Skip to content

Commit 69ae931

Browse files
committed
updated content
1 parent 342e2e3 commit 69ae931

File tree

1 file changed

+53
-18
lines changed

1 file changed

+53
-18
lines changed
Lines changed: 53 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Threat protection report in Microsoft Defender for Endpoint
3-
description: Track alert detections, categories, and severity using the threat protection report.
2+
title: Microsoft Defender for Endpoint reports
3+
description: Access the various reports for devices, protection features, and more in Microsoft Defender for Endpoint.
44
ms.service: defender-endpoint
55
ms.author: deniseb
66
author: denisebmsft
@@ -12,32 +12,51 @@ ms.collection:
1212
- tier2
1313
ms.topic: conceptual
1414
search.appverid: met150
15-
ms.date: 1/31/2024
15+
ms.date: 2/04/2025
1616
---
1717

18-
# Threat protection report in Microsoft Defender for Endpoint
18+
# Microsoft Defender for Endpoint reports
1919

2020
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2121

22-
2322
**Applies to:**
2423

2524
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
2625
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
2726
- [Microsoft Defender XDR](/defender-xdr)
2827

29-
> [!IMPORTANT]
30-
> The Microsoft Defender for Endpoint Threat Protection report page is now deprecated and is no longer available. Microsoft recommends that you transition to either the Defender XDR alerts or advanced hunting to understand endpoint threat protection details. See the following sections for more information.
28+
This article provides an overview of the reports available to Microsoft Defender for Endpoint users. It offers information on various reports that can be used to collect data, summarize findings, and obtain recommended actions when applicable.
29+
30+
## Monthly security summary
31+
32+
The **monthly security summary** report helps organizations get a visual summary of key findings and overall preventative actions taken to enhance the organization's overall security posture completed in the last 30 or 90 days. It helps you identify areas of strength and improvement, track your progress over time, and prioritize your actions based on risk and impact.
33+
34+
To access this report, navigate to **Reports > Endpoints > Monthly Security Summary**. The monthly security summary report contains the following sections:
35+
36+
| Section | Description |
37+
|---------|---------|
38+
| [Microsoft Secure Score](/defender-xdr/microsoft-secure-score) | Microsoft Secure Score is a measurement of an organization's security posture and how well you have implemented security best practices and recommendations across the devices in your organization. The secure score card shows how the overall cybersecurity strength of an organization has improved in the past month and how it compares to other companies with similar number of managed devices. |
39+
|Secure score compared to other organizations | This score is an evaluation of an organization's security score in relation to organizations of a similar size. It's a way to benchmark an organization's performance in implementing security measures compared to other organizations of an equivalent size. |
40+
| Devices onboarded | The devices card provides information on the number of devices that were onboarded in the last month as well as devices still not onboarded. Onboarding devices are essential for enabling protection and detection capabilities. |
41+
| Protection against specific threats | This card shows how effective your defenses are against common attack vectors such as phishing and ransomware. A higher number indicates better defense in place against phishing and ransomware. The report shows how many threats were blocked or mitigated in the last month and how your protection level has increased. |
42+
| Web content monitoring and filtering | Shows the number of malicious URLs that were blocked by Microsoft Defender for Endpoint in the last month. The report also shows the categories of URLs that were blocked and the number of clicks for each category. |
43+
| Suspicious or malicious activities | Track how many incidents and alerts were resolved in the past month using the incidents card. The card also shows all active incidents and alerts that require attention. You'll also be able to see a list of the top 10 severe incidents, their status, number of alerts, and the impacted devices and users. |
3144

32-
## Use the alert queue filter in Defender XDR
45+
You can generate a PDF report of the summary, by selecting **Generate PDF report**. The generated report is a summary of the last 30 days.
3346

34-
Due to the deprecation of the Defender for Endpoint Threat protection report, you can use the Defender XDR alerts view, filtered against Defender for Endpoint, to see the current status of alerts for protected devices. For alert status, such as *unresolved*, you can filter against *New* and *In progress* items. [Learn more about Defender XDR Alerts](/defender-xdr/investigate-alerts).
47+
## Threat protection report
3548

36-
## Use Advanced hunting queries
49+
To gather data on Defender for Endpoint threat protection information, you can use the Microsoft Defender alerts queue or create advanced hunting queries. The following sections provide guidance on how to use these tools to find the information you need.
3750

38-
Due to the deprecation of the Defender for Endpoint Threat protection report, you can use Advanced hunting queries to find Defender for Endpoint threat protection information. Currently there's no alert status in Advanced hunting elements that maps to resolve/unresolve. [Learn more about Advanced hunting in Defender XDR](/defender-xdr/advanced-hunting-overview). See the following section for a sample advanced hunting query that shows endpoint related threat protection details.
51+
### Use the alert queue filter in the Microsoft Defender portal
3952

40-
### Alert status
53+
You can use the Microsoft Defender portal alerts view, filtered against Defender for Endpoint, to see the current status of alerts for protected devices. For alert status, such as *unresolved*, you can filter against *New* and *In progress* items. [Learn more about the alerts queue](/defender-xdr/investigate-alerts).
54+
55+
### Use advanced hunting queries
56+
57+
You can also use advanced hunting queries to find Defender for Endpoint threat protection information. [Learn more about advanced hunting in Defender XDR](/defender-xdr/advanced-hunting-overview). See the following section for a sample advanced hunting query that shows endpoint-related threat protection details.
58+
59+
#### Alert status
4160

4261
```kusto
4362
// Severity
@@ -49,7 +68,7 @@ AlertInfo
4968
// Detection source
5069
AlertInfo
5170
| where Timestamp > startofday(now()) // Today
52-
| summarize count() by Severity
71+
| summarize count() by DetectionSource
5372
| render columnchart
5473
5574
// Detection category
@@ -59,14 +78,13 @@ AlertInfo
5978
| render columnchart
6079
```
6180

62-
63-
### Alert trend
81+
#### Alert trend
6482

6583
```kusto
6684
// Severity
6785
AlertInfo
6886
| where Timestamp > ago(30d)
69-
| summarize count() by DetectionSource , bin(Timestamp, 1d)
87+
| summarize count() by Severity , bin(Timestamp, 1d)
7088
| render timechart
7189
7290
// Detection source
@@ -82,7 +100,24 @@ AlertInfo
82100
| render timechart
83101
```
84102

85-
## Related articles
103+
## Reports about Defender for Endpoint capabilities
104+
105+
The following reports provide in-depth information about events and actions related to Defender for Endpoint capabilities:
106+
107+
- [Device health reports](device-health-reports.md)
108+
- [Host firewall reporting](host-firewall-reporting.md)
109+
- [Web protection monitoring report](web-protection-monitoring.md)
110+
- [Attack surface reduction rules report](attack-surface-reduction-rules-report.md)
111+
- [Device control report](device-control-report.md)
112+
113+
## Create custom reports using Power BI
114+
115+
You can also create customized reports using Power BI. To create your own report, see [Create custom reports using Power BI](/defender-endpoint/api/api-power-bi).
116+
117+
## Aggregated reporting
118+
119+
You can review all signals collected by Defender for Endpoint by turning on aggregated reporting.
120+
121+
To turn aggregated reporting on, go to **Settings > Endpoints > Advanced features**. Toggle on the **Aggregated reporting** feature. Learn more about [aggregated reporting in Defender for Endpoint](/defender-endpoint/aggregated-reporting).
86122

87-
- [Device health and compliance report](device-health-reports.md)
88123
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

0 commit comments

Comments
 (0)