You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/configure-mssp-support.md
+19-15Lines changed: 19 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -13,7 +13,7 @@ ms.collection:
13
13
- tier3
14
14
ms.topic: conceptual
15
15
search.appverid: met150
16
-
ms.date: 12/18/2020
16
+
ms.date: 07/24/2024
17
17
---
18
18
19
19
# Configure managed security service provider integration
@@ -27,41 +27,45 @@ ms.date: 12/18/2020
27
27
28
28
> Want to experience Defender for Endpoint? [Sign up for a free trial.](https://signup.microsoft.com/create-account/signup?products=7f379fee-c4f9-4278-b0a1-e4c8c2fcdf7e&ru=https://aka.ms/MDEp2OpenTrial?ocid=docs-mssp-support-abovefoldlink)
## Managed security service provider partnership opportunities
31
31
32
-
To enable the managed security service provider (MSSP) integration, follow the guidance in this article.
32
+
Security is recognized as a key component in running an enterprise; however, some organizations might not have the capacity or expertise to have a dedicated security operations team to manage the security of their endpoints and network, others may want to have a second set of eyes to review alerts in their network.
33
33
34
-
> [!NOTE]
35
-
> The following terms are used in this article to distinguish between the service provider and service consumer:
36
-
>
37
-
> - MSSPs: Security organizations that offer to monitor and manage security devices for an organization.
38
-
> - MSSP customers: Organizations that engage the services of MSSPs.
34
+
To address this demand, managed security service providers (MSSP) offer to deliver managed detection and response (MDR) services on top of Defender for Endpoint.
39
35
40
-
The integration allows MSSPs to take the following actions:
36
+
Defender for Endpoint adds partnership opportunities for this scenario and allows MSSPs to take the following actions:
41
37
42
38
- Get access to MSSP customer's Microsoft Defender portal
43
-
- Get email notifications, and
39
+
- Get email notifications
44
40
- Fetch alerts through security information and event management (SIEM) tools
45
41
46
-
Before MSSPs can take these actions, the MSSP customer needs to grant access to their Defender for Endpoint tenant so that the MSSP can access the portal.
42
+
> [!NOTE]
43
+
> The following terms are used in this article to distinguish between the service provider and service consumer:
44
+
> - MSSPs: Security organizations who monitor and manage security devices for organizations (customers).
45
+
> - MSSP customers: Organizations who engage the services of MSSPs.
47
46
48
-
Typically, MSSP customers take the initial configuration steps to grant MSSPs access to their Windows Defender Security Central tenant. After access is granted, the MSSP or customer can do the other configuration steps. In general, these are the configuration steps to complete:
47
+
## MSSP integration
48
+
49
+
To enable MSSP integration, the MSSP customer needs to grant access to their Defender for Endpoint tenant so that the MSSP can access their Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)).
50
+
51
+
After access is granted, the MSSP or customer can do the other configuration steps. In general, the following table summarizes the configuration steps to complete:
49
52
50
53
| Step | Who does it|
51
54
|---|---|
52
-
|**Grant the MSSP access to Microsoft Defender XDR**. This action grants the MSSP access to the MSSP customer's Defender for Endpoint tenant. | MSSP Customer |
55
+
|**Grant the MSSP access to the Microsoft Defender portal**. This action grants the MSSP access to the MSSP customer's Microsoft Defender portal. | MSSP Customer |
53
56
|**Configure alert notifications sent to MSSPs**. This action lets the MSSPs know what alerts they need to address for the MSSP customer. | MSSP customer or MSSP |
54
57
|**Fetch alerts from MSSP customer's tenant into SIEM system**. This action allows MSSPs to fetch alerts in SIEM tools. | MSSP |
55
58
|**Fetch alerts from MSSP customer's tenant using APIs**. This action allows MSSPs to fetch alerts using APIs. | MSSP |
56
59
57
-
## Multi-tenant access for MSSPs
60
+
## Multitenant access for MSSPs
58
61
59
-
For information on how to implement a multitenant delegated access, see [Multi-tenant access for Managed Security Service Providers](https://techcommunity.microsoft.com/t5/microsoft-defender-atp/multi-tenant-access-for-managed-security-service-providers/ba-p/1533440).
62
+
For information on how to implement a multitenant delegated access, see [multitenant access for Managed Security Service Providers](https://techcommunity.microsoft.com/t5/microsoft-defender-atp/multi-tenant-access-for-managed-security-service-providers/ba-p/1533440).
60
63
61
64
## Related articles
62
65
63
66
-[Grant MSSP access to the portal](grant-mssp-access.md)
64
67
-[Access the MSSP customer portal](access-mssp-portal.md)
0 commit comments