Skip to content

Commit 6073bc0

Browse files
authored
Merge pull request #1096 from cwatson-cat/8-7-24-mlti-ten-sent
Defender XDR - Add in MTM for tenants w/ Sentinel onboarded to USX [READY FOR MERGE]
2 parents 08ba8f7 + a854568 commit 6073bc0

File tree

8 files changed

+121
-91
lines changed

8 files changed

+121
-91
lines changed

defender-xdr/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -483,7 +483,7 @@
483483
href: https://aka.ms/soc-opt-ref
484484
- name: Manage multitenant environments
485485
items:
486-
- name: Multitenant management in Microsoft Defender XDR
486+
- name: Overview
487487
href: mto-overview.md
488488
- name: Set up multitenant management
489489
href: mto-requirements.md

defender-xdr/mto-advanced-hunting.md

Lines changed: 19 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Advanced hunting in multi-tenant management in Microsoft Defender XDR
3-
description: Learn about advanced hunting in multi-tenant management in Microsoft Defender XDR
2+
title: Advanced hunting in Microsoft Defender multitenant management
3+
description: Learn about advanced hunting in Microsoft Defender multitenant management
44
search.appverid: met150
55
ms.service: defender-xdr
66
ms.author: siosulli
@@ -12,21 +12,21 @@ ms.collection:
1212
- m365-security
1313
- highpri
1414
- tier1
15+
- usx-security
1516
ms.topic: conceptual
16-
ms.date: 07/18/2024
17+
ms.date: 08/19/2024
18+
appliesto:
19+
- Microsoft Defender XDR
20+
- Microsoft Sentinel in the Microsoft Defender portal
1721
---
1822

19-
# Advanced hunting in multi-tenant management in Microsoft Defender XDR
23+
# Advanced hunting in Microsoft Defender multitenant management
2024

21-
**Applies to:**
22-
23-
- [Microsoft Defender XDR](microsoft-365-defender.md)
24-
25-
Advanced hunting in multi-tenant management in Microsoft Defender XDR allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time.
25+
Advanced hunting in Microsoft Defender multitenant management allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time. If you have tenants with a Microsoft Sentinel workspace onboarded to the Microsoft unified security operations platform, search for security information and event management (SIEM) data together with extended detection and response (XDR) data across multiple tenants.
2626

2727
## Run cross-tenant queries
2828

29-
In multi-tenant management, you can use any of the queries you currently have access to. They're filtered by tenant in the **Queries** tab. Select a tenant to view the queries available under each one.
29+
In multitenant management, you can use any of the queries you currently have access to. They're filtered by tenant in the **Queries** tab. Select a tenant to view the queries available under each one.
3030

3131
Once you load the query in the query editor, you can then specify the scope of the query by tenant by selecting **Tenant scope**:
3232

@@ -50,7 +50,7 @@ Likewise, you can manage custom detection rules from multiple tenants in the cus
5050

5151
### View custom detection rules by tenant
5252

53-
1. To view custom detection rules, go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multi-tenant management in Microsoft Defender XDR.
53+
1. To view custom detection rules, go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in Microsoft Defender multitenant management.
5454
2. View the **Tenant name** column to see which tenant the detection rule comes from:
5555

5656
:::image type="content" source="/defender/media/defender/mto-custom-detection-tenant-name.png" alt-text="Screenshot of the Microsoft Defender XDR multi-tenant custom detection page" lightbox="/defender/media/defender/mto-custom-detection-tenant-name.png":::
@@ -61,15 +61,21 @@ To read more about custom detection rules, read [Custom detections overview](cus
6161

6262
### Manage custom detection rules
6363

64-
You can **Run**, **Turn off**, and **Delete** detection rules from multi-tenant management in Microsoft Defender XDR.
64+
You can **Run**, **Turn off**, and **Delete** detection rules from Microsoft Defender multitenant management.
6565

6666
To manage detection rules:
6767

68-
1. Go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multi-tenant management in Microsoft Defender XDR
68+
1. Go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in Microsoft Defender multitenant management
6969
2. Choose the detection rule you want to manage
7070

7171
When you select a single detection rule, a flyout panel opens with the detection rule details:
7272

7373
:::image type="content" source="/defender/media/defender/custom-detection-rule-details.png" alt-text="Screenshot of the Microsoft Defender XDR custom detection rule details page" lightbox="/defender/media/defender/custom-detection-rule-details.png":::
7474

7575
Select **Open detection rules** to view this rule in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com). To learn more, see [Custom detection rules](./custom-detection-rules.md).
76+
77+
## Related content
78+
79+
- [Set up Microsoft Defender multitenant management](mto-requirements.md)
80+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
81+
- [View and manage incidents and alerts](mto-incidents-alerts.md)
Lines changed: 30 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: View and manage incidents and alerts in multi-tenant management in Microsoft Defender XDR
3-
description: Learn about incidents and alerts in multi-tenant management in Microsoft Defender XDR
2+
title: View and manage incidents and alerts in Microsoft Defender multitenant management
3+
description: Learn about incidents and alerts in Microsoft Defender multitenant management
44
search.appverid: met150
55
ms.service: defender-xdr
66
ms.author: siosulli
@@ -12,29 +12,31 @@ ms.collection:
1212
- m365-security
1313
- highpri
1414
- tier1
15+
- usx-security
1516
ms.topic: conceptual
16-
ms.date: 09/01/2023
17+
ms.date: 08/19/2024
18+
appliesto:
19+
- Microsoft Defender XDR
20+
- Microsoft Sentinel in the Microsoft Defender portal
1721
---
1822

19-
# View and manage incidents and alerts
23+
# View and manage incidents and alerts in Microsoft Defender multitenant management
2024

21-
**Applies to:**
25+
Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats. Triage incidents and alerts across security information and event management (SIEM) and extended detection and response (XDR) data for tenants that onboarded a Microsoft Sentinel workspace to the unified security operations platform.
2226

23-
- [Microsoft Defender XDR](microsoft-365-defender.md)
24-
25-
Multi-tenant management in Microsoft Defender XDR enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats.
26-
27-
You can manage incidents & alerts originating from multiple tenants under **Incidents & alerts**.
27+
Manage incidents & alerts originating from multiple tenants under **Incidents & alerts**.
2828

2929
## View and investigate incidents
3030

31-
1. To View or investigate an incident, go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management in Microsoft Defender XDR. The **Tenant name** column shows which tenant the incident originates from:
31+
To view or investigate an incident:
3232

33-
:::image type="content" source="/defender/media/defender/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender XDR multi-tenant incidents page" lightbox="/defender/media/defender/mto-incidents.png":::
33+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in Microsoft Defender multitenant management. The **Tenant name** column shows which tenant the incident originates from:
34+
35+
:::image type="content" source="/defender/media/defender/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender multitenant incidents page." lightbox="/defender/media/defender/mto-incidents.png":::
3436

3537
2. Select the incident you want to view. A flyout panel opens with the incident details page:
3638

37-
:::image type="content" source="/defender/media/defender/mto-incident-details.png" alt-text="Screenshot of the Microsoft Defender XDR incidents details page" lightbox="/defender/media/defender/mto-incident-details.png":::
39+
:::image type="content" source="/defender/media/defender/mto-incident-details.png" alt-text="Screenshot of the Microsoft Defender multitenant incidents details page." lightbox="/defender/media/defender/mto-incident-details.png":::
3840

3941
3. From the incident details page you can:
4042

@@ -47,10 +49,10 @@ To learn more, see [Investigate incidents](/defender-endpoint/investigate-incide
4749

4850
To manage incidents across multiple tenants:
4951

50-
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management.
52+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in Microsoft Defender multitenant management.
5153
2. Choose the incidents you want to manage from the incidents list and select **Manage incidents**.
5254

53-
:::image type="content" source="/defender/media/defender/mto-manage-incidents.png" alt-text="Screenshot of the Microsoft Defender XDR incidents page" lightbox="/defender/media/defender/mto-manage-incidents.png":::
55+
:::image type="content" source="/defender/media/defender/mto-manage-incidents.png" alt-text="Screenshot that highlights the manage incidents option on the incidents page in Microsoft Defender multitenant management." lightbox="/defender/media/defender/mto-manage-incidents.png":::
5456

5557
On the incidents fly-out you can assign incidents, assign incidents tags, set the incident status, and classify multiple incidents for multiple tenants simultaneously.
5658

@@ -61,9 +63,11 @@ To learn more about incidents in the Microsoft Defender portal, see [Manage inci
6163

6264
## View and investigate alerts
6365

64-
1. To view or investigate an alert, go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management and select the alert you want to view. A flyout panel opens with the alert details page:
66+
To view or investigate an alert:
67+
68+
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multitenant management and select the alert you want to view. A flyout panel opens with the alert details page:
6569

66-
:::image type="content" source="/defender/media/defender/mto-alerts-details.png" alt-text="Screenshot of the Microsoft Defender XDR alert details page" lightbox="/defender/media/defender/mto-alerts-details.png":::
70+
:::image type="content" source="/defender/media/defender/mto-alerts-details.png" alt-text="Screenshot of alert details page for an alert in Microsoft Defender multitenant management." lightbox="/defender/media/defender/mto-alerts-details.png":::
6771

6872
2. From the alert details page you can:
6973

@@ -76,13 +80,20 @@ To learn more, see [Investigate alerts](/defender-endpoint/investigate-alerts).
7680

7781
To manage alerts across multiple tenants:
7882

79-
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management.
83+
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in Microsoft Defender multitenant management.
8084
2. Choose the alerts you want to manage from the alerts list and select **Manage alerts**.
8185

82-
:::image type="content" source="/defender/media/defender/mto-manage-alerts.png" alt-text="Screenshot of the Microsoft Defender XDR alerts page" lightbox="/defender/media/defender/mto-manage-alerts.png":::
86+
:::image type="content" source="/defender/media/defender/mto-manage-alerts.png" alt-text="Screenshot that highlights the manage alerts option for selected alerts in Microsoft Defender multitenant management." lightbox="/defender/media/defender/mto-manage-alerts.png":::
8387

8488
On the alert fly-out you can assign alerts, set the alert status, and classify the alerts for multiple tenants simultaneously.
8589

8690
> [!Note]
8791
> Currently, you can only assign multiple alerts from same tenant.
8892
To learn more about alerts in the Microsoft Defender portal, see [Manage alerts](/defender-endpoint/manage-alerts).
93+
94+
## Related content
95+
96+
- [Set up Microsoft Defender multitenant management](mto-requirements.md)
97+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
98+
- [Advanced hunting in Microsoft Defender multitenant management](mto-advanced-hunting.md)
99+

defender-xdr/mto-overview.md

Lines changed: 27 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Multi-tenant management in Microsoft Defender XDR
3-
description: Overview of multi-tenant management in Microsoft Defender XDR.
2+
title: Microsoft Defender multitenant management
3+
description: Learn about multitenant management for Microsoft Defender XDR and Microsoft Sentinel in the Microsoft unified security operations platform.
44
ms.service: defender-xdr
55
ms.author: siosulli
66
author: siosulli
@@ -11,41 +11,48 @@ ms.collection:
1111
- m365-security
1212
- highpri
1313
- tier1
14+
- usx-security
1415
ms.topic: conceptual
15-
ms.date: 09/01/2023
16+
ms.date: 08/19/2024
17+
appliesto:
18+
- Microsoft Defender XDR
19+
- Microsoft Sentinel in the Microsoft Defender portal
20+
- Microsoft Defender for Endpoint Plan 2
21+
- Microsoft Defender for Office 365 P2
1622
---
1723

18-
# Overview of multi-tenant management in Microsoft Defender XDR
24+
# Microsoft Defender multitenant management
1925

20-
**Applies to:**
26+
Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform provides your security operation teams with a single, unified view of all the tenants you manage. This view enables your teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving your security operations.
2127

22-
- [Microsoft Defender XDR](microsoft-365-defender.md)
23-
- [Microsoft Defender for Endpoint Plan 2](/defender-endpoint/microsoft-defender-endpoint)
24-
- [Microsoft Defender for Office 365 P2](https://go.microsoft.com/fwlink/p/?LinkID=2158212)
28+
If you have tenants with a Microsoft Sentinel workspace onboarded to the unified security operations platform, you're able to:
2529

26-
>[!Tip]
27-
>To learn how to turn on preview features, see [Microsoft Defender XDR preview features](preview.md).
30+
- Triage incidents and alerts across security information and event management (SIEM) and extended detection and response (XDR) data.
31+
- Proactively search for SIEM and XDR data across multiple tenants.
2832

29-
Managing multi-tenant environments can add an additional layer of complexity when it comes to keeping up with the ever-evolving security threats facing your enterprise. Navigating across multiple tenants can be time consuming and reduce the overall efficiency of security operation center (SOC) teams.
33+
Only one Microsoft Sentinel workspace per tenant is currently supported in the unified security operations platform. So in Microsoft Defender multitenant management, you have SIEM data from one Microsoft Sentinel workspace per tenant.
3034

31-
Multi-tenant management in Microsoft Defender XDR was designed to provide security operation teams with a single, unified view of all the tenants they manage. This view enables teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving their security operations.
35+
For more information, see:
3236

33-
>[!Tip]
34-
>To learn more about multi-tenant organizations, see [Multi-tenant organizations documentation](/azure/active-directory/multi-tenant-organizations/).
37+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
38+
- [Multitenant organizations documentation](/azure/active-directory/multi-tenant-organizations/)
3539

36-
Some of the key benefits you get with multi-tenant management in Microsoft Defender XDR include:
3740

38-
- **A centralized place to manage incidents across tenants**: A unified view provides SOC analysts with all the information they need for incident investigation across multiple tenants, eliminating the need to sign in and out of each one.
41+
## Benefits of multitenant management
3942

40-
- **Streamlined threat hunting**: Multi-tenancy support enables SOC teams use Microsoft Defender XDR advanced hunting capabilities to create KQL queries that will proactively hunt for threats across multiple tenants.
43+
Some of the key benefits you get with multitenant management for Defender XDR and the Microsoft unified security operations platform include:
44+
45+
- **A centralized place to manage incidents across tenants**: A unified view provides SOC analysts with all the information they need to investigate incidents across multiple tenants, eliminating the need to sign in and out of each one.
46+
47+
- **Streamlined threat hunting**: Multi-tenancy support enables SOC teams use Microsoft Defender XDR advanced hunting capabilities to create Kusto Query Language (KQL) queries that proactively hunt for threats across multiple tenants.
4148

4249
- **Multi-customer management for partners**: Managed Security Service Provider (MSSP) partners can now gain visibility into security incidents, alerts, and threat hunting across multiple customers through a single pane of glass.
4350

4451
<a name='whats-included-in-multi-tenant-management-in-microsoft-365-defender'></a>
4552

46-
## What's included in multi-tenant management in Microsoft Defender XDR
53+
## What's included in multitenant management
4754

48-
The following key capabilities are available for each tenant you have access to in multi-tenant management in Microsoft Defender XDR:
55+
The following key capabilities are available for each tenant you have access to in multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform:
4956

5057
| Capability | Description |
5158
| ------ | ------ |
@@ -60,4 +67,4 @@ The following key capabilities are available for each tenant you have access to
6067

6168
## Next steps
6269

63-
- [Set up multi-tenant management in Microsoft Defender XDR](mto-requirements.md)
70+
- [Set up Microsoft Defender multitenant management](mto-requirements.md)

0 commit comments

Comments
 (0)