Skip to content

Commit 9062a36

Browse files
Merge pull request #1015 from MicrosoftDocs/v-mathavale-9194141
as per 9194141
2 parents 17e50f8 + 2cf89c2 commit 9062a36

File tree

4 files changed

+24
-68
lines changed

4 files changed

+24
-68
lines changed

.openpublishing.redirection.defender.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -199,6 +199,11 @@
199199
"source_path": "defender-endpoint/attack-simulations.md",
200200
"redirect_url": "/defender-endpoint/defender-endpoint-demonstrations",
201201
"redirect_document_id": true
202+
},
203+
{
204+
"source_path": "defender-endpoint/mssp-support.md",
205+
"redirect_url": "/defender-endpoint/configure-mssp-support",
206+
"redirect_document_id": true
202207
}
203208
]
204209
}

defender-endpoint/TOC.yml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1401,8 +1401,6 @@
14011401
href: api/exposed-apis-create-app-partners.md
14021402
- name: Fetch alerts from customer tenant
14031403
href: api/fetch-alerts-mssp.md
1404-
- name: Managed security service provider opportunity
1405-
href: mssp-support.md
14061404
- name: Partner integration scenarios
14071405
items:
14081406
- name: Technical partner opportunities

defender-endpoint/configure-mssp-support.md

Lines changed: 19 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ ms.collection:
1313
- tier3
1414
ms.topic: conceptual
1515
search.appverid: met150
16-
ms.date: 12/18/2020
16+
ms.date: 07/24/2024
1717
---
1818

1919
# Configure managed security service provider integration
@@ -27,41 +27,45 @@ ms.date: 12/18/2020
2727

2828
> Want to experience Defender for Endpoint? [Sign up for a free trial.](https://signup.microsoft.com/create-account/signup?products=7f379fee-c4f9-4278-b0a1-e4c8c2fcdf7e&ru=https://aka.ms/MDEp2OpenTrial?ocid=docs-mssp-support-abovefoldlink)
2929
30-
[!include[Prerelease information](../includes/prerelease.md)]
30+
## Managed security service provider partnership opportunities
3131

32-
To enable the managed security service provider (MSSP) integration, follow the guidance in this article.
32+
Security is recognized as a key component in running an enterprise; however, some organizations might not have the capacity or expertise to have a dedicated security operations team to manage the security of their endpoints and network, others may want to have a second set of eyes to review alerts in their network.
3333

34-
> [!NOTE]
35-
> The following terms are used in this article to distinguish between the service provider and service consumer:
36-
>
37-
> - MSSPs: Security organizations that offer to monitor and manage security devices for an organization.
38-
> - MSSP customers: Organizations that engage the services of MSSPs.
34+
To address this demand, managed security service providers (MSSP) offer to deliver managed detection and response (MDR) services on top of Defender for Endpoint.
3935

40-
The integration allows MSSPs to take the following actions:
36+
Defender for Endpoint adds partnership opportunities for this scenario and allows MSSPs to take the following actions:
4137

4238
- Get access to MSSP customer's Microsoft Defender portal
43-
- Get email notifications, and
39+
- Get email notifications
4440
- Fetch alerts through security information and event management (SIEM) tools
4541

46-
Before MSSPs can take these actions, the MSSP customer needs to grant access to their Defender for Endpoint tenant so that the MSSP can access the portal.
42+
> [!NOTE]
43+
> The following terms are used in this article to distinguish between the service provider and service consumer:
44+
> - MSSPs: Security organizations who monitor and manage security devices for organizations (customers).
45+
> - MSSP customers: Organizations who engage the services of MSSPs.
4746
48-
Typically, MSSP customers take the initial configuration steps to grant MSSPs access to their Windows Defender Security Central tenant. After access is granted, the MSSP or customer can do the other configuration steps. In general, these are the configuration steps to complete:
47+
## MSSP integration
48+
49+
To enable MSSP integration, the MSSP customer needs to grant access to their Defender for Endpoint tenant so that the MSSP can access their Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)).
50+
51+
After access is granted, the MSSP or customer can do the other configuration steps. In general, the following table summarizes the configuration steps to complete:
4952

5053
| Step | Who does it|
5154
|---|---|
52-
| **Grant the MSSP access to Microsoft Defender XDR**. This action grants the MSSP access to the MSSP customer's Defender for Endpoint tenant. | MSSP Customer |
55+
| **Grant the MSSP access to the Microsoft Defender portal**. This action grants the MSSP access to the MSSP customer's Microsoft Defender portal. | MSSP Customer |
5356
| **Configure alert notifications sent to MSSPs**. This action lets the MSSPs know what alerts they need to address for the MSSP customer. | MSSP customer or MSSP |
5457
| **Fetch alerts from MSSP customer's tenant into SIEM system**. This action allows MSSPs to fetch alerts in SIEM tools. | MSSP |
5558
| **Fetch alerts from MSSP customer's tenant using APIs**. This action allows MSSPs to fetch alerts using APIs. | MSSP |
5659

57-
## Multi-tenant access for MSSPs
60+
## Multitenant access for MSSPs
5861

59-
For information on how to implement a multitenant delegated access, see [Multi-tenant access for Managed Security Service Providers](https://techcommunity.microsoft.com/t5/microsoft-defender-atp/multi-tenant-access-for-managed-security-service-providers/ba-p/1533440).
62+
For information on how to implement a multitenant delegated access, see [multitenant access for Managed Security Service Providers](https://techcommunity.microsoft.com/t5/microsoft-defender-atp/multi-tenant-access-for-managed-security-service-providers/ba-p/1533440).
6063

6164
## Related articles
6265

6366
- [Grant MSSP access to the portal](grant-mssp-access.md)
6467
- [Access the MSSP customer portal](access-mssp-portal.md)
6568
- [Configure alert notifications](configure-mssp-notifications.md)
6669
- [Fetch alerts from customer tenant](api/fetch-alerts-mssp.md)
70+
6771
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

defender-endpoint/mssp-support.md

Lines changed: 0 additions & 51 deletions
This file was deleted.

0 commit comments

Comments
 (0)