You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Advanced hunting in multi-tenant management in Microsoft Defender XDR allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time.
25
+
Advanced hunting in multi-tenant management for Microsoft Defender XDR allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time. If you have tenants with a Microsoft Sentinel workspace onboarded to the unified security operations platform, search for SIEM data together with XDR data across multiple tenants.
26
26
27
27
## Run cross-tenant queries
28
28
@@ -73,3 +73,9 @@ When you select a single detection rule, a flyout panel opens with the detection
73
73
:::image type="content" source="/defender/media/defender/custom-detection-rule-details.png" alt-text="Screenshot of the Microsoft Defender XDR custom detection rule details page" lightbox="/defender/media/defender/custom-detection-rule-details.png":::
74
74
75
75
Select **Open detection rules** to view this rule in a new tab for the specific tenant in the [Microsoft Defender portal](https://security.microsoft.com). To learn more, see [Custom detection rules](./custom-detection-rules.md).
76
+
77
+
## Related content
78
+
79
+
-[Set up multi-tenant management in Microsoft Defender XDR](mto-requirements.md)
80
+
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
81
+
-[View and manage incidents and alerts](mto-incidents-alerts.md)
Copy file name to clipboardExpand all lines: defender-xdr/mto-incidents-alerts.md
+22-11Lines changed: 22 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: View and manage incidents and alerts in multi-tenant management in Microsoft Defender XDR
3
-
description: Learn about incidents and alerts in multi-tenant management in Microsoft Defender XDR
2
+
title: View and manage incidents and alerts in multi-tenant management for Microsoft Defender XDR
3
+
description: Learn about incidents and alerts in multi-tenant management for Microsoft Defender XDR
4
4
search.appverid: met150
5
5
ms.service: defender-xdr
6
6
ms.author: siosulli
@@ -12,23 +12,25 @@ ms.collection:
12
12
- m365-security
13
13
- highpri
14
14
- tier1
15
+
- usx-security
15
16
ms.topic: conceptual
16
-
ms.date: 09/01/2023
17
+
ms.date: 08/07/2024
18
+
appliesto:
19
+
- Microsoft Defender XDR
20
+
- Microsoft Sentinel in the Microsoft Defender portal
17
21
---
18
22
19
23
# View and manage incidents and alerts
20
24
21
-
**Applies to:**
25
+
Multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats. Triage incidents and alerts across SIEM and XDR data for tenants that have onboarded a Microsoft Sentinel workspace to the unified security operations platform.
Multi-tenant management in Microsoft Defender XDR enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats.
26
-
27
-
You can manage incidents & alerts originating from multiple tenants under **Incidents & alerts**.
27
+
Manage incidents & alerts originating from multiple tenants under **Incidents & alerts**.
28
28
29
29
## View and investigate incidents
30
30
31
-
1. To View or investigate an incident, go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management in Microsoft Defender XDR. The **Tenant name** column shows which tenant the incident originates from:
31
+
To view or investigate an incident:
32
+
33
+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management in Microsoft Defender XDR. The **Tenant name** column shows which tenant the incident originates from:
32
34
33
35
:::image type="content" source="/defender/media/defender/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender XDR multi-tenant incidents page" lightbox="/defender/media/defender/mto-incidents.png":::
34
36
@@ -61,7 +63,9 @@ To learn more about incidents in the Microsoft Defender portal, see [Manage inci
61
63
62
64
## View and investigate alerts
63
65
64
-
1. To view or investigate an alert, go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management and select the alert you want to view. A flyout panel opens with the alert details page:
66
+
To view or investigate an alert:
67
+
68
+
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management and select the alert you want to view. A flyout panel opens with the alert details page:
65
69
66
70
:::image type="content" source="/defender/media/defender/mto-alerts-details.png" alt-text="Screenshot of the Microsoft Defender XDR alert details page" lightbox="/defender/media/defender/mto-alerts-details.png":::
67
71
@@ -86,3 +90,10 @@ On the alert fly-out you can assign alerts, set the alert status, and classify t
86
90
> [!Note]
87
91
> Currently, you can only assign multiple alerts from same tenant.
88
92
To learn more about alerts in the Microsoft Defender portal, see [Manage alerts](/defender-endpoint/manage-alerts).
93
+
94
+
## Related content
95
+
96
+
-[Set up multi-tenant management in Microsoft Defender XDR](mto-requirements.md)
97
+
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
98
+
-[Advanced hunting in multi-tenant management in Microsoft Defender XDR](mto-advanced-hunting.md)
Copy file name to clipboardExpand all lines: defender-xdr/mto-overview.md
+25-18Lines changed: 25 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Multi-tenant management in Microsoft Defender XDR
3
-
description: Overview of multi-tenant management in Microsoft Defender XDR.
2
+
title: Multi-tenant management for the Microsoft unified security operations platform
3
+
description: Learn about multi-tenant management for Microsoft Defender XDR and Microsoft Sentinel in the the Microsoft unified security operations platform.
4
4
ms.service: defender-xdr
5
5
ms.author: siosulli
6
6
author: siosulli
@@ -11,41 +11,48 @@ ms.collection:
11
11
- m365-security
12
12
- highpri
13
13
- tier1
14
+
- usx-security
14
15
ms.topic: conceptual
15
-
ms.date: 09/01/2023
16
+
ms.date: 08/07/2024
17
+
appliesto:
18
+
- Microsoft Defender XDR
19
+
- Microsoft Sentinel in the Microsoft Defender portal
20
+
- Microsoft Defender for Endpoint Plan 2
21
+
- Microsoft Defender for Office 365 P2
16
22
---
17
23
18
-
# Overview of multi-tenant management in Microsoft Defender XDR
24
+
# Multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform
19
25
20
-
**Applies to:**
26
+
Multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform provides your security operation teams with a single, unified view of all the tenants you manage. This view enables your teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving your security operations.
-[Microsoft Defender for Endpoint Plan 2](/defender-endpoint/microsoft-defender-endpoint)
24
-
-[Microsoft Defender for Office 365 P2](https://go.microsoft.com/fwlink/p/?LinkID=2158212)
28
+
If you have tenants with a Microsoft Sentinel workspace onboarded to the unified security operations platform, you're able to:
25
29
26
-
>[!Tip]
27
-
>To learn how to turn on preview features, see [Microsoft Defender XDR preview features](preview.md).
30
+
- Triage incidents and alerts across SIEM and XDR data.
31
+
- Proactively search for SIEM and XDR data across multiple tenants.
28
32
29
-
Managing multi-tenant environments can add an additional layer of complexity when it comes to keeping up with the ever-evolving security threats facing your enterprise. Navigating across multiple tenants can be time consuming and reduce the overall efficiency of security operation center (SOC) teams.
33
+
Only one Microsoft Sentinel workspace per tenant is currently supported in the unfied security platform. So for multi-tenant management, you'll have SIEM data from one Microsoft Sentinel workspace per tenant.
30
34
31
-
Multi-tenant management in Microsoft Defender XDR was designed to provide security operation teams with a single, unified view of all the tenants they manage. This view enables teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving their security operations.
35
+
For more information, see:
32
36
33
-
>[!Tip]
34
-
>To learn more about multi-tenant organizations, see [Multi-tenant organizations documentation](/azure/active-directory/multi-tenant-organizations/).
37
+
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
Some of the key benefits you get with multi-tenant management in Microsoft Defender XDR include:
37
40
38
-
-**A centralized place to manage incidents across tenants**: A unified view provides SOC analysts with all the information they need for incident investigation across multiple tenants, eliminating the need to sign in and out of each one.
41
+
## Benefits of multi-tenant management
42
+
43
+
Some of the key benefits you get with multi-tenant management for Defender XDR and the Microsoft unified security operations platform include:
44
+
45
+
-**A centralized place to manage incidents across tenants**: A unified view provides SOC analysts with all the information they need to investigate incidents across multiple tenants, eliminating the need to sign in and out of each one.
39
46
40
47
-**Streamlined threat hunting**: Multi-tenancy support enables SOC teams use Microsoft Defender XDR advanced hunting capabilities to create KQL queries that will proactively hunt for threats across multiple tenants.
41
48
42
49
-**Multi-customer management for partners**: Managed Security Service Provider (MSSP) partners can now gain visibility into security incidents, alerts, and threat hunting across multiple customers through a single pane of glass.
## What's included in multi-tenant management in Microsoft Defender XDR
53
+
## What's included in multi-tenant management
47
54
48
-
The following key capabilities are available for each tenant you have access to in multi-tenant management in Microsoft Defender XDR:
55
+
The following key capabilities are available for each tenant you have access to in multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform:
Copy file name to clipboardExpand all lines: defender-xdr/mto-requirements.md
+13-14Lines changed: 13 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
2
title: Set up multitenant management in Microsoft Defender XDR
3
-
description: Learn what steps you need to take to get started with multitenant management in Microsoft Defender XDR.
3
+
description: Learn what steps you need to take to get started with multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform.
4
4
ms.service: defender-xdr
5
5
ms.author: siosulli
6
6
author: siosulli
@@ -11,40 +11,39 @@ ms.collection:
11
11
- m365-security
12
12
- highpri
13
13
- tier1
14
+
- usx-security
14
15
ms.topic: conceptual
15
-
ms.date: 09/01/2023
16
+
ms.date: 08/07/20
17
+
appliesto:
18
+
- Microsoft Defender XDR
19
+
- Microsoft Sentinel in the Microsoft Defender portal
16
20
---
17
21
18
22
# Set up multi-tenant management in Microsoft Defender XDR
This article describes the steps you need to take to start using multi-tenant management in Microsoft Defender XDR.
25
-
26
-
>[!Note]
27
-
>In multi-tenant management, interactions between the multi-tenant user and the managed tenants could involve accessing data and managing configurations. The ability to undertake these actions is determined by the permissions a managed tenant has granted the multi-tenant user.
24
+
This article describes the steps you need to take to start using multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform.
28
25
29
26
1.[Review the requirements](#review-the-requirements)
30
27
2.[Verify your tenant access](#verify-your-tenant-access)
31
28
3.[Set up multi-tenant management in Microsoft Defender XDR](#set-up-multi-tenant-management)
32
29
33
30
>[!Note]
34
-
> [Data privacy](data-privacy.md), [role-based access control (RBAC)](m365d-permissions.md) and [Licensing](prerequisites.md#licensing-requirements) are respected by multi-tenant management in Microsoft Defender XDR.
31
+
>- In multi-tenant management, interactions between the multi-tenant user and the managed tenants could involve accessing data and managing configurations. The ability to undertake these actions is determined by the permissions a managed tenant has granted the multi-tenant user.
32
+
>-[Data privacy](data-privacy.md), [role-based access control (RBAC)](m365d-permissions.md) and [Licensing](prerequisites.md#licensing-requirements) are respected by multi-tenant management in Microsoft Defender XDR.
35
33
36
34
## Review the requirements
37
35
38
-
The following table lists the basic requirements you need to use multi-tenant management in Microsoft Defender XDR.
36
+
The following table lists the basic requirements you need to use multi-tenant management for Microsoft Defender XDR and the unified security operations platform.
39
37
40
38
| Requirement | Description |
41
39
|:---|:---|
42
40
| Microsoft Defender XDR prerequisites | Verify you meet the [Microsoft Defender XDR prerequisites](prerequisites.md)|
43
41
| Multi-tenant access | To view and manage the data you have access to in multi-tenant management, you need to ensure you have the necessary access. For each tenant you want to view and manage, you need to have either: <br/> <br/> - [Granular delegated admin privileges (GDAP)](/partner-center/gdap-introduction) <br/> - [Microsoft Entra B2B authentication](/azure/active-directory/external-identities/what-is-b2b) <br/> <br/> To learn more about how to synchronize multiple B2B users across tenants, see [Configure cross-tenant synchronization](/azure/active-directory/multi-tenant-organizations/cross-tenant-synchronization-configure).|
44
42
| Permissions | Users must be assigned the correct roles and permissions at the individual tenant level, in order to view and manage the associated data in multi-tenant management. To learn more, see: <br/><br/> - [Manage access to Microsoft Defender XDR with Microsoft Entra global roles](./m365d-permissions.md) <br/> - [Custom roles in role-based access control for Microsoft Defender XDR](./custom-roles.md)<br/><br/> To learn how to grant permissions for multiple users at scale, see [What is entitlement management](/azure/active-directory/governance/entitlement-management-overview).|
43
+
| SIEM data (Optional) |To include SIEM data with the XDR data, one or more tenants must include a Microsoft Sentinel workspace onboarded to unified security operations platform. For more information, see [Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md).<br/><br/>Only one Microsoft Sentinel workspace per tenant is currently supported in the unfied security operations platform. So for multi-tenant management, you'll have SIEM data from one Microsoft Sentinel workspace per tenant.|
44
+
45
+
We recommend that you set up [multi-factor authentication trust](/azure/active-directory/external-identities/authentication-conditional-access) for each tenant to avoid missing data in multi-tenant management for Microsoft Defender XDR and the unified security operations platform.
45
46
46
-
>[!Note]
47
-
> Setting up [multi-factor authentication trust](/azure/active-directory/external-identities/authentication-conditional-access) is highly recommended for each tenant to avoid missing data in multi-tenant management Microsoft Defender XDR.
0 commit comments