Skip to content

Commit 5e4209c

Browse files
Learn Build Service GitHub AppLearn Build Service GitHub App
authored andcommitted
Merging changes synced from https://github.com/MicrosoftDocs/defender-docs-pr (branch live)
2 parents 28064b3 + bc7c18b commit 5e4209c

22 files changed

+179
-84
lines changed

CloudAppSecurityDocs/applications-inventory.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,17 +7,17 @@ description: The new Applications page located under Assets in Microsoft Defende
77
---
88
# Applications inventory (Preview)
99

10-
Protecting your SaaS ecosystem requires taking inventory of all SaaS and OAuth connected apps that are in your environment. With the increasing number of applications, having a comprehensive inventory is crucial to ensure security and compliance. The Defender for Cloud apps Applications page provides a centralized view of all SaaS and connected OAuth apps in your organization, enabling efficient monitoring and management.
10+
Protecting your SaaS ecosystem requires taking inventory of all SaaS and connected OAuth apps that are in your environment. With the increasing number of applications, having a comprehensive inventory is crucial to ensure security and compliance. The Applications page provides a centralized view of all SaaS and connected OAuth apps in your organization, enabling efficient monitoring and management.
1111
At a glance you can see information such as app name, risk score, privilege level, publisher information, and other details for easy identification of SaaS and OAuth apps most at risk.
1212

13-
The Application page includes the following tabs:
13+
The Applications page includes the following tabs:
1414

1515
* SaaS apps: A consolidated view of all SaaS applications in your network. This tab highlights key details, including app name, status (unprotected/protected app) and whether the app is marked as sanctioned or unsanctioned.
16-
* OAuth apps: Displays a list of OAuth apps such as Microsoft Entra ID, Google workspace and Salesforce.
16+
* OAuth apps: A comprehensive view of OAuth apps registered on Microsoft Entra ID, Google workspace and Salesforce. This tab highlights OAuth apps metadata, publisher info and app origin, permissions used, data accessed and other insights.
1717

1818
## Navigate to the Applications page
1919

20-
In the Defender portal at <https://security.microsoft.com>, go to **Assets** \> **Applications**. Or, to go directly to the **Applications** page, by clicking on the banner links on the existing Cloud discovery and App governance pages.
20+
In the Defender portal at <https://security.microsoft.com>, go to **Assets** > **Applications**. Or, go directly to the **Applications** page, by clicking on the banner links on the existing Cloud discovery and App governance pages.
2121

2222
:::image type="content" source="media/banner-on-cloud-discovery-pages.png" alt-text="Screenshot of the Cloud Discovery page with a banner about the new unified application inventory experience" lightbox="media/banner-on-cloud-discovery-pages.png":::
2323

CloudAppSecurityDocs/protect-aws.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -161,8 +161,7 @@ You can connect AWS **Security auditing** to Defender for Cloud Apps connections
161161
**For an existing connector**
162162

163163
1. In the list of connectors, on the row in which the AWS connector appears, select **Edit settings**.
164-
165-
![Screenshot of the Connected Apps page, showing edit Security Auditing link.](media/aws-connect-app-edit-audit.png)
164+
166165

167166
1. On the **Instance name** and **Connect Amazon Web Services** pages, select **Next**. On the **Security auditing page**, paste the **Access key** and **Secret key** from the .csv file into the relevant fields, and select **Next**.
168167

CloudAppSecurityDocs/protect-gcp.md

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Protect your Google Cloud Platform environment | Microsoft Defender for Cloud Apps
33
description: Learn how about connecting your Google Cloud Platform app to Defender for Cloud Apps using the API connector.
4-
ms.date: 12/05/2023
4+
ms.date: 03/04/2025
55
ms.topic: how-to
66
---
77
# How Defender for Cloud Apps helps protect your Google Cloud Platform (GCP) environment
@@ -47,7 +47,8 @@ For more information about remediating threats from apps, see [Governing connect
4747

4848
## Protect GCP in real time
4949

50-
Review our best practices for [securing and collaborating with external users](best-practices.md#secure-collaboration-with-external-users-by-enforcing-real-time-session-controls) and [blocking and protecting the download of sensitive data to unmanaged or risky devices](best-practices.md#block-and-protect-download-of-sensitive-data-to-unmanaged-or-risky-devices).
50+
Review our best practices for [securing and collaborating with external users](best-practices.md#secure-collaboration-with-external-users-by-enforcing-real-time-session-controls) and [
51+
blocking and protecting the download of sensitive data to unmanaged or risky devices](best-practices.md#block-and-protect-download-of-sensitive-data-to-unmanaged-or-risky-devices).
5152

5253
## Connect Google Cloud Platform to Microsoft Defender for Cloud Apps
5354

@@ -167,8 +168,6 @@ This procedure describes how to add the GCP connection details to connect Google
167168

168169
1. In the list of connectors, on the row in which the GCP connector appears, select **Edit settings**.
169170

170-
![Screenshot of the Connected Apps page, showing edit Security Auditing link.](media/connect-gcp-app-edit-audit.png)
171-
172171
1. In the **Enter details** page, do the following, and then select **Submit**.
173172
1. In the **Organization ID** box, enter the organization you made a note of earlier.
174173
1. In the **Private key file** box, browse to the JSON file you downloaded earlier.

CloudAppSecurityDocs/protect-zoom.md

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Connect Zoom | Microsoft Defender for Cloud Apps
33
description: This article provides information about how to connect your Zoom environment to Defender for Cloud Apps using the API connector for visibility and control over use.
4-
ms.date: 06/18/2023
4+
ms.date: 03/04/2025
55
ms.topic: how-to
66
---
77

@@ -20,7 +20,7 @@ To see security posture recommendations for Zoom in Microsoft Secure Score, crea
2020
For example, recommendations for Zoom include:
2121

2222
- *Enable multi-factor authentication (MFA)*
23-
- *Enable session timeout for web users*
23+
- Enable session timeout for web users
2424
- *Enforce end to end encryption in all Zoom meetings*
2525

2626
If a connector already exists and you don't see Zoom recommendations yet, refresh the connection by disconnecting the API connector, and then reconnecting it with the `“account:read:admin`, `chat_channel:read:admin` and `user:read:admin”` permissions.
@@ -39,6 +39,11 @@ Before connecting Zoom to Defender for Cloud Apps, make sure that you have the f
3939

4040
The admin account is used only for initial consent while connecting Zoom to Defender for Cloud Apps. Defender for Cloud Apps uses an OAuth app for daily transactions.
4141

42+
>[!NOTE]
43+
> The authentication mechanism utilized in the Zoom connector doesn't support two separate connectors utilizing the same user credentials.<br>
44+
>
45+
> When a new instance with an existing authentication token is used, this revokes the old connector token and will cause a "Bad credentials" error.
46+
4247
## How to connect Zoom to Defender for Cloud Apps
4348

4449
1. Sign into Zoom as an account owner or admin.

CloudAppSecurityDocs/release-notes.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,6 @@ For news about earlier releases, see [Archive of past updates for Microsoft Defe
2222

2323
## April 2025
2424

25-
2625
### OAuthAppInfo table added to Defender XDR advanced hunting (Preview)
2726

2827
The [OAuthAppInfo](/defender-xdr/advanced-hunting-oauthappinfo-table) table is now available in Defender XDR advanced hunting, enabling security teams to explore and analyze OAuth app-related metadata with enhanced visibility.

defender-xdr/alerts-incidents-correlation.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Alert correlation and incident merging in the Microsoft Defender portal
3-
description: Learn how alerts are correlated, and how and why incidents may be merged, in the Microsoft Defender portal.
3+
description: Learn how alerts are correlated, and how and why incidents might be merged, in the Microsoft Defender portal.
44
ms.service: defender-xdr
55
f1.keywords:
66
- NOCSH
@@ -18,7 +18,7 @@ ms.topic: conceptual
1818
search.appverid:
1919
- MOE150
2020
- MET150
21-
ms.date: 02/02/2025
21+
ms.date: 03/17/2025
2222
appliesto:
2323
- Microsoft Defender XDR
2424
- Microsoft Sentinel in the Microsoft Defender portal
@@ -37,6 +37,10 @@ When alerts are generated by the various detection mechanisms in the Microsoft D
3737

3838
The criteria used by the Defender portal to correlate alerts together in a single incident are part of its proprietary, internal correlation logic. This logic is also responsible for giving an appropriate name to the new incident.
3939

40+
### Alert correlation by workspace
41+
42+
The Defender portal allows you to connect to one primary workspace and multiple secondary workspaces for Microsoft Sentinel. A primary workspace's alerts are correlated with Microsoft Defender XDR data. So, incidents include alerts from Microsoft Sentinel's primary workspace and Defender XDR in a unified queue. All other onboarded workspaces are considered secondary workspaces. For secondary workspaces, incidents are created based on the workspace’s data and won't include Defender XDR data. The Defender portal keeps incident creation and alert correlation separate between the Microsoft Sentinel workspaces. For more information, see [Multiple Microsoft Sentinel workspaces in the Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2310579).
43+
4044
### Manual correlation of alerts
4145

4246
While Microsoft Defender already uses advanced correlation mechanisms, you might want to decide differently whether a given alert belongs with a particular incident or not. In such a case, you can unlink an alert from one incident and link it to another. Every alert must belong to an incident, so you can either link the alert to another existing incident, or to a new incident that you create on the spot.

defender-xdr/prerequisites.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ ms.topic: conceptual
1616
search.appverid:
1717
- MOE150
1818
- MET150
19-
ms.date: 02/04/2025
19+
ms.date: 04/03/2025
2020
appliesto:
2121
- Microsoft Defender XDR
2222
---
@@ -52,7 +52,8 @@ Any of these licenses give you access to Microsoft Defender XDR features via the
5252
For more information, [view the Microsoft 365 Enterprise service plans](https://www.microsoft.com/licensing/product-licensing/microsoft-365-enterprise).
5353

5454
> [!NOTE]
55-
> Automatic attack disruption requires Microsoft Defender for Endpoint Plan 2. For more information, see [Configure automatic attack disruption capabilities](configure-attack-disruption.md).
55+
> - Automatic attack disruption requires Microsoft Defender for Endpoint Plan 2. For more information, see [Configure automatic attack disruption capabilities](configure-attack-disruption.md).
56+
> - Threat analytics also requires Defender for Endpoint Plan 2. For more information, see [Threat analytics in Microsoft Defender XDR](threat-analytics.md).
5657
5758
> Don't have license yet? [Try or buy a Microsoft 365 subscription](/microsoft-365/commerce/try-or-buy-microsoft-365)
5859
314 KB
Loading
145 KB
Loading
183 KB
Loading

0 commit comments

Comments
 (0)