You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Advanced hunting in multi-tenant management in Microsoft Defender XDR allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time.
25
+
Advanced hunting in Microsoft Defender multitenant management allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time. If you have tenants with a Microsoft Sentinel workspace onboarded to the Microsoft unified security operations platform, search for security information and event management (SIEM) data together with extended detection and response (XDR) data across multiple tenants.
26
26
27
27
## Run cross-tenant queries
28
28
29
-
In multi-tenant management, you can use any of the queries you currently have access to. They're filtered by tenant in the **Queries** tab. Select a tenant to view the queries available under each one.
29
+
In multitenant management, you can use any of the queries you currently have access to. They're filtered by tenant in the **Queries** tab. Select a tenant to view the queries available under each one.
30
30
31
31
Once you load the query in the query editor, you can then specify the scope of the query by tenant by selecting **Tenant scope**:
32
32
@@ -50,7 +50,7 @@ Likewise, you can manage custom detection rules from multiple tenants in the cus
50
50
51
51
### View custom detection rules by tenant
52
52
53
-
1. To view custom detection rules, go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multi-tenant management in Microsoft Defender XDR.
53
+
1. To view custom detection rules, go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in Microsoft Defender multitenant management.
54
54
2. View the **Tenant name** column to see which tenant the detection rule comes from:
55
55
56
56
:::image type="content" source="/defender/media/defender/mto-custom-detection-tenant-name.png" alt-text="Screenshot of the Microsoft Defender XDR multi-tenant custom detection page" lightbox="/defender/media/defender/mto-custom-detection-tenant-name.png":::
@@ -61,15 +61,21 @@ To read more about custom detection rules, read [Custom detections overview](cus
61
61
62
62
### Manage custom detection rules
63
63
64
-
You can **Run**, **Turn off**, and **Delete** detection rules from multi-tenant management in Microsoft Defender XDR.
64
+
You can **Run**, **Turn off**, and **Delete** detection rules from Microsoft Defender multitenant management.
65
65
66
66
To manage detection rules:
67
67
68
-
1. Go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multi-tenant management in Microsoft Defender XDR
68
+
1. Go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in Microsoft Defender multitenant management
69
69
2. Choose the detection rule you want to manage
70
70
71
71
When you select a single detection rule, a flyout panel opens with the detection rule details:
72
72
73
73
:::image type="content" source="/defender/media/defender/custom-detection-rule-details.png" alt-text="Screenshot of the Microsoft Defender XDR custom detection rule details page" lightbox="/defender/media/defender/custom-detection-rule-details.png":::
74
74
75
75
Select **Open detection rules** to view this rule in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com). To learn more, see [Custom detection rules](./custom-detection-rules.md).
76
+
77
+
## Related content
78
+
79
+
-[Set up Microsoft Defender multitenant management](mto-requirements.md)
80
+
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
81
+
-[View and manage incidents and alerts](mto-incidents-alerts.md)
title: View and manage incidents and alerts in multi-tenant management in Microsoft Defender XDR
3
-
description: Learn about incidents and alerts in multi-tenant management in Microsoft Defender XDR
2
+
title: View and manage incidents and alerts in Microsoft Defender multitenant management
3
+
description: Learn about incidents and alerts in Microsoft Defender multitenant management
4
4
search.appverid: met150
5
5
ms.service: defender-xdr
6
6
ms.author: siosulli
@@ -12,29 +12,31 @@ ms.collection:
12
12
- m365-security
13
13
- highpri
14
14
- tier1
15
+
- usx-security
15
16
ms.topic: conceptual
16
-
ms.date: 09/01/2023
17
+
ms.date: 08/19/2024
18
+
appliesto:
19
+
- Microsoft Defender XDR
20
+
- Microsoft Sentinel in the Microsoft Defender portal
17
21
---
18
22
19
-
# View and manage incidents and alerts
23
+
# View and manage incidents and alerts in Microsoft Defender multitenant management
20
24
21
-
**Applies to:**
25
+
Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats. Triage incidents and alerts across security information and event management (SIEM) and extended detection and response (XDR) data for tenants that onboarded a Microsoft Sentinel workspace to the unified security operations platform.
Multi-tenant management in Microsoft Defender XDR enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats.
26
-
27
-
You can manage incidents & alerts originating from multiple tenants under **Incidents & alerts**.
27
+
Manage incidents & alerts originating from multiple tenants under **Incidents & alerts**.
28
28
29
29
## View and investigate incidents
30
30
31
-
1.To View or investigate an incident, go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management in Microsoft Defender XDR. The **Tenant name** column shows which tenant the incident originates from:
31
+
To view or investigate an incident:
32
32
33
-
:::image type="content" source="/defender/media/defender/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender XDR multi-tenant incidents page" lightbox="/defender/media/defender/mto-incidents.png":::
33
+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in Microsoft Defender multitenant management. The **Tenant name** column shows which tenant the incident originates from:
34
+
35
+
:::image type="content" source="/defender/media/defender/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender multitenant incidents page." lightbox="/defender/media/defender/mto-incidents.png":::
34
36
35
37
2. Select the incident you want to view. A flyout panel opens with the incident details page:
36
38
37
-
:::image type="content" source="/defender/media/defender/mto-incident-details.png" alt-text="Screenshot of the Microsoft Defender XDR incidents details page" lightbox="/defender/media/defender/mto-incident-details.png":::
39
+
:::image type="content" source="/defender/media/defender/mto-incident-details.png" alt-text="Screenshot of the Microsoft Defender multitenant incidents details page." lightbox="/defender/media/defender/mto-incident-details.png":::
38
40
39
41
3. From the incident details page you can:
40
42
@@ -47,10 +49,10 @@ To learn more, see [Investigate incidents](/defender-endpoint/investigate-incide
47
49
48
50
To manage incidents across multiple tenants:
49
51
50
-
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management.
52
+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in Microsoft Defender multitenant management.
51
53
2. Choose the incidents you want to manage from the incidents list and select **Manage incidents**.
52
54
53
-
:::image type="content" source="/defender/media/defender/mto-manage-incidents.png" alt-text="Screenshot of the Microsoft Defender XDR incidents page" lightbox="/defender/media/defender/mto-manage-incidents.png":::
55
+
:::image type="content" source="/defender/media/defender/mto-manage-incidents.png" alt-text="Screenshot that highlights the manage incidents option on the incidents page in Microsoft Defender multitenant management." lightbox="/defender/media/defender/mto-manage-incidents.png":::
54
56
55
57
On the incidents fly-out you can assign incidents, assign incidents tags, set the incident status, and classify multiple incidents for multiple tenants simultaneously.
56
58
@@ -61,9 +63,11 @@ To learn more about incidents in the Microsoft Defender portal, see [Manage inci
61
63
62
64
## View and investigate alerts
63
65
64
-
1. To view or investigate an alert, go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management and select the alert you want to view. A flyout panel opens with the alert details page:
66
+
To view or investigate an alert:
67
+
68
+
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multitenant management and select the alert you want to view. A flyout panel opens with the alert details page:
65
69
66
-
:::image type="content" source="/defender/media/defender/mto-alerts-details.png" alt-text="Screenshot of the Microsoft Defender XDR alert details page" lightbox="/defender/media/defender/mto-alerts-details.png":::
70
+
:::image type="content" source="/defender/media/defender/mto-alerts-details.png" alt-text="Screenshot of alert details page for an alert in Microsoft Defender multitenant management." lightbox="/defender/media/defender/mto-alerts-details.png":::
67
71
68
72
2. From the alert details page you can:
69
73
@@ -76,13 +80,20 @@ To learn more, see [Investigate alerts](/defender-endpoint/investigate-alerts).
76
80
77
81
To manage alerts across multiple tenants:
78
82
79
-
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management.
83
+
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in Microsoft Defender multitenant management.
80
84
2. Choose the alerts you want to manage from the alerts list and select **Manage alerts**.
81
85
82
-
:::image type="content" source="/defender/media/defender/mto-manage-alerts.png" alt-text="Screenshot of the Microsoft Defender XDR alerts page" lightbox="/defender/media/defender/mto-manage-alerts.png":::
86
+
:::image type="content" source="/defender/media/defender/mto-manage-alerts.png" alt-text="Screenshot that highlights the manage alerts option for selected alerts in Microsoft Defender multitenant management." lightbox="/defender/media/defender/mto-manage-alerts.png":::
83
87
84
88
On the alert fly-out you can assign alerts, set the alert status, and classify the alerts for multiple tenants simultaneously.
85
89
86
90
> [!Note]
87
91
> Currently, you can only assign multiple alerts from same tenant.
88
92
To learn more about alerts in the Microsoft Defender portal, see [Manage alerts](/defender-endpoint/manage-alerts).
93
+
94
+
## Related content
95
+
96
+
-[Set up Microsoft Defender multitenant management](mto-requirements.md)
97
+
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
98
+
-[Advanced hunting in Microsoft Defender multitenant management](mto-advanced-hunting.md)
title: Multi-tenant management in Microsoft Defender XDR
3
-
description: Overview of multi-tenant management in Microsoft Defender XDR.
2
+
title: Microsoft Defender multitenant management
3
+
description: Learn about multitenant management for Microsoft Defender XDR and Microsoft Sentinel in the Microsoft unified security operations platform.
4
4
ms.service: defender-xdr
5
5
ms.author: siosulli
6
6
author: siosulli
@@ -11,41 +11,48 @@ ms.collection:
11
11
- m365-security
12
12
- highpri
13
13
- tier1
14
+
- usx-security
14
15
ms.topic: conceptual
15
-
ms.date: 09/01/2023
16
+
ms.date: 08/19/2024
17
+
appliesto:
18
+
- Microsoft Defender XDR
19
+
- Microsoft Sentinel in the Microsoft Defender portal
20
+
- Microsoft Defender for Endpoint Plan 2
21
+
- Microsoft Defender for Office 365 P2
16
22
---
17
23
18
-
# Overview of multi-tenant management in Microsoft Defender XDR
24
+
# Microsoft Defender multitenant management
19
25
20
-
**Applies to:**
26
+
Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform provides your security operation teams with a single, unified view of all the tenants you manage. This view enables your teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving your security operations.
-[Microsoft Defender for Endpoint Plan 2](/defender-endpoint/microsoft-defender-endpoint)
24
-
-[Microsoft Defender for Office 365 P2](https://go.microsoft.com/fwlink/p/?LinkID=2158212)
28
+
If you have tenants with a Microsoft Sentinel workspace onboarded to the unified security operations platform, you're able to:
25
29
26
-
>[!Tip]
27
-
>To learn how to turn on preview features, see [Microsoft Defender XDR preview features](preview.md).
30
+
- Triage incidents and alerts across security information and event management (SIEM) and extended detection and response (XDR) data.
31
+
- Proactively search for SIEM and XDR data across multiple tenants.
28
32
29
-
Managing multi-tenant environments can add an additional layer of complexity when it comes to keeping up with the ever-evolving security threats facing your enterprise. Navigating across multiple tenants can be time consuming and reduce the overall efficiency of security operation center (SOC) teams.
33
+
Only one Microsoft Sentinel workspace per tenant is currently supported in the unified security operations platform. So in Microsoft Defender multitenant management, you have SIEM data from one Microsoft Sentinel workspace per tenant.
30
34
31
-
Multi-tenant management in Microsoft Defender XDR was designed to provide security operation teams with a single, unified view of all the tenants they manage. This view enables teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving their security operations.
35
+
For more information, see:
32
36
33
-
>[!Tip]
34
-
>To learn more about multi-tenant organizations, see [Multi-tenant organizations documentation](/azure/active-directory/multi-tenant-organizations/).
37
+
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
Some of the key benefits you get with multi-tenant management in Microsoft Defender XDR include:
37
40
38
-
-**A centralized place to manage incidents across tenants**: A unified view provides SOC analysts with all the information they need for incident investigation across multiple tenants, eliminating the need to sign in and out of each one.
41
+
## Benefits of multitenant management
39
42
40
-
-**Streamlined threat hunting**: Multi-tenancy support enables SOC teams use Microsoft Defender XDR advanced hunting capabilities to create KQL queries that will proactively hunt for threats across multiple tenants.
43
+
Some of the key benefits you get with multitenant management for Defender XDR and the Microsoft unified security operations platform include:
44
+
45
+
-**A centralized place to manage incidents across tenants**: A unified view provides SOC analysts with all the information they need to investigate incidents across multiple tenants, eliminating the need to sign in and out of each one.
46
+
47
+
-**Streamlined threat hunting**: Multi-tenancy support enables SOC teams use Microsoft Defender XDR advanced hunting capabilities to create Kusto Query Language (KQL) queries that proactively hunt for threats across multiple tenants.
41
48
42
49
-**Multi-customer management for partners**: Managed Security Service Provider (MSSP) partners can now gain visibility into security incidents, alerts, and threat hunting across multiple customers through a single pane of glass.
## What's included in multi-tenant management in Microsoft Defender XDR
53
+
## What's included in multitenant management
47
54
48
-
The following key capabilities are available for each tenant you have access to in multi-tenant management in Microsoft Defender XDR:
55
+
The following key capabilities are available for each tenant you have access to in multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform:
49
56
50
57
| Capability | Description |
51
58
| ------ | ------ |
@@ -60,4 +67,4 @@ The following key capabilities are available for each tenant you have access to
60
67
61
68
## Next steps
62
69
63
-
-[Set up multi-tenant management in Microsoft Defender XDR](mto-requirements.md)
70
+
-[Set up Microsoft Defender multitenant management](mto-requirements.md)
0 commit comments