You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/mto-advanced-hunting.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Advanced hunting in multi-tenant management in Microsoft Defender XDR
3
-
description: Learn about advanced hunting in multi-tenant management in Microsoft Defender XDR
2
+
title: Advanced hunting in multitenant management in Microsoft Defender XDR
3
+
description: Learn about advanced hunting in multitenant management in Microsoft Defender XDR
4
4
search.appverid: met150
5
5
ms.service: defender-xdr
6
6
ms.author: siosulli
@@ -20,13 +20,13 @@ appliesto:
20
20
- Microsoft Sentinel in the Microsoft Defender portal
21
21
---
22
22
23
-
# Advanced hunting in multi-tenant management for Microsoft Defender XDR
23
+
# Advanced hunting in multitenant management for Microsoft Defender XDR
24
24
25
-
Advanced hunting in multi-tenant management for Microsoft Defender XDR allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time. If you have tenants with a Microsoft Sentinel workspace onboarded to the unified security operations platform, search for SIEM data together with XDR data across multiple tenants.
25
+
Advanced hunting in multitenant management for Microsoft Defender XDR allows you to proactively hunt for intrusion attempts and breach activity in email, data, devices, and accounts across multiple tenants at the same time. If you have tenants with a Microsoft Sentinel workspace onboarded to the unified security operations platform, search for security information and event management (SIEM) data together with extended detection and response (XDR) data across multiple tenants.
26
26
27
27
## Run cross-tenant queries
28
28
29
-
In multi-tenant management, you can use any of the queries you currently have access to. They're filtered by tenant in the **Queries** tab. Select a tenant to view the queries available under each one.
29
+
In multitenant management, you can use any of the queries you currently have access to. They're filtered by tenant in the **Queries** tab. Select a tenant to view the queries available under each one.
30
30
31
31
Once you load the query in the query editor, you can then specify the scope of the query by tenant by selecting **Tenant scope**:
32
32
@@ -50,7 +50,7 @@ Likewise, you can manage custom detection rules from multiple tenants in the cus
50
50
51
51
### View custom detection rules by tenant
52
52
53
-
1. To view custom detection rules, go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multi-tenant management in Microsoft Defender XDR.
53
+
1. To view custom detection rules, go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multitenant management in Microsoft Defender XDR.
54
54
2. View the **Tenant name** column to see which tenant the detection rule comes from:
55
55
56
56
:::image type="content" source="/defender/media/defender/mto-custom-detection-tenant-name.png" alt-text="Screenshot of the Microsoft Defender XDR multi-tenant custom detection page" lightbox="/defender/media/defender/mto-custom-detection-tenant-name.png":::
@@ -61,11 +61,11 @@ To read more about custom detection rules, read [Custom detections overview](cus
61
61
62
62
### Manage custom detection rules
63
63
64
-
You can **Run**, **Turn off**, and **Delete** detection rules from multi-tenant management in Microsoft Defender XDR.
64
+
You can **Run**, **Turn off**, and **Delete** detection rules from multitenant management in Microsoft Defender XDR.
65
65
66
66
To manage detection rules:
67
67
68
-
1. Go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multi-tenant management in Microsoft Defender XDR
68
+
1. Go to the [Custom detection rules page](https://mto.security.microsoft.com/v2/custom_detection) in multitenant management in Microsoft Defender XDR
69
69
2. Choose the detection rule you want to manage
70
70
71
71
When you select a single detection rule, a flyout panel opens with the detection rule details:
@@ -76,6 +76,6 @@ Select **Open detection rules** to view this rule in a new tab for the specific
76
76
77
77
## Related content
78
78
79
-
-[Set up multi-tenant management in Microsoft Defender XDR](mto-requirements.md)
79
+
-[Set up multitenant management in Microsoft Defender XDR](mto-requirements.md)
80
80
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
81
81
-[View and manage incidents and alerts](mto-incidents-alerts.md)
Copy file name to clipboardExpand all lines: defender-xdr/mto-incidents-alerts.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: View and manage incidents and alerts in multi-tenant management for Microsoft Defender XDR
3
-
description: Learn about incidents and alerts in multi-tenant management for Microsoft Defender XDR
2
+
title: View and manage incidents and alerts in multitenant management for Microsoft Defender XDR
3
+
description: Learn about incidents and alerts in multitenant management for Microsoft Defender XDR
4
4
search.appverid: met150
5
5
ms.service: defender-xdr
6
6
ms.author: siosulli
@@ -22,15 +22,15 @@ appliesto:
22
22
23
23
# View and manage incidents and alerts
24
24
25
-
Multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats. Triage incidents and alerts across SIEM and XDR data for tenants that have onboarded a Microsoft Sentinel workspace to the unified security operations platform.
25
+
Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform enables security operation center (SOC) analysts to access and analyze data from multiple tenants in one place, allowing them to quickly identify and respond to threats. Triage incidents and alerts across security information and event management (SIEM) and extended detection and response (XDR) data for tenants that onboarded a Microsoft Sentinel workspace to the unified security operations platform.
26
26
27
27
Manage incidents & alerts originating from multiple tenants under **Incidents & alerts**.
28
28
29
29
## View and investigate incidents
30
30
31
31
To view or investigate an incident:
32
32
33
-
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management in Microsoft Defender XDR. The **Tenant name** column shows which tenant the incident originates from:
33
+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multitenant management in Microsoft Defender XDR. The **Tenant name** column shows which tenant the incident originates from:
34
34
35
35
:::image type="content" source="/defender/media/defender/mto-incidents.png" alt-text="Screenshot of the Microsoft Defender multi-tenant incidents page" lightbox="/defender/media/defender/mto-incidents.png":::
36
36
@@ -49,7 +49,7 @@ To learn more, see [Investigate incidents](/defender-endpoint/investigate-incide
49
49
50
50
To manage incidents across multiple tenants:
51
51
52
-
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multi-tenant management.
52
+
1. Go to the [Incidents page](https://mto.security.microsoft.com/incidents) in multitenant management.
53
53
2. Choose the incidents you want to manage from the incidents list and select **Manage incidents**.
54
54
55
55
:::image type="content" source="/defender/media/defender/mto-manage-incidents.png" alt-text="Screenshot of the Microsoft Defender XDR incidents page" lightbox="/defender/media/defender/mto-manage-incidents.png":::
@@ -65,7 +65,7 @@ To learn more about incidents in the Microsoft Defender portal, see [Manage inci
65
65
66
66
To view or investigate an alert:
67
67
68
-
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management and select the alert you want to view. A flyout panel opens with the alert details page:
68
+
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multitenant management and select the alert you want to view. A flyout panel opens with the alert details page:
69
69
70
70
:::image type="content" source="/defender/media/defender/mto-alerts-details.png" alt-text="Screenshot of the Microsoft Defender XDR alert details page" lightbox="/defender/media/defender/mto-alerts-details.png":::
71
71
@@ -80,7 +80,7 @@ To learn more, see [Investigate alerts](/defender-endpoint/investigate-alerts).
80
80
81
81
To manage alerts across multiple tenants:
82
82
83
-
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multi-tenant management.
83
+
1. Go to the [Alerts page](https://mto.security.microsoft.com/alerts) in multitenant management.
84
84
2. Choose the alerts you want to manage from the alerts list and select **Manage alerts**.
85
85
86
86
:::image type="content" source="/defender/media/defender/mto-manage-alerts.png" alt-text="Screenshot of the Microsoft Defender XDR alerts page" lightbox="/defender/media/defender/mto-manage-alerts.png":::
@@ -93,7 +93,7 @@ To learn more about alerts in the Microsoft Defender portal, see [Manage alerts]
93
93
94
94
## Related content
95
95
96
-
-[Set up multi-tenant management in Microsoft Defender XDR](mto-requirements.md)
96
+
-[Set up multitenant management in Microsoft Defender XDR](mto-requirements.md)
97
97
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
98
-
-[Advanced hunting in multi-tenant management in Microsoft Defender XDR](mto-advanced-hunting.md)
98
+
-[Advanced hunting in multitenant management in Microsoft Defender XDR](mto-advanced-hunting.md)
Copy file name to clipboardExpand all lines: defender-xdr/mto-overview.md
+13-13Lines changed: 13 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: Multi-tenant management for the Microsoft unified security operations platform
3
-
description: Learn about multi-tenant management for Microsoft Defender XDR and Microsoft Sentinel in the the Microsoft unified security operations platform.
2
+
title: Multitenant management for the Microsoft unified security operations platform
3
+
description: Learn about multitenant management for Microsoft Defender XDR and Microsoft Sentinel in the Microsoft unified security operations platform.
4
4
ms.service: defender-xdr
5
5
ms.author: siosulli
6
6
author: siosulli
@@ -21,38 +21,38 @@ appliesto:
21
21
- Microsoft Defender for Office 365 P2
22
22
---
23
23
24
-
# Multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform
24
+
# Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform
25
25
26
-
Multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform provides your security operation teams with a single, unified view of all the tenants you manage. This view enables your teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving your security operations.
26
+
Multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform provides your security operation teams with a single, unified view of all the tenants you manage. This view enables your teams to quickly investigate incidents and perform advanced hunting across data from multiple tenants, improving your security operations.
27
27
28
28
If you have tenants with a Microsoft Sentinel workspace onboarded to the unified security operations platform, you're able to:
29
29
30
-
- Triage incidents and alerts across SIEM and XDR data.
30
+
- Triage incidents and alerts across security information and event management (SIEM) and extended detection and response (XDR) data.
31
31
- Proactively search for SIEM and XDR data across multiple tenants.
32
32
33
-
Only one Microsoft Sentinel workspace per tenant is currently supported in the unfied security platform. So for multi-tenant management, you'll have SIEM data from one Microsoft Sentinel workspace per tenant.
33
+
Only one Microsoft Sentinel workspace per tenant is currently supported in the unified security operations platform. So in multitenant management, you have SIEM data from one Microsoft Sentinel workspace per tenant.
34
34
35
35
For more information, see:
36
36
37
37
-[Connect Microsoft Sentinel to Microsoft Defender XDR](microsoft-sentinel-onboard.md)
Some of the key benefits you get with multi-tenant management for Defender XDR and the Microsoft unified security operations platform include:
43
+
Some of the key benefits you get with multitenant management for Defender XDR and the Microsoft unified security operations platform include:
44
44
45
45
-**A centralized place to manage incidents across tenants**: A unified view provides SOC analysts with all the information they need to investigate incidents across multiple tenants, eliminating the need to sign in and out of each one.
46
46
47
-
-**Streamlined threat hunting**: Multi-tenancy support enables SOC teams use Microsoft Defender XDR advanced hunting capabilities to create KQL queries that will proactively hunt for threats across multiple tenants.
47
+
-**Streamlined threat hunting**: Multi-tenancy support enables SOC teams use Microsoft Defender XDR advanced hunting capabilities to create Kusto Query Language (KQL) queries that proactively hunt for threats across multiple tenants.
48
48
49
49
-**Multi-customer management for partners**: Managed Security Service Provider (MSSP) partners can now gain visibility into security incidents, alerts, and threat hunting across multiple customers through a single pane of glass.
The following key capabilities are available for each tenant you have access to in multi-tenant management for Microsoft Defender XDR and the Microsoft unified security operations platform:
55
+
The following key capabilities are available for each tenant you have access to in multitenant management for Microsoft Defender XDR and the Microsoft unified security operations platform:
56
56
57
57
| Capability | Description |
58
58
| ------ | ------ |
@@ -67,4 +67,4 @@ The following key capabilities are available for each tenant you have access to
67
67
68
68
## Next steps
69
69
70
-
-[Set up multi-tenant management in Microsoft Defender XDR](mto-requirements.md)
70
+
-[Set up multitenant management in Microsoft Defender XDR](mto-requirements.md)
0 commit comments