Skip to content

Commit 7325015

Browse files
authored
Merge pull request #1442 from MicrosoftDocs/main
Publish main to live, Monday 10:30AM PDT, 09/23
2 parents 2f02b97 + 86928cc commit 7325015

14 files changed

+116
-12
lines changed

defender-endpoint/linux-whatsnew.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,24 @@ This article is updated frequently to let you know what's new in the latest rele
4444
>
4545
> If you have any concerns or need assistance during this transition, contact support.
4646
47+
<details>
48+
<summary> Sept-2024 (Build: 101.24072.0001 | Release version: 30.124072.0001.0)</summary>
49+
50+
## Sept-2024 Build: 101.24072.0001 | Release version: 30.124072.0001.0
51+
52+
&ensp;Released: **September 23, 2024**<br/>
53+
&ensp;Published: **September 23, 2024**<br/>
54+
&ensp;Build: **101.24072.0001**<br/>
55+
&ensp;Release version: **30.124072.0001.0**<br/>
56+
&ensp;Engine version: **1.1.24060.6**<br/>
57+
&ensp;Signature version: **1.415.228.0**<br/>
58+
59+
**What's new**
60+
61+
- Added support for Ubuntu 24.04
62+
- Updated default engine version to `1.1.24060.6` and default signatures version to `1.415.228.0`.
63+
64+
</details>
4765

4866
<details>
4967
<summary> July-2024 (Build: 101.24062.0001 | Release version: 30.124062.0001.0)</summary>

defender-endpoint/mde-sdp-strategy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ Defender for Endpoint’s kernel drivers capture system-wide signals like proces
3535

3636
The process for rolling out software and driver updates for Defender for Endpoint is shown in this image:
3737

38-
:::image type="content" alt-text="process for rolling out software and driver updates for Defender for Endpoint" source="/defender/media/defender-endpoint/mde-software-driver-updates.png" lightbox="/defender/media/defender-endpoint/mde-software-driver-updates.png":::
38+
:::image type="content" alt-text="Screenshot that shows the process for rolling out software and driver updates for Defender for Endpoint." source="/defender/media/defender-endpoint/mde-software-driver-updates.png" lightbox="/defender/media/defender-endpoint/mde-software-driver-updates.png":::
3939

4040
### Microsoft SDP for monthly updates
4141

defender-endpoint/navigate-defender-endpoint-antivirus-exclusions.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ ms.topic: how-to
88
author: denisebmsft
99
ms.author: deniseb
1010
ms.custom: nextgen
11-
ms.date: 09/19/2024
11+
ms.date: 09/23/2024
1212
ms.reviewer: joshbregman
1313
manager: deniseb
1414
ms.collection:
@@ -239,6 +239,5 @@ Depending on what you're using, you might need to refer to the documentation for
239239
- [Submissions, suppressions and exclusions](submissions-suppressions-exclusions.md)
240240
- [Important points about exclusions](configure-exclusions-microsoft-defender-antivirus.md#important-points-about-exclusions)
241241
- [Common mistakes to avoid when defining exclusions](common-exclusion-mistakes-microsoft-defender-antivirus.md)
242-
- [Blog post: The Hitchhiker's Guide to Microsoft Defender for Endpoint exclusions](https://cloudbrothers.info/en/guide-to-defender-exclusions/)
243242

244243
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

defender-endpoint/supported-capabilities-by-platform.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ ms.collection:
1313
ms.topic: conceptual
1414
ms.subservice: onboard
1515
search.appverid: met150
16-
ms.date: 09/18/2024
16+
ms.date: 09/23/2024
1717
---
1818

1919
# Supported Microsoft Defender for Endpoint capabilities by platform
@@ -63,13 +63,13 @@ The following table gives information about the supported Microsoft Defender for
6363

6464
<sup>[1]</sup> Refers to the modern, unified solution for Windows Server 2012 R2 and Windows Server 2016. For more information, see [Onboard Windows Servers to the Defender for Endpoint service](configure-server-endpoints.md).
6565

66-
<sup>[2]</sup> Feature is currently in preview ([Microsoft Defender for Endpoint preview features](/defender-xdr/preview))
66+
<sup>[2]</sup> Feature is currently in preview ([Microsoft Defender for Endpoint preview features](/defender-xdr/preview)).
6767

68-
<sup>[3]</sup> Feature is currently in preview ([Microsoft Defender for Endpoint preview features](/defender-xdr/preview)) Or you can also use Live Response [2]
68+
<sup>[3]</sup> Feature is currently in preview ([Microsoft Defender for Endpoint preview features](/defender-xdr/preview)). Or you can also use Live Response [2].
6969

70-
<sup>[4]</sup> Collect file only, is currently in preview ([Microsoft Defender for Endpoint preview features](/defender-xdr/preview)) Or you can also use Live Response [2]
70+
<sup>[4]</sup> Collect file only. Or, you can use Live Response [2].
7171

72-
<sup>[5]</sup> Endpoint & network device discovery is supported on Windows Server 2019 or later, Windows 10, and Windows 11
72+
<sup>[5]</sup> Endpoint & network device discovery is supported on Windows Server 2019 or later, Windows 10, and Windows 11.
7373

7474
> [!NOTE]
7575
> Windows 7, 8.1, Windows Server 2008 R2 include support for the EDR sensor, and antivirus using System Center Endpoint Protection (SCEP).
Lines changed: 84 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,84 @@
1+
---
2+
title: Summarize identity information with Microsoft Copilot in Microsoft Defender
3+
description: Summarize an identity information with Microsoft Copilot in Microsoft Defender to investigate identities.
4+
ms.service: defender-xdr
5+
f1.keywords:
6+
- NOCSH
7+
ms.author: diannegali
8+
author: diannegali
9+
ms.localizationpriority: medium
10+
manager: deniseb
11+
audience: ITPro
12+
ms.collection:
13+
- m365-security
14+
- tier1
15+
- security-copilot
16+
ms.topic: conceptual
17+
search.appverid:
18+
- MOE150
19+
- MET150
20+
ms.date: 09/23/2024
21+
appliiesto:
22+
- Microsoft Defender XDR
23+
- Microsoft Sentinel in the unified security operations center (SOC) platform
24+
---
25+
26+
# Summarize identity information with Microsoft Copilot in Microsoft Defender
27+
28+
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
29+
30+
Security operations teams investigating users can easily understand identity information with the identity summary capability in [Microsoft Copilot for Security](/security-copilot/microsoft-security-copilot) in Microsoft Defender. Through generative AI and harnessing the power of Microsoft Defender for Identity, Copilot creates contextual insights about an identity in an organization, helping analysts quickly understand important data to speed up their investigation.
31+
32+
With the identity summary capability, analysts can immediately identify suspicious or risky identity-related changes and actions that can negatively impact an organization. The summary also includes potential misconfigurations that affects an identity. Using natural language, Copilot delivers clear and actionable user information that analysts can use in their incident investigation activities. The capability currently focuses on users and will include service accounts in its next iteration.
33+
34+
The identity summary contains essential information about an identity, including:
35+
36+
- The date when a user account is created, and whether the user account is of high, medium, or low criticality
37+
- Any unusual behavioral patterns related to sign in locations, sign in frequency, or frequency of failed sign in attempts
38+
- A user’s current role, including their department and position, and whether there are notable role changes compared to the user’s job title and department to highlight inconsistencies
39+
- Data about a user’s last sign in to a device, whether or not the device is associated to the user, in the last 30 days
40+
- Authentication methods and applications used
41+
- Risks associated with a user based on Microsoft Entra ID
42+
- General information like a user’s professional title and contact information, department, and their manager’s contact information
43+
44+
The identity summary capability is available in the Microsoft Defender portal for customers who have provisioned access to Copilot for Security. Users who access the Copilot for Security standalone portal can use this capability through the Microsoft Defender XDR plugin. Know more about [preinstalled plugins in Copilot for Security](/security-copilot/manage-plugins#preinstalled-plugins).
45+
46+
This guide describes what the script analysis capability is and how it works, including how you can provide feedback on the results generated.
47+
48+
## Summarize identity information
49+
50+
You can access the identity summary capability in the following ways:
51+
52+
- From an incident page, choose an identity on the incident graph and then (1) select **User details**. In the user details pane, (2) select **Summarize**. The results are displayed in the Copilot side panel.
53+
54+
:::image type="content" source="/defender/media/copilot-in-defender/identity-summary/identity-incident-graph-small.png" alt-text="Screenshot showing the Summarize option in the user details pane." lightbox="/defender/media/copilot-in-defender/identity-summary/identity-incident-graph.png":::
55+
56+
- Alternatively, you can select **Go to user page** on the bottom of the user details pane to open the user page. Copilot automatically generates the identity summary and displays the side panel upon opening the user page.
57+
58+
- You can also access the identity summary capability by choosing a user in the **Assets** tab of an incident. Select **Summarize** in the user details pane to generate the identity summary.
59+
60+
:::image type="content" source="/defender/media/copilot-in-defender/identity-summary/identity-assets-small.png" alt-text="Screenshot showing the Assets tab and a user account highlighted." lightbox="/defender/media/copilot-in-defender/identity-summary/identity-assets.png":::
61+
62+
- From the main menu, navigate to **Assets > Identities**. Select a username from the list, then select **View user page** to open the user page. Copilot automatically generates the identity summary and displays the side panel upon opening the user page.
63+
64+
:::image type="content" source="/defender/media/copilot-in-defender/identity-summary/identity-identities-small.png" alt-text="Screenshot highlighting the view user page option in an username search within Identities." lightbox="/defender/media/copilot-in-defender/identity-summary/identity-identities.png":::
65+
66+
- Type a username in the Microsoft Defender portal’s **search box** then select the username from the search results. In the user details side panel, select **Summarize** to generate the identity summary.
67+
68+
Review the identity summary results. You can copy the results to clipboard, regenerate the results, or open Security Copilot by selecting the More actions ellipsis (...) on top of the identity summary card. You can extend your investigation of identity using prompts and other plugins in the Copilot for Security portal.
69+
70+
> [!TIP]
71+
> When investigating users in the Copilot for Security portal, Microsoft recommends including the word ***Defender*** in your prompts to ensure that the identity summary capability delivers the results. For example, you can use the prompt *Show the Defender summary of this user in the last {time frame}* to generate the identity summary of a user account within the time frame indicated. You can specify up to 120 days on the time frame, with the default being 30 days when you don’t indicate one.
72+
73+
Microsoft highly encourages you to provide feedback to Copilot, as it’s crucial for a capability’s continuous improvement. To provide feedback, navigate to the bottom of the Copilot side panel and select the feedback icon ![Screenshot of the feedback icon for Copilot in Defender cards](/defender/media/copilot-in-defender/create-report/copilot-defender-feedback.png).
74+
75+
:::image type="content" source="/defender/media/copilot-in-defender/identity-summary/feedback-textbox.png" alt-text="Screenshot that shows the Feedback text box where you can share your feedback.":::
76+
77+
Fill in the dedicated text box to share your thoughts, experiences, and requests. Microsoft values your feedback and takes it seriously in our commitment to enhance Copilot’s performance and user experience.
78+
79+
## See also
80+
81+
- [Get started with Microsoft Copilot for Security](/security-copilot/get-started-security-copilot)
82+
- [Learn about other Copilot for Security embedded experiences](/security-copilot/experiences-security-copilot)
83+
84+
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]
25.5 KB
Loading
140 KB
Loading
440 KB
Loading
49.3 KB
Loading
143 KB
Loading

0 commit comments

Comments
 (0)