Skip to content

Commit 58a1a1f

Browse files
committed
Merge branch 'dex-scoped-coverage' of https://github.com/MicrosoftDocs/defender-docs-pr into dex-scoped-coverage
2 parents c47d32f + b53bb0c commit 58a1a1f

File tree

3 files changed

+17
-20
lines changed

3 files changed

+17
-20
lines changed

defender-xdr/TOC.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -430,16 +430,16 @@
430430
items:
431431
- name: Managed detection and response
432432
href: managed-detection-and-response-xdr.md
433-
- name: Reports
434-
href: reports-xdr.md
433+
- name: Scoped coverage
434+
href: defender-experts-scoped-coverage.md
435435
- name: Communicate with Defender Experts for XDR
436436
href: communicate-defender-experts-xdr.md
437+
- name: Reports
438+
href: reports-xdr.md
437439
- name: Defender Experts for Hunting
438440
href: defender-experts-for-hunting.md
439441
- name: Auditing
440442
href: auditing.md
441-
- name: Defender Experts Scoped coverage
442-
href: defender-experts-scoped-coverage.md
443443
- name: Frequently asked questions
444444
items:
445445
- name: General information

defender-xdr/defender-experts-scoped-coverage.md

Lines changed: 13 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -34,24 +34,24 @@ Devices and users that are out of scope won't be supported by Defender Experts.
3434

3535
## Using Defender Experts scoped coverage
3636

37-
Defender Experts would create a pre-defined device and user group to which you can add devices and users which would then be considered as the set of assets that are in scope for this service.
37+
Defender Experts create a predefined Microsoft Defender for Endpoint device group or a Microsoft Entra ID user group in the Microsoft Defender portal to which you can add devices and users, respectively. The default name assigned to the created device or user group begins with **Defender_Experts_Scoped_Coverage_**.
3838

39-
Currently, we do not offer support to rename this group nor have the option to support nested groups. The devices and users would have to be added individually to the groups created.
39+
:::image type="content" source="media/defender_scoped_devices.png" alt-text="Screenshot of Defender Experts Scoped devices." lightbox="media/defender_scoped_devices.png":::
40+
41+
The devices and users you add to these groups are then considered as the set of assets that are in scope for this service.
4042

4143
> [!IMPORTANT]
44+
> Defender Experts need **System administrator** permissions to create the device and user groups. [Learn more about granting permissions to our experts](get-started-xdr.md#grant-permissions-to-our-experts)
45+
>
4246
> The device group must also be in the highest order of priority for the devices under it to be considered in scope. This is a known product limitation.
4347
44-
To set up scoped coverage, in the Microsoft Defender XDR portal, we will create a pre-defined Microsoft Defender for Endpoint (MDE) device group or Microsoft Entra ID user group. The default name assigned to a device or user group is **Defender_Experts_Scoped_Coverage_**.
45-
46-
:::image type="content" source="media/defender_scoped_devices.png" alt-text="Screenshot of Defender Experts Scoped devices." lightbox="media/defender_scoped_devices.png":::
48+
Currently, the service doesn't offer support to rename these predefined groups, so we recommend that you don't rename the created device or user group. It also doesn't support nested groups. The devices and users would have to be added individually to the groups created.
4749

48-
You require the **System Administrator** permissions to create such device and user groups, however it is recommended that you do not change the name of the user/device group created by Defender Experts.
50+
The following section lists down questions that you or your SOC team might have regarding scoped coverage:
4951

50-
The following section lists down questions that you or your SOC team might have regarding scoped coverage.
51-
52-
1. **What aspects of the XDR service remain consistent with Defender Experts Scoped coverage?**
52+
1. **What aspects of the XDR service remain consistent with Defender Experts scoped coverage?**
5353
- This service doesn't change our pricing structure. You still pay for Defender Experts service based on E5 (and servers, Microsoft Defender for Cloud, and Open XDR) for your desired user base.
54-
- This service doesn't scope according to individual Microsoft Defender products and services (such as Microsoft Defender for Endpoint, Microsoft Defender for Office 365, or Microsoft Defender for Cloud). That is, the minimum baseline for scoped coverage will continue to be E5 license.
54+
- This service doesn't scope according to individual Microsoft Defender products and services (such as Defender for Endpoint, Microsoft Defender for Office 365, or Microsoft Defender for Cloud). That is, the minimum baseline for scoped coverage is still the E5 license.
5555
- There's no change in permissions for analysts in Defender Experts for XDR. Defender Experts analysts will still have access to your entire tenant and not just the scoped assets.
5656

5757
2. **Can I change the scoped assets later?**
@@ -60,12 +60,9 @@ The following section lists down questions that you or your SOC team might have
6060

6161
3. **What type of response actions does this service provide?**
6262

63-
There's no changes to existing response actions that are in scope. Read our [FAQs related to Microsoft Defender Experts for XDR Managed response](../defender-xdr/frequently-asked-questions.md) to learn more.
63+
There are no changes to existing response actions that are in scope. Read our [FAQs related to Microsoft Defender Experts for XDR Managed response](../defender-xdr/frequently-asked-questions.md) to learn more.
6464

6565
### See also
6666

67-
[Get started with Microsoft Defender Experts for XDR service](managed-detection-and-response-xdr.md)
68-
69-
### Next step
70-
71-
[Frequently asked questions](faq-incident-notifications-xdr.md)
67+
- [Get started with Microsoft Defender Experts for XDR service](managed-detection-and-response-xdr.md)
68+
- [Understanding and managing Defender Experts for XDR incident updates](faq-incident-notifications-xdr.md)

defender-xdr/dex-scoped-coverage.md

Whitespace-only changes.

0 commit comments

Comments
 (0)