You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/defender-experts-scoped-coverage.md
+13-16Lines changed: 13 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -34,24 +34,24 @@ Devices and users that are out of scope won't be supported by Defender Experts.
34
34
35
35
## Using Defender Experts scoped coverage
36
36
37
-
Defender Experts would create a pre-defined device and user group to which you can add devices and users which would then be considered as the set of assets that are in scope for this service.
37
+
Defender Experts create a predefined Microsoft Defender for Endpoint device group or a Microsoft Entra ID user group in the Microsoft Defender portal to which you can add devices and users, respectively. The default name assigned to the created device or user group begins with **Defender_Experts_Scoped_Coverage_**.
38
38
39
-
Currently, we do not offer support to rename this group nor have the option to support nested groups. The devices and users would have to be added individually to the groups created.
39
+
:::image type="content" source="media/defender_scoped_devices.png" alt-text="Screenshot of Defender Experts Scoped devices." lightbox="media/defender_scoped_devices.png":::
40
+
41
+
The devices and users you add to these groups are then considered as the set of assets that are in scope for this service.
40
42
41
43
> [!IMPORTANT]
44
+
> Defender Experts need **System administrator** permissions to create the device and user groups. [Learn more about granting permissions to our experts](get-started-xdr.md#grant-permissions-to-our-experts)
45
+
>
42
46
> The device group must also be in the highest order of priority for the devices under it to be considered in scope. This is a known product limitation.
43
47
44
-
To set up scoped coverage, in the Microsoft Defender XDR portal, we will create a pre-defined Microsoft Defender for Endpoint (MDE) device group or Microsoft Entra ID user group. The default name assigned to a device or user group is **Defender_Experts_Scoped_Coverage_**.
45
-
46
-
:::image type="content" source="media/defender_scoped_devices.png" alt-text="Screenshot of Defender Experts Scoped devices." lightbox="media/defender_scoped_devices.png":::
48
+
Currently, the service doesn't offer support to rename these predefined groups, so we recommend that you don't rename the created device or user group. It also doesn't support nested groups. The devices and users would have to be added individually to the groups created.
47
49
48
-
You require the **System Administrator** permissions to create such device and user groups, however it is recommended that you do not change the name of the user/device group created by Defender Experts.
50
+
The following section lists down questions that you or your SOC team might have regarding scoped coverage:
49
51
50
-
The following section lists down questions that you or your SOC team might have regarding scoped coverage.
51
-
52
-
1.**What aspects of the XDR service remain consistent with Defender Experts Scoped coverage?**
52
+
1.**What aspects of the XDR service remain consistent with Defender Experts scoped coverage?**
53
53
- This service doesn't change our pricing structure. You still pay for Defender Experts service based on E5 (and servers, Microsoft Defender for Cloud, and Open XDR) for your desired user base.
54
-
- This service doesn't scope according to individual Microsoft Defender products and services (such as Microsoft Defender for Endpoint, Microsoft Defender for Office 365, or Microsoft Defender for Cloud). That is, the minimum baseline for scoped coverage will continue to be E5 license.
54
+
- This service doesn't scope according to individual Microsoft Defender products and services (such as Defender for Endpoint, Microsoft Defender for Office 365, or Microsoft Defender for Cloud). That is, the minimum baseline for scoped coverage is still the E5 license.
55
55
- There's no change in permissions for analysts in Defender Experts for XDR. Defender Experts analysts will still have access to your entire tenant and not just the scoped assets.
56
56
57
57
2.**Can I change the scoped assets later?**
@@ -60,12 +60,9 @@ The following section lists down questions that you or your SOC team might have
60
60
61
61
3.**What type of response actions does this service provide?**
62
62
63
-
There's no changes to existing response actions that are in scope. Read our [FAQs related to Microsoft Defender Experts for XDR Managed response](../defender-xdr/frequently-asked-questions.md) to learn more.
63
+
There are no changes to existing response actions that are in scope. Read our [FAQs related to Microsoft Defender Experts for XDR Managed response](../defender-xdr/frequently-asked-questions.md) to learn more.
64
64
65
65
### See also
66
66
67
-
[Get started with Microsoft Defender Experts for XDR service](managed-detection-and-response-xdr.md)
0 commit comments