Skip to content

Commit 5ba1d54

Browse files
authored
Merge branch 'main' into link_fix
2 parents f1898de + 2c035ab commit 5ba1d54

File tree

7 files changed

+82
-71
lines changed

7 files changed

+82
-71
lines changed

defender-xdr/activate-defender-rbac.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,7 @@ search.appverid: met150
2929
- [Microsoft Defender for Office 365 P2](https://go.microsoft.com/fwlink/?LinkID=2158212)
3030
- [Microsoft Defender Vulnerability Management](/defender-vulnerability-management/defender-vulnerability-management)
3131
- [Microsoft Defender for Cloud](/azure/defender-for-cloud/defender-for-cloud-introduction)
32+
- [Microsoft Defender for Cloud Apps](/defender-cloud-apps/)
3233
- [Microsoft Security Exposure Management](/security-exposure-management/)
3334

3435
For the Microsoft Defender XDR security portal to start enforcing the permissions and assignments configured in your new [custom roles](create-custom-rbac-roles.md) or [imported roles](import-rbac-roles.md), you must activate the Microsoft Defender XDR Unified RBAC model for some or all of your workloads.

defender-xdr/investigate-users.md

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -10,16 +10,16 @@ author: diannegali
1010
manager: dansimp
1111
audience: ITPro
1212
ms.collection:
13-
- m365-security
14-
- tier2
15-
- usx-security
13+
- m365-security
14+
- tier2
15+
- usx-security
1616
ms.topic: conceptual
1717
search.appverid: met150
1818
ms.custom: seo-marvel-jun2020
19-
ms.date: 03/29/2024
19+
ms.date: 09/30/2024
2020
appliesto:
21-
- Microsoft Defender XDR
22-
- Microsoft Sentinel in the Microsoft Defender portal
21+
- Microsoft Defender XDR
22+
- Microsoft Sentinel in the Microsoft Defender portal
2323
---
2424

2525
# User entity page in Microsoft Defender
@@ -56,8 +56,10 @@ The user page shows the Microsoft Entra organization as well as groups, helping
5656

5757
### Entity details
5858

59-
The **Entity details** panel on the left side of the page provides information about the user, such as the Microsoft Entra identity risk level, the number of devices the user is signed in to, when the user was first and last seen, the user's accounts, groups that the user belongs to, contact information, and more. You see other details depending on the integration features you enabled.
59+
The **Entity details** panel on the left side of the page provides information about the user, such as the Microsoft Entra identity risk level, the insider risk severity level (Preview), the number of devices the user is signed in to, when the user was first and last seen, the user's accounts, groups that the user belongs to, contact information, and more. You see other details depending on the integration features you enabled.
6060

61+
> [!NOTE]
62+
> (Preview) Microsoft Defender XDR users with access to [Microsoft Purview Insider Risk Management](/purview/insider-risk-management-solution-overview) can now see a user's insider risk severity and gain insights on a user's suspicious activities in the user page. Select the **insider risk severity** under Entity details to see the risk insights about the user.
6163
### Visual view of incidents and alerts
6264

6365
This card includes all incidents and alerts associated with the user entity, grouped by severity.

defender-xdr/whats-new.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -97,6 +97,8 @@ You can also get product updates and important notifications through the [messag
9797

9898
## May 2024
9999

100+
- (Preview) Security analysts can now investigate a user's insider risk in the Microsoft Defender portal with **insider risk severity and insights** available for Microsoft Defender XDR users with provisioned access to Microsoft Purview Insider Risk Management. See the [entity details in the user page](investigate-users.md#entity-details) for more information.
101+
100102
- (GA) The endpoint security policies page is now available in multitenant management in Microsoft Defender XDR. Create, edit, and delete security policies for your tenants' devices from the **Endpoint security policies** page. For more information, see [Endpoint security policies in multitenant management](mto-endpoint-security-policy.md).
101103

102104
- Create alert tuning rules using **Alert severity** and **Alert title** values as conditions. Alert tuning can help you streamline the alert queue, saving triage time by hiding or resolving alerts automatically, each time a certain expected organizational behavior occurs, and rule conditions are met. For more information, see [Tune an alert](investigate-alerts.md#tune-an-alert).
811 Bytes
Loading
13.4 KB
Loading

0 commit comments

Comments
 (0)