Skip to content

Commit 7201a71

Browse files
committed
Defender XDR - Add in MTM for tenants w/ Sentinel onboarded to USX
1 parent 008d3d1 commit 7201a71

File tree

5 files changed

+80
-55
lines changed

5 files changed

+80
-55
lines changed

defender-xdr/mto-advanced-hunting.md

Lines changed: 13 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -12,17 +12,17 @@ ms.collection:
1212
- m365-security
1313
- highpri
1414
- tier1
15+
- usx-security
1516
ms.topic: conceptual
16-
ms.date: 07/18/2024
17+
ms.date: 08/07/2024
18+
appliesto:
19+
- Microsoft Defender XDR
20+
- Microsoft Sentinel in the Microsoft Defender portal
1721
---
1822

19-
# Advanced hunting in multi-tenant management in Microsoft Defender XDR
23+
# Advanced hunting in multi-tenant management for Microsoft Defender XDR
2024

21-
**Applies to:**
22-
23-
- [Microsoft Defender XDR](microsoft-365-defender.md)
24-
25-
Advanced hunting in multi-tenant management in Microsoft Defender XDR allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time.
25+
Advanced hunting in multi-tenant management for Microsoft Defender XDR allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time. If you have tenants with a Microsoft Sentinel workspace onboarded to the unified security operations platform, search for SIEM data together with XDR data across multiple tenants.
2626

2727
## Run cross-tenant queries
2828

@@ -73,3 +73,9 @@ When you select a single detection rule, a flyout panel opens with the detection
7373
:::image type="content" source="/defender/media/defender/custom-detection-rule-details.png" alt-text="Screenshot of the Microsoft Defender XDR custom detection rule details page" lightbox="/defender/media/defender/custom-detection-rule-details.png":::
7474

7575
Select **Open detection rules** to view this rule in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com). To learn more, see [Custom detection rules](./custom-detection-rules.md).
76+
77+
## Related content
78+
79+
- [Set up multi-tenant management in Microsoft Defender XDR](mto-requirements.md)
80+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
81+
- [View and manage incidents and alerts](mto-incidents-alerts.md)

defender-xdr/mto-incidents-alerts.md

Lines changed: 22 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: View and manage incidents and alerts in multi-tenant management in Microsoft Defender XDR
3-
description: Learn about incidents and alerts in multi-tenant management in Microsoft Defender XDR
2+
title: View and manage incidents and alerts in multi-tenant management for Microsoft Defender XDR
3+
description: Learn about incidents and alerts in multi-tenant management for Microsoft Defender XDR
44
search.appverid: met150
55
ms.service: defender-xdr
66
ms.author: siosulli
@@ -12,23 +12,25 @@ ms.collection:
1212
- m365-security
1313
- highpri
1414
- tier1
15+
- usx-security
1516
ms.topic: conceptual
16-
ms.date: 09/01/2023
17+
ms.date: 08/07/2024
18+
appliesto:
19+
- Microsoft Defender XDR
20+
- Microsoft Sentinel in the Microsoft Defender portal
1721
---
1822

1923
# View and manage incidents and alerts
2024

21-
**Applies to:**
25+
Multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats. Triage incidents and alerts across SIEM and XDR data for tenants that have onboarded a Microsoft Sentinel workspace to the unified security operations platform.
2226

23-
- [Microsoft Defender XDR](microsoft-365-defender.md)
24-
25-
Multi-tenant management in Microsoft Defender XDR enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats.
26-
27-
You can manage incidents & alerts originating from multiple tenants under **Incidents & alerts**.
27+
Manage incidents & alerts originating from multiple tenants under **Incidents & alerts**.
2828

2929
## View and investigate incidents
3030

31-
1. To View or investigate an incident, go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management in Microsoft Defender XDR. The **Tenant name** column shows which tenant the incident originates from:
31+
To view or investigate an incident:
32+
33+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management in Microsoft Defender XDR. The **Tenant name** column shows which tenant the incident originates from:
3234

3335
:::image type="content" source="/defender/media/defender/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender XDR multi-tenant incidents page" lightbox="/defender/media/defender/mto-incidents.png":::
3436

@@ -61,7 +63,9 @@ To learn more about incidents in the Microsoft Defender portal, see [Manage inci
6163

6264
## View and investigate alerts
6365

64-
1. To view or investigate an alert, go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management and select the alert you want to view. A flyout panel opens with the alert details page:
66+
To view or investigate an alert:
67+
68+
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management and select the alert you want to view. A flyout panel opens with the alert details page:
6569

6670
:::image type="content" source="/defender/media/defender/mto-alerts-details.png" alt-text="Screenshot of the Microsoft Defender XDR alert details page" lightbox="/defender/media/defender/mto-alerts-details.png":::
6771

@@ -86,3 +90,10 @@ On the alert fly-out you can assign alerts, set the alert status, and classify t
8690
> [!Note]
8791
> Currently, you can only assign multiple alerts from same tenant.
8892
To learn more about alerts in the Microsoft Defender portal, see [Manage alerts](/defender-endpoint/manage-alerts).
93+
94+
## Related content
95+
96+
- [Set up multi-tenant management in Microsoft Defender XDR](mto-requirements.md)
97+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
98+
- [Advanced hunting in multi-tenant management in Microsoft Defender XDR](mto-advanced-hunting.md)
99+

defender-xdr/mto-overview.md

Lines changed: 25 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Multi-tenant management in Microsoft Defender XDR
3-
description: Overview of multi-tenant management in Microsoft Defender XDR.
2+
title: Multi-tenant management for the Microsoft unified security operations platform
3+
description: Learn about multi-tenant management for Microsoft Defender XDR and Microsoft Sentinel in the the Microsoft unified security operations platform.
44
ms.service: defender-xdr
55
ms.author: siosulli
66
author: siosulli
@@ -11,41 +11,48 @@ ms.collection:
1111
- m365-security
1212
- highpri
1313
- tier1
14+
- usx-security
1415
ms.topic: conceptual
15-
ms.date: 09/01/2023
16+
ms.date: 08/07/2024
17+
appliesto:
18+
- Microsoft Defender XDR
19+
- Microsoft Sentinel in the Microsoft Defender portal
20+
- Microsoft Defender for Endpoint Plan 2
21+
- Microsoft Defender for Office 365 P2
1622
---
1723

18-
# Overview of multi-tenant management in Microsoft Defender XDR
24+
# Multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform
1925

20-
**Applies to:**
26+
Multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform provides your security operation teams with a single, unified view of all the tenants you manage. This view enables your teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving your security operations.
2127

22-
- [Microsoft Defender XDR](microsoft-365-defender.md)
23-
- [Microsoft Defender for Endpoint Plan 2](/defender-endpoint/microsoft-defender-endpoint)
24-
- [Microsoft Defender for Office 365 P2](https://go.microsoft.com/fwlink/p/?LinkID=2158212)
28+
If you have tenants with a Microsoft Sentinel workspace onboarded to the unified security operations platform, you're able to:
2529

26-
>[!Tip]
27-
>To learn how to turn on preview features, see [Microsoft Defender XDR preview features](preview.md).
30+
- Triage incidents and alerts across SIEM and XDR data.
31+
- Proactively search for SIEM and XDR data across multiple tenants.
2832

29-
Managing multi-tenant environments can add an additional layer of complexity when it comes to keeping up with the ever-evolving security threats facing your enterprise. Navigating across multiple tenants can be time consuming and reduce the overall efficiency of security operation center (SOC) teams.
33+
Only one Microsoft Sentinel workspace per tenant is currently supported in the unfied security platform. So for multi-tenant management, you'll have SIEM data from one Microsoft Sentinel workspace per tenant.
3034

31-
Multi-tenant management in Microsoft Defender XDR was designed to provide security operation teams with a single, unified view of all the tenants they manage. This view enables teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving their security operations.
35+
For more information, see:
3236

33-
>[!Tip]
34-
>To learn more about multi-tenant organizations, see [Multi-tenant organizations documentation](/azure/active-directory/multi-tenant-organizations/).
37+
- [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
38+
- [Multi-tenant organizations documentation](/azure/active-directory/multi-tenant-organizations/)
3539

36-
Some of the key benefits you get with multi-tenant management in Microsoft Defender XDR include:
3740

38-
- **A centralized place to manage incidents across tenants**: A unified view provides SOC analysts with all the information they need for incident investigation across multiple tenants, eliminating the need to sign in and out of each one.
41+
## Benefits of multi-tenant management
42+
43+
Some of the key benefits you get with multi-tenant management for Defender XDR and the Microsoft unified security operations platform include:
44+
45+
- **A centralized place to manage incidents across tenants**: A unified view provides SOC analysts with all the information they need to investigate incidents across multiple tenants, eliminating the need to sign in and out of each one.
3946

4047
- **Streamlined threat hunting**: Multi-tenancy support enables SOC teams use Microsoft Defender XDR advanced hunting capabilities to create KQL queries that will proactively hunt for threats across multiple tenants.
4148

4249
- **Multi-customer management for partners**: Managed Security Service Provider (MSSP) partners can now gain visibility into security incidents, alerts, and threat hunting across multiple customers through a single pane of glass.
4350

4451
<a name='whats-included-in-multi-tenant-management-in-microsoft-365-defender'></a>
4552

46-
## What's included in multi-tenant management in Microsoft Defender XDR
53+
## What's included in multi-tenant management
4754

48-
The following key capabilities are available for each tenant you have access to in multi-tenant management in Microsoft Defender XDR:
55+
The following key capabilities are available for each tenant you have access to in multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform:
4956

5057
| Capability | Description |
5158
| ------ | ------ |

defender-xdr/mto-requirements.md

Lines changed: 13 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: Set up multitenant management in Microsoft Defender XDR
3-
description: Learn what steps you need to take to get started with multitenant management in Microsoft Defender XDR.
3+
description: Learn what steps you need to take to get started with multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform.
44
ms.service: defender-xdr
55
ms.author: siosulli
66
author: siosulli
@@ -11,40 +11,39 @@ ms.collection:
1111
- m365-security
1212
- highpri
1313
- tier1
14+
- usx-security
1415
ms.topic: conceptual
15-
ms.date: 09/01/2023
16+
ms.date: 08/07/20
17+
appliesto:
18+
- Microsoft Defender XDR
19+
- Microsoft Sentinel in the Microsoft Defender portal
1620
---
1721

1822
# Set up multi-tenant management in Microsoft Defender XDR
1923

20-
**Applies to:**
21-
22-
- [Microsoft Defender XDR](microsoft-365-defender.md)
23-
24-
This article describes the steps you need to take to start using multi-tenant management in Microsoft Defender XDR.
25-
26-
>[!Note]
27-
>In multi-tenant management, interactions between the multi-tenant user and the managed tenants could involve accessing data and managing configurations. The ability to undertake these actions is determined by the permissions a managed tenant has granted the multi-tenant user.
24+
This article describes the steps you need to take to start using multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform.
2825

2926
1. [Review the requirements](#review-the-requirements)
3027
2. [Verify your tenant access](#verify-your-tenant-access)
3128
3. [Set up multi-tenant management in Microsoft Defender XDR](#set-up-multi-tenant-management)
3229

3330
>[!Note]
34-
> [Data privacy](data-privacy.md), [role-based access control (RBAC)](m365d-permissions.md) and [Licensing](prerequisites.md#licensing-requirements) are respected by multi-tenant management in Microsoft Defender XDR.
31+
>- In multi-tenant management, interactions between the multi-tenant user and the managed tenants could involve accessing data and managing configurations. The ability to undertake these actions is determined by the permissions a managed tenant has granted the multi-tenant user.
32+
>- [Data privacy](data-privacy.md), [role-based access control (RBAC)](m365d-permissions.md) and [Licensing](prerequisites.md#licensing-requirements) are respected by multi-tenant management in Microsoft Defender XDR.
3533
3634
## Review the requirements
3735

38-
The following table lists the basic requirements you need to use multi-tenant management in Microsoft Defender XDR.
36+
The following table lists the basic requirements you need to use multi-tenant management for Microsoft Defender XDR and the unified security operations platform.
3937

4038
| Requirement | Description |
4139
|:---|:---|
4240
| Microsoft Defender XDR prerequisites | Verify you meet the [Microsoft Defender XDR prerequisites](prerequisites.md)|
4341
| Multi-tenant access | To view and manage the data you have access to in multi-tenant management, you need to ensure you have the necessary access. For each tenant you want to view and manage, you need to have either: <br/> <br/> - [Granular delegated admin privileges (GDAP)](/partner-center/gdap-introduction) <br/> - [Microsoft Entra B2B authentication](/azure/active-directory/external-identities/what-is-b2b) <br/> <br/> To learn more about how to synchronize multiple B2B users across tenants, see [Configure cross-tenant synchronization](/azure/active-directory/multi-tenant-organizations/cross-tenant-synchronization-configure).|
4442
| Permissions | Users must be assigned the correct roles and permissions at the individual tenant level, in order to view and manage the associated data in multi-tenant management. To learn more, see: <br/><br/> - [Manage access to Microsoft Defender XDR with Microsoft Entra global roles](./m365d-permissions.md) <br/> - [Custom roles in role-based access control for Microsoft Defender XDR](./custom-roles.md)<br/><br/> To learn how to grant permissions for multiple users at scale, see [What is entitlement management](/azure/active-directory/governance/entitlement-management-overview).|
43+
| SIEM data (Optional) |To include SIEM data with the XDR data, one or more tenants must include a Microsoft Sentinel workspace onboarded to unified security operations platform. For more information, see [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md).<br/><br/>Only one Microsoft Sentinel workspace per tenant is currently supported in the unfied security operations platform. So for multi-tenant management, you'll have SIEM data from one Microsoft Sentinel workspace per tenant.|
44+
45+
We recommend that you set up [multi-factor authentication trust](/azure/active-directory/external-identities/authentication-conditional-access) for each tenant to avoid missing data in multi-tenant management for Microsoft Defender XDR and the unified security operations platform.
4546

46-
>[!Note]
47-
> Setting up [multi-factor authentication trust](/azure/active-directory/external-identities/authentication-conditional-access) is highly recommended for each tenant to avoid missing data in multi-tenant management Microsoft Defender XDR.
4847

4948
## Verify your tenant access
5049

defender-xdr/mto-tenants.md

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -12,15 +12,17 @@ ms.collection:
1212
- m365-security
1313
- highpri
1414
- tier1
15+
- usx-security
1516
ms.topic: conceptual
16-
ms.date: 03/20/2024
17+
ms.date: 08/07/2024
18+
appliesto:
19+
- Microsoft Defender XDR
20+
- Microsoft Sentinel in the Microsoft Defender portal
1721
---
1822

19-
# Manage tenants
23+
# Manage tenants in Microsoft Defender XDR
2024

21-
**Applies to:**
22-
23-
- [Microsoft Defender XDR](microsoft-365-defender.md)
25+
Add or remove tenants from the settings page in multi-tenant management from the Microsoft Defender portal.
2426

2527
## View the tenants page
2628

0 commit comments

Comments
 (0)