Skip to content

Commit 9fe6e5a

Browse files
committed
Merge branch 'main' of https://github.com/MicrosoftDocs/defender-docs-pr into yelevin/rename-link-to-move
2 parents 1404073 + f344433 commit 9fe6e5a

File tree

4 files changed

+80
-106
lines changed

4 files changed

+80
-106
lines changed

.openpublishing.redirection.defender-endpoint.json

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,11 @@
7979
"source_path": "defender-endpoint/pilot-deploy-defender-endpoint.md",
8080
"redirect_url": "/defender-xdr/pilot-deploy-defender-endpoint",
8181
"redirect_document_id": false
82-
}
82+
},
83+
{
84+
"source_path": "defender-endpoint/monthly-security-summary-report.md",
85+
"redirect_url": "/defender-endpoint/threat-protection-reports#monthly-security-summary",
86+
"redirect_document_id": true
87+
}
8388
]
8489
}

defender-endpoint/TOC.yml

Lines changed: 19 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -605,9 +605,6 @@
605605
- name: Manage device group and tags
606606
href: machine-tags.md
607607

608-
- name: Host firewall reporting in Microsoft Defender for Endpoint
609-
href: host-firewall-reporting.md
610-
611608
- name: Tamper resiliency
612609
href: tamper-resiliency.md
613610

@@ -633,8 +630,6 @@
633630
href: attack-surface-reduction-rules-deployment-operationalize.md
634631
- name: Attack surface reduction rules reference
635632
href: attack-surface-reduction-rules-reference.md
636-
- name: Attack surface reduction rules report
637-
href: attack-surface-reduction-rules-report.md
638633
- name: Troubleshoot attack surface reduction rules
639634
href: troubleshoot-asr-rules.md
640635
- name: Enable ASR rules alternate configuration methods
@@ -665,8 +660,6 @@
665660
href: device-control-deploy-manage-gpo.md
666661
- name: Device control frequently asked questions
667662
href: device-control-faq.md
668-
- name: Device control reports
669-
href: device-control-report.md
670663
- name: Exploit protection
671664
items:
672665
- name: Protect devices from exploits
@@ -703,8 +696,6 @@
703696
items:
704697
- name: Web threat protection overview
705698
href: web-threat-protection.md
706-
- name: Monitor web security
707-
href: web-protection-monitoring.md
708699
- name: Respond to web threats
709700
href: web-protection-response.md
710701
- name: Web content filtering
@@ -910,13 +901,6 @@
910901

911902
- name: Diagnostics for Microsoft Defender Antivirus
912903
items:
913-
- name: Device health reports
914-
href: device-health-reports.md
915-
items:
916-
- name: Microsoft Defender Antivirus health report
917-
href: device-health-microsoft-defender-antivirus-health.md
918-
- name: Sensor health and OS report
919-
href: device-health-sensor-health-os.md
920904
- name: Microsoft Defender Core service overview
921905
href: microsoft-defender-core-service-overview.md
922906
- name: Microsoft Defender Core service configurations and experimentation
@@ -1121,14 +1105,27 @@
11211105
items:
11221106
- name: Reports
11231107
items:
1124-
- name: Monthly security summary
1125-
href: monthly-security-summary-report.md
1126-
- name: Create custom reports using Power BI
1127-
href: api/api-power-bi.md
1128-
- name: Threat protection reports
1108+
- name: Microsoft Defender for Endpoint reports
11291109
href: threat-protection-reports.md
1110+
- name: Device health reports
1111+
href: device-health-reports.md
1112+
items:
1113+
- name: Microsoft Defender Antivirus health report
1114+
href: device-health-microsoft-defender-antivirus-health.md
1115+
- name: Sensor health and OS report
1116+
href: device-health-sensor-health-os.md
1117+
- name: Host firewall reporting
1118+
href: host-firewall-reporting.md
1119+
- name: Web protection and monitoring reports
1120+
href: web-protection-monitoring.md
1121+
- name: Device control reports
1122+
href: device-control-report.md
1123+
- name: Attack surface reduction rules report
1124+
href: attack-surface-reduction-rules-report.md
11301125
- name: Aggregated reports
1131-
href: aggregated-reporting.md
1126+
href: aggregated-reporting.md
1127+
- name: Create custom reports using Power BI
1128+
href: api/api-power-bi.md
11321129
- name: Configure integration with other Microsoft solutions
11331130
items:
11341131
- name: Configure conditional access

defender-endpoint/monthly-security-summary-report.md

Lines changed: 0 additions & 65 deletions
This file was deleted.
Lines changed: 55 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Threat protection report in Microsoft Defender for Endpoint
3-
description: Track alert detections, categories, and severity using the threat protection report.
2+
title: Microsoft Defender for Endpoint reports
3+
description: Access the various reports for devices, protection features, and more in Microsoft Defender for Endpoint.
44
ms.service: defender-endpoint
55
ms.author: deniseb
66
author: denisebmsft
@@ -12,32 +12,51 @@ ms.collection:
1212
- tier2
1313
ms.topic: conceptual
1414
search.appverid: met150
15-
ms.date: 1/31/2024
15+
ms.date: 2/04/2025
1616
---
1717

18-
# Threat protection report in Microsoft Defender for Endpoint
18+
# Microsoft Defender for Endpoint reports
1919

2020
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2121

22-
2322
**Applies to:**
2423

2524
- [Microsoft Defender for Endpoint Plan 1](microsoft-defender-endpoint.md)
2625
- [Microsoft Defender for Endpoint Plan 2](microsoft-defender-endpoint.md)
2726
- [Microsoft Defender XDR](/defender-xdr)
2827

29-
> [!IMPORTANT]
30-
> The Microsoft Defender for Endpoint Threat Protection report page is now deprecated and is no longer available. Microsoft recommends that you transition to either the Defender XDR alerts or advanced hunting to understand endpoint threat protection details. See the following sections for more information.
28+
This article provides an overview of the reports available to Microsoft Defender for Endpoint users. It offers information on various reports that can be used to collect data, summarize findings, and obtain recommended actions when applicable.
29+
30+
## Monthly security summary
31+
32+
The **monthly security summary** report helps organizations get a visual summary of key findings and overall preventative actions taken to enhance the organization's overall security posture completed in the last 30 or 90 days. It helps you identify areas of strength and improvement, track your progress over time, and prioritize your actions based on risk and impact.
33+
34+
To access this report, navigate to **Reports > Endpoints > Monthly Security Summary**. The monthly security summary report contains the following sections:
35+
36+
| Section | Description |
37+
|---------|---------|
38+
| [Microsoft Secure Score](/defender-xdr/microsoft-secure-score) | Microsoft Secure Score is a measurement of an organization's security posture and how well you have implemented security best practices and recommendations across the devices in your organization. The secure score card shows how the overall cybersecurity strength of an organization has improved in the past month and how it compares to other companies with similar number of managed devices. |
39+
|Secure score compared to other organizations | This score is an evaluation of an organization's security score in relation to organizations of a similar size. It's a way to benchmark an organization's performance in implementing security measures compared to other organizations of an equivalent size. |
40+
| Devices onboarded | The devices card provides information on the number of devices that were onboarded in the last month as well as devices still not onboarded. Onboarding devices are essential for enabling protection and detection capabilities. |
41+
| Protection against specific threats | This card shows how effective your defenses are against common attack vectors such as phishing and ransomware. A higher number indicates better defense in place against phishing and ransomware. The report shows how many threats were blocked or mitigated in the last month and how your protection level has increased. |
42+
| Web content monitoring and filtering | Shows the number of malicious URLs that were blocked by Microsoft Defender for Endpoint in the last month. The report also shows the categories of URLs that were blocked and the number of clicks for each category. |
43+
| Suspicious or malicious activities | Track how many incidents and alerts were resolved in the past month using the incidents card. The card also shows all active incidents and alerts that require attention. You'll also be able to see a list of the top 10 severe incidents, their status, number of alerts, and the impacted devices and users. |
3144

32-
## Use the alert queue filter in Defender XDR
45+
You can generate a PDF report of the summary, by selecting **Generate PDF report**. The generated report is a summary of the last 30 days.
3346

34-
Due to the deprecation of the Defender for Endpoint Threat protection report, you can use the Defender XDR alerts view, filtered against Defender for Endpoint, to see the current status of alerts for protected devices. For alert status, such as *unresolved*, you can filter against *New* and *In progress* items. [Learn more about Defender XDR Alerts](/defender-xdr/investigate-alerts).
47+
## Threat protection report
3548

36-
## Use Advanced hunting queries
49+
To gather data on Defender for Endpoint threat protection information, you can use the Microsoft Defender portal's alerts queue or create advanced hunting queries. The following sections provide guidance on how to use these tools to find the information you need.
3750

38-
Due to the deprecation of the Defender for Endpoint Threat protection report, you can use Advanced hunting queries to find Defender for Endpoint threat protection information. Currently there's no alert status in Advanced hunting elements that maps to resolve/unresolve. [Learn more about Advanced hunting in Defender XDR](/defender-xdr/advanced-hunting-overview). See the following section for a sample advanced hunting query that shows endpoint related threat protection details.
51+
### Use the alert queue filter in the Microsoft Defender portal
3952

40-
### Alert status
53+
You can use the Microsoft Defender portal alerts view, using Defender for Endpoint as the **detection source**, to see the current status of alerts for protected devices. Use the **Status** filter to see *New*, *In progress*, and *Resolved* alerts. [Learn more about the alerts queue](/defender-xdr/investigate-alerts).
54+
55+
### Use advanced hunting queries
56+
57+
You can also use advanced hunting queries to find Defender for Endpoint threat protection information. [Learn more about advanced hunting in Defender XDR](/defender-xdr/advanced-hunting-overview). The following sample advanced hunting queries show alert-related information.
58+
59+
#### Alert information by severity, detection source, and category
4160

4261
```kusto
4362
// Severity
@@ -49,7 +68,7 @@ AlertInfo
4968
// Detection source
5069
AlertInfo
5170
| where Timestamp > startofday(now()) // Today
52-
| summarize count() by Severity
71+
| summarize count() by DetectionSource
5372
| render columnchart
5473
5574
// Detection category
@@ -59,14 +78,13 @@ AlertInfo
5978
| render columnchart
6079
```
6180

62-
63-
### Alert trend
81+
#### Alert trends by severity, detection source, and category
6482

6583
```kusto
6684
// Severity
6785
AlertInfo
6886
| where Timestamp > ago(30d)
69-
| summarize count() by DetectionSource , bin(Timestamp, 1d)
87+
| summarize count() by Severity , bin(Timestamp, 1d)
7088
| render timechart
7189
7290
// Detection source
@@ -82,7 +100,26 @@ AlertInfo
82100
| render timechart
83101
```
84102

85-
## Related articles
103+
## Reports about Defender for Endpoint capabilities
104+
105+
The following reports provide in-depth information about events and actions related to Defender for Endpoint capabilities:
106+
107+
- [Device health reports](device-health-reports.md)
108+
- [Microsoft Defender Antivirus health report](device-health-microsoft-defender-antivirus-health.md)
109+
- [Sensor health & OS report](device-health-sensor-health-os.md)
110+
- [Host firewall reporting](host-firewall-reporting.md)
111+
- [Web protection monitoring report](web-protection-monitoring.md)
112+
- [Attack surface reduction rules report](attack-surface-reduction-rules-report.md)
113+
- [Device control report](device-control-report.md)
114+
115+
## Create custom reports using Power BI
116+
117+
You can also create customized reports using Power BI. To create your own report, see [Create custom reports using Power BI](/defender-endpoint/api/api-power-bi).
118+
119+
## Aggregated reporting
120+
121+
You can review all signals collected by Defender for Endpoint by turning on aggregated reporting.
122+
123+
To turn aggregated reporting on, go to **Settings > Endpoints > Advanced features**. Toggle on the **Aggregated reporting** feature. Learn more about [aggregated reporting in Defender for Endpoint](/defender-endpoint/aggregated-reporting).
86124

87-
- [Device health and compliance report](device-health-reports.md)
88125
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

0 commit comments

Comments
 (0)