Skip to content

Commit 9dbb944

Browse files
authored
Merge branch 'main' into repo_sync_working_branch
2 parents 3ad4b52 + 2e0803d commit 9dbb944

19 files changed

+17
-12
lines changed

defender-endpoint/configure-server-exclusions-microsoft-defender-antivirus.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ description: Windows Server includes automatic exclusions, based on server role.
66
ms.service: defender-endpoint
77
ms.subservice: ngp
88
ms.localizationpriority: medium
9-
ms.date: 08/07/2023
9+
ms.date: 08/21/2023
1010
author: siosulli
1111
ms.author: siosulli
1212
ms.topic: conceptual
@@ -29,7 +29,7 @@ search.appverid: met150
2929

3030
**Platforms**
3131

32-
- Windows
32+
- Windows Server
3333

3434
This article describes types of exclusions that you don't have to define for Microsoft Defender Antivirus:
3535

defender-xdr/manage-incidents.md

Lines changed: 15 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -11,13 +11,14 @@ manager: deniseb
1111
audience: ITPro
1212
ms.collection:
1313
- m365-security
14+
- usx-security
1415
- tier1
1516
ms.custom: admindeeplinkDEFENDER
1617
ms.topic: conceptual
1718
search.appverid:
1819
- MOE150
1920
- MET150
20-
ms.date: 08/19/2024
21+
ms.date: 08/21/2024
2122
appliesto:
2223
- Microsoft Defender XDR
2324
- Microsoft Sentinel in the Microsoft Defender portal
@@ -149,7 +150,7 @@ You can also add your own comments using the comment box available within the ac
149150
> [!IMPORTANT]
150151
> Some information in this article relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
151152
>
152-
> The export incident data feature is currently available to Microsoft Defender XDR and Microsoft Defender unified security operations center (SOC) platform customers with the Microsoft Copilot for security license.
153+
> The export incident data feature is currently available to Microsoft Defender XDR and Microsoft unified security operations center (SOC) platform customers with the Microsoft Copilot for security license.
153154
154155
You can export an incident's data to PDF through the **Export incident as PDF** function and save it into PDF format. This function allows security teams to review an incident's details offline at any given time.
155156

@@ -163,30 +164,34 @@ The incident data exported includes the following information:
163164

164165
Here's an example of the exported PDF:
165166

166-
:::image type="content" source="/defender/media/incidents-queue/export-incident-results-small.png" alt-text="Screenshot of the exported PDF's first page." lightbox="/defender/media/incidents-queue/export-incident-results.png":::
167+
:::image type="content" source="/defender/media/incidents-queue/export-results-small.png" alt-text="Screenshot of the exported PDF's first page." lightbox="/defender/media/incidents-queue/export-results.png":::
167168

168169
If you have the [Copilot for Security](/security-copilot/microsoft-security-copilot) license, the exported PDF contains the following additional incident data:
169170

170171
- [Incident summary](security-copilot-m365d-incident-summary.md)
171172
- [Incident report](security-copilot-m365d-create-incident-report.md)
172173

173-
The export to PDF function is also available in the Copilot side panel of a generated incident report.
174+
The export to PDF function is also available in the Copilot side panel. When you select the **More actions** ellipsis (...) on the upper right corner of the incident report results card, you can choose **Export incident as PDF**.
174175

175176
![Screenshot of additional actions in the incident report results card.](/defender/media/incidents-queue/export-incident-more-actions1.png)
176177

177178
To generate the PDF, perform the following steps:
178179

179-
1. Open an incident page. Select the **More actions** ellipsis (...) on the upper right corner and choose **Export incident as PDF**. The function becomes grayed out while the PDF is being generated.
180+
1. Open an incident page. Select the **More actions** ellipsis (...) on the upper right corner and choose **Export incident as PDF**.
180181

181-
:::image type="content" source="/defender/media/incidents-queue/export-incident-main-small.png" alt-text="Screenshot highlighting the export incident to PDF option." lightbox="/defender/media/incidents-queue/export-incident-main.png":::
182+
:::image type="content" source="/defender/media/incidents-queue/export-ellipsis-small.png" alt-text="Screenshot highlighting the export incident to PDF option." lightbox="/defender/media/incidents-queue/export-ellipsis.png":::
182183

183-
1. A dialog box appears, indicating that the PDF is being generated. Select **Got it** to close the dialog box. Additionally, a status message indicating the current state of the download appears below the incident title. The export process may take a few minutes depending on the incident's complexity and the amount of data to be exported.
184+
1. In the dialog box that appears next, confirm the incident information that you want to include or exclude in the PDF. All incident information is selected by default. Select **Export PDF** to proceed.
184185

185-
:::image type="content" source="/defender/media/incidents-queue/export-incident-predownload-small.png" alt-text="Screenshot highlighting export message and status before download." lightbox="/defender/media/incidents-queue/export-incident-predownload.png":::
186+
:::image type="content" source="/defender/media/incidents-queue/export-options.png" alt-text="Screenshot highlighting the export incident to PDF option.":::
186187

187-
1. Once the PDF is ready, the status message indicates that the PDF is ready and another dialog box appears. Select **Download** from the dialog box to save the PDF to your device.
188+
1. A status message indicating the current state of the download appears below the incident title. The export process may take a few minutes depending on the incident's complexity and the amount of data to be exported.
188189

189-
:::image type="content" source="/defender/media/incidents-queue/export-incident-download-small.png" alt-text="Screenshot highlighting export message and status when download is available." lightbox="/defender/media/incidents-queue/export-incident-download.png":::
190+
:::image type="content" source="/defender/media/incidents-queue/export-prepare-small.png" alt-text="Screenshot highlighting export message and status before download." lightbox="/defender/media/incidents-queue/export-prepare.png":::
191+
192+
1. Another dialog box appears indicating that the PDF is ready. Select **Download** from the dialog box to save the PDF to your device. The status message below the incident title also updates to indicate that the download is available.
193+
194+
:::image type="content" source="/defender/media/incidents-queue/export-download-small.png" alt-text="Screenshot highlighting export message and status when download is available." lightbox="/defender/media/incidents-queue/export-download.png":::
190195

191196
The report is cached for a couple of minutes. The system provides the previously generated PDF if you try to export the same incident again within a short time frame. To generate a newer version of the PDF, wait for a few minutes for the cache to expire.
192197

105 KB
Loading
253 KB
Loading
62.1 KB
Loading
156 KB
Loading
-172 KB
Binary file not shown.
-445 KB
Binary file not shown.
-176 KB
Binary file not shown.
-454 KB
Binary file not shown.

0 commit comments

Comments
 (0)