.redirection.defender-endpoint.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,15 @@
11
{
22
"redirections": [
3+
{
4+
"source_path": "defender-endpoint/threat-analytics-analyst-reports.md",
5+
"redirect_url": "/defender-xdr/threat-analytics-analyst-reports",
6+
"redirect_document_id": false
7+
},
8+
{
9+
"source_path": "defender-endpoint/threat-analytics.md",
10+
"redirect_url": "/defender-xdr/threat-analytics",
11+
"redirect_document_id": false
12+
},
313
{
414
"source_path": "defender-endpoint/configure-microsoft-threat-experts.md",
515
"redirect_url": "/defender-xdr/defender-experts-for-hunting",

ATPDocs/whats-new.md

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,13 @@ For more information, see also:
2222

2323
For updates about versions and features released six months ago or earlier, see the [What's new archive for Microsoft Defender for Identity](whats-new-archive.md).
2424

25+
## March 2025
26+
27+
### New LDAP query events added to the IdentityQueryEvents table in Advanced Hunting
28+
New LDAP query events will be added by March 6th to the `IdentityQueryEvents` table in Advanced Hunting to provide more visibility into additional LDAP search queries running in the customer environment.
29+
This update may lead to an increase in activity within the Advanced Hunting IdentityQueryEvents table for LDAP queries. If you have custom detections related to these queries, you may see a higher number of triggered alerts.
30+
We recommend that you review your existing custom detections to ensure they align with your objectives. If needed, you can adjust your query accordingly.
31+
2532
## February 2025
2633

2734
### DefenderForIdentity PowerShell module updates (version 1.0.0.3)
@@ -67,6 +74,12 @@ We have added and updated the following events in the `IdentityDirectoryEvents`
6774

6875
Additionally, the **built-in schema reference** for Advanced Hunting in Microsoft Defender XDR has been updated to include detailed information on all supported event types (**`ActionType`** values) in identity-related tables, ensuring complete visibility into available events. For more information, see [Advanced hunting schema details](/defender-xdr/advanced-hunting-schema-tables).
6976

77+
## January 2025
78+
79+
### New Identity guide tour
80+
81+
Explore key MDI features with the new **Identities Tour** in the M365 portal. Navigate Incidents, Hunting, and Settings to enhance identity security and threat investigation.
82+
7083
## December 2024
7184

7285
### New security posture assessment: Prevent Certificate Enrollment with arbitrary Application Policies (ESC15)

CloudAppSecurityDocs/tutorial-dlp.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -79,7 +79,6 @@ Our approach to information protection can be split into the following phases th
7979
1. Under **Inspection method**, choose and configure one of the following classification services:
8080

8181
- **[Data Classification Services](dcs-inspection.md)**: Uses classification decisions you've made across Microsoft 365, Microsoft Purview Information Protection, and Defender for Cloud Apps to provide a unified labeling experience. This is the preferred content inspection method as it provides a consistent and unified experience across Microsoft products.
82-
- **[Built-in DLP](content-inspection-built-in.md)**: Inspects files for sensitive information using our built-in DLP content inspection engine.
8382

8483
1. For highly sensitive files, select **Create an alert** and choose the alerts you require, so that you're informed when there are files with unprotected sensitive information in your organization.
8584
1. Select **Create**.

defender-business/get-defender-business.md

Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ audience: Admin
99
ms.topic: overview
1010
ms.service: defender-business
1111
ms.localizationpriority: medium
12-
ms.date: 06/07/2024
12+
ms.date: 02/28/2025
1313
ms.reviewer: efratka
1414
f1.keywords: NOCSH
1515
ms.collection:
@@ -35,12 +35,30 @@ Sections include:
3535

3636
To get Defender for Business, you can choose from several options:
3737

38+
- Work with a Microsoft partner who can help you get everything set up and configured.
3839
- Try or buy the standalone version of Defender for Business.
3940
- Get Microsoft 365 Business Premium, which includes Defender for Business.
40-
- Work with a Microsoft partner who can help you get everything set up and configured.
4141

4242
Use the following tabs to learn more about each option.
4343

44+
## [Work with a Microsoft partner](#tab/findpartner)
45+
46+
Microsoft has a list of solution providers who are authorized to sell offerings, including Microsoft 365 Business Premium and Microsoft Defender for Business. If you'd prefer to work with a Microsoft partner, you can follow these steps to find a solution provider in your area:
47+
48+
1. Go to [Browse Partners](https://appsource.microsoft.com/en-us/marketplace/partner-dir).
49+
50+
2. In the **Filters** pane, specify search criteria, such as:
51+
52+
- Your location
53+
- Your organization's size
54+
- **Focus areas**, such as **Security** and/or **Threat Protection**
55+
56+
- **Services**, such as **Licensing** or **Managed Services (MSP)**
57+
58+
As soon as you select one or more criteria, the list of partners updates.
59+
60+
3. Review the list of results. Select a provider to learn more about their expertise and the services they provide.
61+
4462
## [Get Defender for Business (standalone)](#tab/getmdb)
4563

4664
Defender for Business provides advanced security protection for your company's devices. For more information, see [What is Microsoft Defender for Business](mdb-overview.md)?
@@ -77,24 +95,6 @@ Microsoft 365 Business Premium includes Defender for Business, Microsoft Defende
7795
> [!IMPORTANT]
7896
> Make sure to complete all the steps described in [Microsoft 365 Business Premium – productivity and cybersecurity for small business](/Microsoft-365/business-premium/m365bp-overview).
7997
80-
## [Work with a Microsoft partner](#tab/findpartner)
81-
82-
Microsoft has a list of solution providers who are authorized to sell offerings, including Microsoft 365 Business Premium and Microsoft Defender for Business. If you'd prefer to work with a Microsoft partner, you can follow these steps to find a solution provider in your area:
83-
84-
1. Go to the [Browse Partners](https://appsource.microsoft.com/en-us/marketplace/partner-dir).
85-
86-
2. In the **Filters** pane, specify search criteria, such as:
87-
88-
- Your location
89-
- Your organization's size
90-
- **Focus areas**, such as **Security** and/or **Threat Protection**
91-
92-
- **Services**, such as **Licensing** or **Managed Services (MSP)**
93-
94-
As soon as you select one or more criteria, the list of partners updates.
95-
96-
3. Review the list of results. Select a provider to learn more about their expertise and the services they provide.
97-
9898
---
9999

100100
## How to get Microsoft Defender for Business servers
@@ -113,7 +113,7 @@ Microsoft Defender for Business servers is an add-on to Defender for Business th
113113
>
114114
> - In order to add on Microsoft Defender for Business servers, you'll need at least one paid license for [Defender for Business](mdb-overview.md) (standalone) or [Microsoft 365 Business Premium](/Microsoft-365/business-premium/m365bp-overview).
115115
> - There's a limit of 60 Microsoft Defender for Business servers licenses per subscription to Microsoft 365 Business Premium or Defender for Business.
116-
> - If preferred, you could use [Microsoft Defender for Servers Plan 1 or Plan 2](/azure/defender-for-cloud/plan-defender-for-servers) instead to onboard your servers. To learn more, see [What happens if I have a mix of Microsoft endpoint security subscriptions](mdb-faq.yml#what-happens-if-i-have-a-mix-of-microsoft-endpoint-security-subscriptions)?
116+
> - If preferred, you could use [Microsoft Defender for Servers Plan 1 or Plan 2](/azure/defender-for-cloud/plan-defender-for-servers) instead to onboard your servers.
117117
118118
## Portals you use for setup and management
119119

0 commit comments

Comments
 (0)