Skip to content

Commit 5fd78d6

Browse files
authored
Merge pull request #2223 from MicrosoftDocs/dex-scoped-coverage
Dex scoped coverage
2 parents e56824d + 08e6c67 commit 5fd78d6

File tree

4 files changed

+74
-3
lines changed

4 files changed

+74
-3
lines changed

defender-xdr/TOC.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -430,10 +430,12 @@
430430
items:
431431
- name: Managed detection and response
432432
href: managed-detection-and-response-xdr.md
433-
- name: Reports
434-
href: reports-xdr.md
433+
- name: Scoped coverage
434+
href: defender-experts-scoped-coverage.md
435435
- name: Communicate with Defender Experts for XDR
436436
href: communicate-defender-experts-xdr.md
437+
- name: Reports
438+
href: reports-xdr.md
437439
- name: Defender Experts for Hunting
438440
href: defender-experts-for-hunting.md
439441
- name: Auditing
Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
---
2+
title: Scoped coverage in Microsoft Defender Experts for XDR
3+
ms.reviewer:
4+
description: Defender Experts scoped coverage covers a specific section of the organization where SOC support is limited.
5+
ms.service: defender-experts
6+
ms.subservice: dex-xdr
7+
ms.author: vpattnaik
8+
author: vpattnai
9+
ms.localizationpriority: medium
10+
manager: dansimp
11+
audience: ITPro
12+
ms.collection:
13+
- m365-security
14+
- tier1
15+
ms.topic: conceptual
16+
ms.custom:
17+
- cx-ti
18+
- cx-dex
19+
search.appverid: met150
20+
ms.date: 12/19/2024
21+
---
22+
23+
# Scoped coverage in Microsoft Defender Experts for XDR
24+
25+
**Applies to:**
26+
27+
- [Microsoft Defender XDR](microsoft-365-defender.md)
28+
29+
Microsoft Defender Experts for XDR offers scoped coverage for customers who wish to have Defender Experts cover only a section of their organization (for example, specific geography, subsidiary, or function) that requires security operations center (SOC) support or where their security support is limited.
30+
31+
You can define a specific set of devices and/or users for which Defender Experts will offer support. Any incident that impacts any of the defined set of devices and users will be considered in scope, and our experts will provide the necessary response actions to mitigate the threat.
32+
33+
Devices and users that are out of scope won't be supported by Defender Experts. If they're part of an incident where at least one device or user in scope is impacted, we'll keep you informed about the out-of-scope assets but won't take any response actions or offer guidance.
34+
35+
## Using Defender Experts scoped coverage
36+
37+
Defender Experts create a predefined Microsoft Defender for Endpoint device group or a Microsoft Entra ID user group in the Microsoft Defender portal to which you can add devices and users, respectively. The default name assigned to the created device or user group begins with **Defender_Experts_Scoped_Coverage_**.
38+
39+
:::image type="content" source="media/defender_scoped_devices.png" alt-text="Screenshot of Defender Experts Scoped devices." lightbox="media/defender_scoped_devices.png":::
40+
41+
The devices and users you add to these groups are then considered as the set of assets that are in scope for this service.
42+
43+
> [!IMPORTANT]
44+
> Defender Experts need **System administrator** permissions to create the device and user groups. [Learn more about granting permissions to our experts](get-started-xdr.md#grant-permissions-to-our-experts)
45+
>
46+
> The device group must also be in the highest order of priority for the devices under it to be considered in scope. This is a known product limitation.
47+
48+
Currently, the service doesn't offer support to rename these predefined groups, so we recommend that you don't rename the created device or user group. It also doesn't support nested groups. The devices and users would have to be added individually to the groups created.
49+
50+
The following section lists down questions that you or your SOC team might have regarding scoped coverage:
51+
52+
1. **What aspects of the XDR service remain consistent with Defender Experts scoped coverage?**
53+
- This service doesn't change our pricing structure. You still pay for Defender Experts service based on E5 (and servers, Microsoft Defender for Cloud, and Open XDR) for your desired user base.
54+
- This service doesn't scope according to individual Microsoft Defender products and services (such as Defender for Endpoint, Microsoft Defender for Office 365, or Microsoft Defender for Cloud). That is, the minimum baseline for scoped coverage is still the E5 license.
55+
- There's no change in permissions for analysts in Defender Experts for XDR. Defender Experts analysts will still have access to your entire tenant and not just the scoped assets.
56+
57+
2. **Can I change the scoped assets later?**
58+
59+
You're allowed to change the scoped assets based on your needs. Keep in mind that the changes you make might take some time to take effect in our service. We recommend that you take into account your organization's rhythm of business for incidents before and after the changes are made.
60+
61+
3. **What type of response actions does this service provide?**
62+
63+
There are no changes to existing response actions that are in scope. Read our [FAQs related to Microsoft Defender Experts for XDR Managed response](../defender-xdr/frequently-asked-questions.md) to learn more.
64+
65+
### See also
66+
67+
- [Get started with Microsoft Defender Experts for XDR service](managed-detection-and-response-xdr.md)
68+
- [Understanding and managing Defender Experts for XDR incident updates](faq-incident-notifications-xdr.md)
262 KB
Loading

defender-xdr/whats-new.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,9 +32,10 @@ You can also get product updates and important notifications through the [messag
3232

3333
## December 2024
3434

35+
- Microsoft Defender Experts for XDR now offers [scoped coverage](defender-experts-scoped-coverage.md) for customers who wish to define a specific set of devices and/or users, based on geography, subsidiary, or function, for which they'd like Defender Experts to provide support.
3536
- (Preview) The [Link to incident](advanced-hunting-defender-results.md#link-query-results-to-an-incident) feature in Microsoft Defender advanced hunting now allows linking of Microsoft Sentinel query results. In both the Microsoft Defender unified experience and in [Defender XDR advanced hunting](advanced-hunting-link-to-incident.md), you can now specify whether an entity is an impacted asset or related evidence.
3637
- (Preview) In [advanced hunting](advanced-hunting-defender-use-custom-rules.md#use-adx-operator-for-azure-data-explorer-queries-preview), Microsoft Defender portal users can now use the `adx()` operator to query tables stored in Azure Data Explorer. You no longer need to go to log analytics in Microsoft Sentinel to use this operator if you are already in Microsoft Defender.
37-
- New documentation library for Microsoft's unified security operations platform. Find centralized documentation about [Microsoft's unified SecOps platform in the Microsoft Defender portal](/unified-secops-platform/overview-unified-security). Microsoft's unified SecOps platform brings together the full capabilities of Microsoft Sentinel, Microsoft Defender XDR, Microsoft Security Exposure Management, and generative AI into the Defender portal. Learn about the features and functionality available with Microsoft's unified SecOps platform, then start to plan your deployment.
38+
- New documentation library for Microsoft's unified security operations platform. Find centralized documentation about [Microsoft's unified SecOps platform in the Microsoft Defender portal](/unified-secops-platform/overview-unified-security). Microsoft's unified SecOps platform brings together the full capabilities of Microsoft Sentinel, Microsoft Defender XDR, Microsoft Security Exposure Management, and generative AI into the Defender portal. Learn about the features and functionality available with Microsoft's unified SecOps platform, then start to plan your deployment.
3839

3940
## November 2024
4041

0 commit comments

Comments
 (0)