Skip to content

Commit 631d77a

Browse files
authored
Merge pull request #3042 from MicrosoftDocs/main
Published main to live, Thursday 5:00 PM IST, 03/06
2 parents 2c0a33a + 215ff41 commit 631d77a

File tree

6 files changed

+21
-14
lines changed

6 files changed

+21
-14
lines changed

defender-endpoint/TOC.yml

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1078,13 +1078,14 @@
10781078
href: information-protection-investigation.md
10791079

10801080
- name: Advanced hunting
1081-
href: /defender-xdr/advanced-hunting-overview
1081+
href: /defender-xdr/advanced-hunting-overview?toc=/defender-endpoint/toc.json&bc=/defender-endpoint/breadcrumb/toc.json
10821082

1083-
- name: Threat analytics overview
1084-
href: /defender-xdr/threat-analytics
1083+
- name: Threat analytics
10851084
items:
1085+
- name: Overview
1086+
href: /defender-xdr/threat-analytics?toc=/defender-endpoint/toc.json&bc=/defender-endpoint/breadcrumb/toc.json
10861087
- name: Read the analyst report
1087-
href: /defender-xdr/threat-analytics-analyst-reports
1088+
href: /defender-xdr/threat-analytics-analyst-reports?toc=/defender-endpoint/toc.json&bc=/defender-endpoint/breadcrumb/toc.json
10881089

10891090
- name: EDR in block mode
10901091
href: edr-in-block-mode.md

defender-xdr/additional-information-xdr.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.custom:
1919
- cx-ti
2020
- cx-dex
2121
search.appverid: met150
22-
ms.date: 10/30/2024
22+
ms.date: 03/05/2025
2323
appliesto:
2424
- Microsoft Defender XDR
2525
---
@@ -34,7 +34,7 @@ To realize the benefits of Microsoft Defender Experts for XDR, you and your secu
3434

3535
- **Engage actively through the readiness assessment process** – The [readiness assessment](get-started-xdr.md#prepare-your-environment-for-the-defender-experts-service) when onboarding for Defender Experts for XDR is an integral part of the offering. Completing it successfully ensures prompt service coverage and protects your organization against known threats.
3636
- **Act on managed responses in a timely manner** – For any suspicious incidents and alerts, our experts provide a detailed investigation summary and managed responses for remediation. We expect your SOC team to act on these managed responses in a timely manner to prevent further impact from any malicious attempts.
37-
- **Configure recommended settings and follow best practices to improve security posture** – As part of our service, your service delivery manager and security analyst team share ongoing recommendations to strengthen your security posture. These recommendations are based on incidents investigated in your organization. Your SOC team should review these recommendations and implement them as soon as possible to protect your organization against future threats.
37+
- **Configure recommended settings and follow best practices to improve security posture** – As part of our service, we will share ongoing recommendations to strengthen your security posture. These recommendations are based on incidents investigated in your organization. Your SOC team should review these recommendations and implement them as soon as possible to protect your organization against future threats.
3838

3939
### Note about incident response
4040

defender-xdr/communicate-defender-experts-xdr.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.collection:
1414
- essentials-manage
1515
ms.topic: conceptual
1616
search.appverid: met150
17-
ms.date: 05/01/2024
17+
ms.date: 03/05/2025
1818
---
1919

2020
# Communicating with experts in the Microsoft Defender Experts for XDR service
@@ -23,7 +23,7 @@ ms.date: 05/01/2024
2323

2424
- [Microsoft Defender XDR](microsoft-365-defender.md)
2525

26-
Microsoft Defender Experts for XDR provides you with multiple channels of communication to discuss incidents with our experts, ask them questions on demand, or get service readiness or operations support from your service delivery managers (SDMs).
26+
Microsoft Defender Experts for XDR provides you with multiple channels of communication to discuss incidents with our experts, ask them questions on demand, or get service readiness or operations support from your service delivery managers (SDMs), if included in your service.
2727

2828
## Incident and managed response notifications
2929

@@ -79,6 +79,9 @@ While the previous scenarios involve our experts initiating communication with y
7979

8080
The service delivery manager (SDM) is responsible for managing the overall relationship for your organization with the Defender Experts for XDR service. They are your trusted advisor working along with XDR experts' team to help you protect your organization.
8181

82+
> [!NOTE]
83+
> Service delivery managers are included if your Defender Experts for XDR service is licensed for 500 or more seats.
84+
8285
The SDM provides the following services:
8386

8487
- Service readiness support

defender-xdr/dex-xdr-overview.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 02/05/2025
20+
ms.date: 03/05/2025
2121
---
2222

2323
# Microsoft Defender Experts for XDR
@@ -40,18 +40,22 @@ Defender Experts for XDR augments your SOC by combining automation and Microsoft
4040
- **Access expertise when you need it** - Extend your team's capacity with access to Defender Experts for assistance on an investigation
4141
- **Stay ahead of emerging threats** - Our experts proactively hunt for emerging threats in your environment, informed by unparalleled threat intelligence and visibility
4242

43-
Apart from the constantly updated research and intelligence tailored for the threats currently seen across the various Microsoft Defender XDR signals, you also receive managed response from our security analysts and support from Microsoft's security-focused service delivery managers (SDMs). This service lets you enjoy the following capabilities:
43+
Apart from the constantly updated research and intelligence tailored for the threats currently seen across the various Microsoft Defender XDR signals, you also receive managed response from our security analysts and, if your service includes it, support from Microsoft's security-focused service delivery managers (SDMs)*. This service lets you enjoy the following capabilities:
4444

4545
- **Managed detection and response** - Expert analysts manage your Microsoft Defender XDR incident queue and handle triage and investigation on your behalf; they partner with you and your team to take action or guide you to respond to incidents
4646
- **Proactive threat hunting** - [Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md) is built in to extend your team's threat hunting capabilities and prioritize significant threats
4747
- **Ask Defender Experts** - Select [Ask Defender Experts](experts-on-demand.md) in the Microsoft Defender portal to get expert advice about threats your organization is facing. You can ask for help on a specific incident, nation-state actor, or attack vector-related notifications
4848
- **Live dashboards and reports** - Transparent view of our operations on your behalf and noise free, actionable view into what matters for you coupled with detailed analytics
4949
- **Proactive check-ins for continuous security improvements** - Periodic check-ins with your named service delivery team to guide your Defender Experts for XDR experience and improve your security posture
5050

51+
> [!NOTE]
52+
> Service delivery managers are included if your Defender Experts for XDR service is licensed for 500 or more seats.
53+
5154
[Read the Defender Experts for XDR ebook](https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Defender-Experts-for-XDR-eBook-Final.pdf) and maximize the benefits of this product suite.
5255

5356
### Next step
5457

5558
[Before you begin](before-you-begin-xdr.md)
5659

5760
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]
61+

defender-xdr/get-started-xdr.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 10/30/2024
20+
ms.date: 03/05/2025
2121
---
2222

2323
# Get started with Microsoft Defender Experts for XDR
@@ -131,7 +131,7 @@ Similar to the other excluded device or user groups, you instead get remediation
131131
Defender Experts for XDR lets you determine the individuals or groups within your organization that need to be notified if there are critical incidents, service updates, occasional queries, and other recommendations:
132132

133133
- **Incident notification contacts** – These contacts are persons or teams that we can notify for managed response actions or any communication that requires immediate response. Given the urgent nature of the communications, we recommended that these contacts are always available.
134-
- **Service review contacts** – These contacts are persons or teams that we can engage with for ongoing security briefings done by our service delivery team.
134+
- **Service review contacts** – These contacts are persons or teams that will be engaged with for service updates and, if your service includes a service delivery manager, service briefings.
135135

136136
Once identified, the individuals or groups will receive an email notifying them that they were as a contact for incident notification or service review purposes.
137137

@@ -204,7 +204,7 @@ The readiness assessment has two parts:
204204
> [!IMPORTANT]
205205
> Defender Experts for XDR reviews your readiness assessment periodically, especially if there are any changes to your environment, such as the addition of new devices and identities. It's important that you regularly monitor and run the readiness assessment beyond the initial onboarding to ensure that your environment has strong security posture to reduce risk.
206206
207-
After you complete all the required tasks and met the onboarding targets in your readiness assessment, your service delivery manager (SDM) initiates the monitoring phase of the Defender Experts for XDR service, where, for a few days, our experts start monitoring your environment closely to identify latent threats, sources of risk, and normal activity. As we get better understanding of your critical assets, we can streamline the service and fine-tune our responses.
207+
After you complete all the required tasks and met the onboarding targets in your readiness assessment, the monitoring phase of your Defender Experts for XDR service will start, where, for a few days, our experts start monitoring your environment closely to identify latent threats, sources of risk, and normal activity. As we get better understanding of your critical assets, we can streamline the service and fine-tune our responses.
208208

209209
Once our experts begin to perform comprehensive response work on your behalf, you'll start receiving [notifications about incidents](managed-detection-and-response-xdr.md#incident-updates) that require remediation steps and targeted recommendations on critical incidents. You can also [chat with our experts](communicate-defender-experts-xdr.md) or your SDMs regarding important queries and regular business and security posture reviews. Additionally you can also [view real-time reports](reports-xdr.md) on the number of incidents we've investigated and resolved on your behalf.
210210

exposure-management/integration-licensing.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,6 @@ The following licenses will allow access to Microsoft Secure Score experience on
6666

6767
- Microsoft 365 E3
6868
- Microsoft 365 A3
69-
- Microsoft Defender for Endpoint (Plan 2)
7069
- Microsoft Defender for Office 365 (Plan 1)
7170

7271
## Next steps

0 commit comments

Comments
 (0)