You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/configure-asset-rules.md
+16-7Lines changed: 16 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.collection:
12
12
- tier2
13
13
ms.topic: conceptual
14
14
search.appverid: met150
15
-
ms.date: 07/11/2023
15
+
ms.date: 09/04/2024
16
16
---
17
17
18
18
# Asset rule management - Dynamic rules for devices
@@ -37,24 +37,31 @@ Dynamic rules can help manage device context by assigning tags and device values
37
37
38
38
A rule can be based on device name, domain, OS platform, internet facing status, onboarding status and manual device tags. You can select or create a tag that will be applied based on the conditions you've set.
39
39
40
+
> [!IMPORTANT]
41
+
> Use of [dynamic device tagging](/defender-xdr/configure-asset-rules) capabilities in Defender for Endpoint to tag devices with `MDE-Management` isn't currently supported with security settings management. Devices tagged through this capability don't successfully enroll. This is currently under investigation.
42
+
40
43
The following steps guide you on how to create a new dynamic rule in Microsoft Defender XDR:
41
44
42
45
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) as a user who can view and perform actions on all devices.
46
+
43
47
2. In the navigation pane, select **Settings**\>**Microsoft Defender XDR**\>**Asset Rule Management**.
48
+
44
49
3. Select **Create a new rule**.
50
+
45
51
4. Enter a **Rule name** and **Description***.
52
+
46
53
5. Select **Next** to choose the conditions you want to assign:
47
54
48
-
:::image type="content" source="/defender/media/defender/rule-conditions.png" alt-text="Screenshot of the Rule conditions page" lightbox="/defender/media/defender/rule-conditions.png":::
55
+
:::image type="content" source="/defender/media/defender/rule-conditions.png" alt-text="Screenshot of the Rule conditions page" lightbox="/defender/media/defender/rule-conditions.png":::
49
56
50
57
6. Select **Next** and choose the tag to apply to this rule.
51
58
52
-
:::image type="content" source="/defender/media/defender/actions-to-apply.png" alt-text="Screenshot of the actions page" lightbox="/defender/media/defender/actions-to-apply.png":::
59
+
:::image type="content" source="/defender/media/defender/actions-to-apply.png" alt-text="Screenshot of the actions page" lightbox="/defender/media/defender/actions-to-apply.png":::
53
60
54
61
7. Select **Next** to review and finish creating the rule and then select **Submit**.
55
62
56
-
>[!Note]
57
-
> It may take up to 1 hour for changes to be reflected in the portal.
63
+
>[!NOTE]
64
+
> It may take up to 1 hour for changes to be reflected in the portal.
58
65
59
66
### Dynamic tags in the Device Inventory
60
67
@@ -63,13 +70,15 @@ You can see the dynamic tags assigned in the Device Inventory view.
63
70
To see tags on individual devices:
64
71
65
72
1. Select **Devices** from the **Assets** navigation menu in the [Microsoft Defender portal](https://security.microsoft.com).
73
+
66
74
2. In the **Device Inventory** page, select the device name that you want to view.
75
+
67
76
3. Select **Manage tags**.
68
77
69
-
:::image type="content" source="/defender/media/defender/manage-machine-tags.png" alt-text="Screenshot of the machine tags page" lightbox="/defender/media/defender/manage-machine-tags.png":::
78
+
:::image type="content" source="/defender/media/defender/manage-machine-tags.png" alt-text="Screenshot of the machine tags page" lightbox="/defender/media/defender/manage-machine-tags.png":::
70
79
71
80
### Updating rules
72
81
73
-
Dynamic tags and device values set by dynamic rules can't be manually updated. To edit, delete or turn off a rule, in the **Asset Rule Management** page select the rule and choose the action you wish to take:
82
+
Dynamic tags and device values set by dynamic rules can't be manually updated. To edit, delete or turn off a rule, in the **Asset Rule Management** page select the rule and choose an action.
74
83
75
84
:::image type="content" source="/defender/media/defender/update-rule.png" alt-text="Screenshot of the rule details page" lightbox="/defender/media/defender/update-rule.png":::
0 commit comments