Skip to content

Commit 63dcc47

Browse files
committed
Update MTO AH
1 parent dce2266 commit 63dcc47

File tree

1 file changed

+12
-1
lines changed

1 file changed

+12
-1
lines changed

unified-secops-platform/mto-advanced-hunting.md

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,8 @@ appliesto:
2424

2525
Advanced hunting in Microsoft Defender multitenant management allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time. If you have tenants with a Microsoft Sentinel workspace onboarded to the Microsoft Defender portal, search for security information and event management (SIEM) data together with extended detection and response (XDR) data across multiple tenants.
2626

27+
28+
2729
## Run cross-tenant queries
2830

2931
In multitenant management, you can use any of the queries you currently have access to. They're filtered by tenant in the **Queries** tab. Select a tenant to view the queries available under each one.
@@ -44,7 +46,16 @@ The query results contain the tenant ID:
4446

4547
To learn more about advanced hunting in Microsoft Defender XDR, read [Proactively hunt for threats with advanced hunting in Microsoft Defender XDR](/defender-xdr/advanced-hunting-overview).
4648

47-
## Custom detection rules
49+
## View schema tables
50+
51+
You can view the [advanced hunting schema tables](/defender-xdr/advanced-hunting-schema-tables.md) in the left pane inside the advanced hunting page under the **Schema** tab.
52+
53+
The schema list is a unified view of all tables from all your tenants regardless of the tenant selected in the upper right tenant selector.
54+
55+
This could mean that some tables that appear here might only be available for query in some tenants, like custom Microsoft Sentinel tables.
56+
57+
58+
## View and manage custom detection rules
4859

4960
Likewise, you can manage custom detection rules from multiple tenants in the custom detection rules page.
5061

0 commit comments

Comments
 (0)