You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/before-you-begin-xdr.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -63,7 +63,7 @@ The following product isn't covered by this service:
63
63
64
64
To enable the Defender Experts for Severs coverage, Defender for Servers Plan 1 or Plan 2 in Defender for Cloud must be enabled. Endpoint protection should also be turned on for both Windows and Linux devices that allow protection powered by Defender for Endpoint, including automatic agent deployment to your servers, and security data integration with Defender for Cloud.
65
65
66
-
Depending on the coverage you're looking for, you can enable the Defender for Servers plan for an Microsoft Azure subscription, Amazon Web Services account, or Google Cloud Platform project.
66
+
Depending on the coverage you're looking for, you can enable the Defender for Servers plan for a Microsoft Azure subscription, Amazon Web Services account, or Google Cloud Platform project.
> Microsoft Defender Experts for XDR is sold separately from other Microsoft Defender XDR products. If you're a Microsoft Defender XDR customer and are interested in purchasing Defender Experts for XDR and the cloud workload add-on, please complete this [customer interest form](https://aka.ms/IWantDefenderExperts).
30
+
> Microsoft Defender Experts for XDR is sold separately from other Microsoft Defender XDR products. If you're a Microsoft Defender XDR customer and are interested in purchasing Defender Experts for XDR and the cloud workload add-on, complete this [customer interest form](https://aka.ms/IWantDefenderExperts).
31
31
32
32
> [!NOTE]
33
33
> Any incident response services offered by Defender Experts will be offered under the Defender Experts Service Terms.
34
34
35
-
**Microsoft Defender Experts for XDR** is a managed extended detection and response service that helps your security operations centers (SOCs) focus and accurately respond to incidents that matter. It provides extended detection and response for customers who use Microsoft Defender XDR services: Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID. The service also offers an add-on service, **Microsoft Defender Experts for Servers**, which provides coverage for cloud workloads, beginning with on-premises and multi-cloud servers protected by Microsoft Defender for Cloud.
35
+
**Microsoft Defender Experts for XDR** is a managed extended detection and response service that helps your security operations centers (SOCs) focus and accurately respond to incidents that matter. It provides extended detection and response for customers who use Microsoft Defender XDR services: Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID. It also offers an add-on service, **Microsoft Defender Experts for Servers**, which provides coverage for cloud workloads, beginning with on-premises and multicloud servers protected by Microsoft Defender for Cloud.
36
36
37
37
Defender Experts for XDR augments your SOC by combining automation and Microsoft's security analyst expertise. This combination helps you detect and respond to threats with confidence and improve your security posture. With deep product expertise powered by threat intelligence, we're uniquely positioned to help you:
The following section lists down questions you or your SOC team might have regarding Micorosft Defender Experts coverage for cloud workloads.
28
+
The following section lists down questions you or your SOC team might have regarding Microsoft Defender Experts coverage for servers and cloud workloads.
29
29
30
30
| Questions | Answers |
31
31
|---------|---------|
32
-
|**What is Managed response?**| Microsoft Defender Experts for XDR offers **Managed response** where our experts manage the entire remediation process for incidents that require them. This process includes investigating the incident to identify the root cause, determining the required response actions, and taking those actions on your behalf.|
33
-
|**What actions are in scope for Managed response?**| All actions found below are in scope for Managed response for any device and user that isn't excluded.<br><br>*For devices**(Available now)*<ul><li>Isolate machine<br><li>Release machine from isolation<br><li>Stop and quarantine file<br><li>Restrict app execution<br><li>Remove app restriction</ul><br>*For users (Available now)*<ul><li>Disable user<br><li>Enable user</ul><br>*For users (Coming soon)*<ul><li>Revoke refresh token<br><li>Soft delete emails</ul> |
34
-
|**Can I customize the extent of Managed response?**| You can configure the extent to which our experts do Managed response actions on your behalf by excluding certain devices and users (individually or by groups) either during onboarding or later by modifying your service's settings. [Read more about excluding device groups](get-started-xdr.md#exclude-devices-and-users-from-remediation)|
35
-
|**What support do Defender Experts offer for excluded assets?**| If our experts determine that you need to perform response actions on excluded devices or users, we notify you through various customizable methods and direct you to your Microsoft Defender XDR portal. From your portal, you can then view a detailed summary of our investigation process and the required response actions in the portal and perform these required actions directly. Similar capabilities are also available through Defender APIs, in case you prefer using a security information and event management (SIEM), IT service management (ITSM), or any other third-party tool. |
36
-
|**How am I going to be informed about the response actions?**| Response actions that our experts have completed on your behalf and any pending ones that you need to perform on your excluded assets are displayed in the **Managed response** panel in your Defender portal's **Incidents** page. <br><br>In addition, you'll also receive an email containing a link to the incident and instructions to view the Managed response in the portal. Moreover, if you have integration with Microsoft Sentinel or APIs, you'll also be notified within those tools by looking for Defender Experts statuses. For more information, see [FAQs related to Microsoft Defender Experts for XDR incident notifications](faq-incident-notifications-xdr.md).|
37
-
|**Can I customize Managed response based on actions?**| No. If you have devices or users that are considered high-value or sensitive, you can add them to your exclusion list. Our experts will NOT take any action on them and will only provide guidance if they're impacted by an incident.|
32
+
|**What does the server and cloud workload coverage add-on mean for the Microsoft Defender Experts service? Can I purchase this coverage only?**| The server and cloud coverage service, called **Microsoft Defender Experts for Servers** and **Microsoft Defender Experts for Hunting – Servers**, is only available as an add-on to existing [Microsoft Defender Experts for XDR](dex-xdr-overview.md) and [Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md) customers, respectively. To avail of this add-on, you need at least one Defender Experts for XDR or Defender Experts for Hunting license to enable coverage of all your servers in Microsoft Defender for Cloud.|
33
+
|**Can I configure which servers the Defender Experts will cover?**| This add-on service covers **all** your servers in your tenant that have [Defender for Servers](/azure/defender-for-cloud/defender-for-servers-overview) protection enabled in Defender for Cloud. |
34
+
|**Do the Defender Experts investigate all Defender for Servers alerts**| There are some Defender for Servers alerts that our analysts aren't able to investigate. Currently, DNS alerts are out of scope due to limited data available for investigation. |
35
+
|**I only have Microsoft Defender Endpoint. How can I get server coverage?**| If you have servers that have Defender for Endpoint deployed on them with a Microsoft Defender for Endpoint for Server license, you can get the server coverage through the Defender Experts for XDR service. The service doesn't cover Microsoft Defender for Cloud workloads. [Learn more](before-you-begin-xdr.md#product-configuration-and-service-coverage)<br><br>If you want coverage for servers in Defender for Cloud, you need to avail the Microsoft Defender Experts for Servers or Defender Experts for Hunting - Servers add-on. |
36
+
38
37
39
38
### See also
40
39
41
-
-[Managed detection and response](managed-detection-and-response-xdr.md)
42
-
-[FAQs related to Microsoft Defender Experts for XDR incident notifications](faq-incident-notifications-xdr.md)
40
+
-[General information on Defender Experts for XDR service](frequently-asked-questions.md)
41
+
-[General information on Microsoft Defender Experts for Hunting service](faq-defender-experts-hunting.md)
This document applies for Microsoft Defender Experts for XDR and its add-on service, Microsoft Defedner Experts for Servers.
29
+
This document applies for Microsoft Defender Experts for XDR and its add-on service, Microsoft Defender Experts for Servers.
30
30
31
31
For onboarding instructions, check out this short video:
32
32
@@ -55,11 +55,11 @@ You also need to grant our experts one or both of the following permissions:
55
55
> [!IMPORTANT]
56
56
> If you skip providing additional permissions, our experts won't be able to take certain response actions to secure your organization.
57
57
>
58
-
> Even though our experts are granted these relatively powerful permissions, they will only have individual access to specific areas for a limited period. [Learn more about how Defender Experts for XDR permissions work](dex-xdr-permissions.md)
58
+
> Even though our experts are granted these relatively powerful permissions, they'll only have individual access to specific areas for a limited period. [Learn more about how Defender Experts for XDR permissions work](dex-xdr-permissions.md)
59
59
60
60
**To grant our experts permissions:**
61
61
62
-
1. In the same Defender Experts settings setup, under **Permissions**, choose the access level(s) you want to grant our experts.
62
+
1. In the same Defender Experts settings setup, under **Permissions**, choose one or more access levels you want to grant our experts.
63
63
64
64
1. If you wish to [exclude device and user groups](#exclude-devices-and-users-from-remediation) in your organization from remediation actions, select **Manage exclusions**.
65
65
@@ -75,7 +75,7 @@ Defender Experts for XDR lets you exclude devices and users from remediation act
75
75
76
76
1. In the same Defender Experts settings setup, under **Exclusions**, go to the **Device groups** tab.
77
77
78
-
2. Select **+ Add device groups**, then search for and choose the device group(s) that you wish to exclude.
78
+
2. Select **+ Add device groups**, then search for and choose one or more device groups that you wish to exclude.
79
79
> [!NOTE]
80
80
> This page only lists existing device groups. If you wish to create a new device group, you first need to go to the Defender for Endpoint settings in your Microsoft Defender portal. Then, refresh this page to search for and choose the newly created group. [Learn more about creating device groups](/defender-endpoint/machine-groups)
81
81
@@ -90,7 +90,7 @@ Defender Experts for XDR lets you exclude devices and users from remediation act
90
90
**To exclude user groups:**
91
91
92
92
1. In the same Defender Experts settings setup, under **Exclusions**, go to the **User groups** tab.
93
-
2. Select **+ Add user groups**, then search for and choose the user group(s) that you wish to exclude.
93
+
2. Select **+ Add user groups**, then search for and choose one or more user groups that you wish to exclude.
94
94
> [!NOTE]
95
95
> This page only lists existing user groups. If you wish to create a new user group, you first need to sign into the Microsoft Entra ID admin center as a Global Administrator. Then, refresh this page to search for and choose the newly created group. [Learn more about creating user groups](/entra/fundamentals/groups-view-azure-portal)
96
96
@@ -101,7 +101,7 @@ Defender Experts for XDR lets you exclude devices and users from remediation act
101
101
:::image type="content" source="media/exclude-user-groups.png" alt-text="Screenshot to exclude user groups in Defender Experts for XDR." lightbox="media/exclude-user-groups.png":::
102
102
103
103
> [!NOTE]
104
-
> You can only exclude users by adding them to a Microsoft Entra ID security group. On-prem Entra ID users cannot be excluded at this time.
104
+
> You can only exclude users by adding them to a Microsoft Entra ID security group. On-premises Microsoft Entra ID users can't be excluded at this time.
105
105
106
106
To edit or update exclusions after the initial setup, go to **Settings** > **Defender Experts** > **Exclusions**, then go to the **Device groups** or **User groups** tab.
107
107
@@ -160,7 +160,7 @@ To edit or update your notification contacts after the initial setup, go to **Se
160
160
Apart from email and [in-portal chat](communicate-defender-experts-xdr.md#in-portal-chat), you also have to option to use Microsoft Teams to receive updates about managed responses and communicate with our experts in real time. When this setting is turned on, a new team named **Defender Experts team** is created, where managed response notifications related to ongoing incidents are sent as new posts in the **Managed response** channel. [Learn more about using Teams chat](communicate-defender-experts-xdr.md#teams-chat)
161
161
162
162
> [!IMPORTANT]
163
-
> Defender Experts will have access to all messages posted on any channel in the created **Defender Experts team**. To prevent Defender Experts from accessing messages in this team, go to **Apps** in Teams then navigate to **Manage your apps** > **Defender Experts** > **Remove**. This removal action cannot be reversed.
163
+
> Defender Experts will have access to all messages posted on any channel in the created **Defender Experts team**. To prevent Defender Experts from accessing messages in this team, go to **Apps** in Teams then navigate to **Manage your apps** > **Defender Experts** > **Remove**. This removal action can't be reversed.
0 commit comments