Skip to content

Commit a6c1bae

Browse files
authored
Merge branch 'main' into patch-1
2 parents ffe534b + c5167fc commit a6c1bae

File tree

204 files changed

+1551
-1336
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

204 files changed

+1551
-1336
lines changed

.openpublishing.redirection.defender-endpoint.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,10 @@
11
{
22
"redirections": [
3+
{
4+
"source_path": "defender-endpoint/configure-microsoft-threat-experts.md",
5+
"redirect_url": "/defender-xdr/defender-experts-for-hunting",
6+
"redirect_document_id": false
7+
},
38
{
49
"source_path": "defender-endpoint/microsoft-defender-antivirus-using-mde-security-set-mngmnt.md",
510
"redirect_url": "/defender-endpoint/evaluate-mdav-using-gp",

CloudAppSecurityDocs/cas-compliance-trust.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ Defender for Cloud Apps operates in the Microsoft Azure data centers in the foll
3131
|**Customers whose tenants are provisioned in the European Union or the United Kingdom** | Either the European Union and/or the United Kingdom |
3232
|**Customers whose tenants are provisioned in any other region** | The United States and/or a data center in the region that's nearest to the location of where the customer's Microsoft Entra tenant has been provisioned |
3333

34-
In addition to the locations above, the App Governance features within Defender for Cloud Apps operate in the Microsoft Azure data centers in the following geographical regions:
34+
In addition to the locations above, the App Governance features within Defender for Cloud Apps operate in the Microsoft Azure data centers in the following geographical regions listed below. Customer with App Governance enabled will have data stored within the data storage location the customer provisions in above, and in a second data storage location as described below:
3535

3636
|Customer provisioning location |Data storage location |
3737
|---------|---------|
@@ -65,7 +65,7 @@ Defender for Cloud Apps shares data, including customer data, among the followin
6565
- Microsoft Defender for Cloud
6666
- Microsoft Sentinel
6767
- Microsoft Defender for Endpoint
68-
- Microsoft Security Exposure Management (Preview)
68+
- Microsoft Security Exposure Management
6969
- Microsoft Purview
7070
- Microsoft Entra ID Protection
7171

CloudAppSecurityDocs/network-requirements.md

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,15 @@ ms.topic: reference
1111

1212
This article provides a list of ports and IP addresses you need to allow and allowlist to work with Microsoft Defender for Cloud Apps.
1313

14+
In order to stay up to date on IP ranges, it's recommended to refer to the following Azure service tags for Microsoft Defender for Cloud Apps services. The latest IP ranges are found in the service tag. For more information, see [Azure IP ranges](https://azureipranges.azurewebsites.net/).
15+
16+
| Service tag name | Defender for Cloud Apps services included |
17+
|:---|:---|
18+
| MicrosoftCloudAppSecurity | Portal access, Access and session controls, SIEM agent connection, App connector, Mail server, Log collector. |
19+
20+
The following tables list the current static IP ranges covered by the MicrosoftCloudAppSecurity service tag. For latest list, refer to the [Azure service tags](/azure/virtual-network/service-tags-overview) documentation.
21+
22+
1423
## View your data center
1524

1625
Some of the requirements below depend on which data center you're connected to.

defender-endpoint/TOC.yml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -934,6 +934,15 @@
934934
antivirus windows defender antivirus
935935
- name: Troubleshoot performance issues related to real-time protection
936936
href: troubleshoot-performance-issues.md
937+
- name: Troubleshoot Microsoft Defender Antivirus performance issues with WPRUI
938+
href: troubleshoot-av-performance-issues-with-wprui.md
939+
displayName: Troubleshoot antivirus performance issues with WPRUI windows
940+
performance recorder UI WPR windows performance recorder
941+
- name: Troubleshoot Microsoft Defender Antivirus performance issues with Process
942+
Monitor
943+
href: troubleshoot-av-performance-issues-with-procmon.md
944+
displayName: Troubleshoot Microsoft Defender Antivirus MDAV performance perf
945+
issues with Process Monitor ProcMon
937946
- name: Review event logs and error codes to troubleshoot issues with Microsoft Defender Antivirus
938947
href: troubleshoot-microsoft-defender-antivirus.yml
939948
- name: Troubleshoot Microsoft Defender Antivirus while migrating from a third-party solution

defender-endpoint/adv-tech-of-mdav.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,9 @@
11
---
22
title: Advanced technologies at the core of Microsoft Defender Antivirus
33
description: Microsoft Defender Antivirus engines and advanced technologies
4-
author: YongRhee-MSFT
5-
ms.author: yongrhee
4+
author: emmwalshh
5+
ms.author: ewalsh
6+
ms.reviewer: yongrhee
67
manager: deniseb
78
ms.service: defender-endpoint
89
ms.topic: overview

defender-endpoint/amsi-on-mdav.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
---
22
title: "Anti-malware Scan Interface (AMSI) integration with Microsoft Defender Antivirus"
33
description: Describes fileless malware and how Microsoft Defender Antivirus uses AMSI to protect against hidden threats.
4-
author: denisebmsft
5-
ms.author: deniseb
4+
author: emmwalshh
5+
ms.author: ewalsh
66
manager: deniseb
77
ms.reviewer: yongrhee
88
ms.date: 12/05/2024

defender-endpoint/analyzer-feedback.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,9 @@ description: Provide feedback on the Microsoft Defender for Endpoint client anal
44
ms.service: defender-endpoint
55
f1.keywords:
66
- NOCSH
7-
ms.author: deniseb
8-
author: denisebmsft
7+
ms.author: ewalsh
8+
author: emmwalshh
9+
ms.reviewer: yongrhee
910
ms.localizationpriority: medium
1011
manager: deniseb
1112
audience: ITPro

defender-endpoint/android-whatsnew.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
ms.topic: reference
1616
ms.subservice: android
1717
search.appverid: met150
18-
ms.date: 01/03/2025
18+
ms.date: 01/06/2025
1919
---
2020

2121
# What's new in Microsoft Defender for Endpoint on Android
@@ -40,7 +40,7 @@ Recommendation cards prominently display any active alerts, ensuring you stay in
4040

4141
The following screenshot is an example of what the user sees in their dashboard:
4242

43-
:::image type="content" source="media/android-whatsnew/android-dashboard-screen.png" alt-text="Screenshot showing what the user sees on the device.":::
43+
:::image type="content" source="media/android-whatsnew/android-dashboard-screen.png" alt-text="Screenshot showing the user's dashboard in the Microsoft Defender app.":::
4444

4545
**Recommendation cards for alerts**
4646

@@ -59,10 +59,10 @@ The current enterprise dashboard experience now features a tile view for your se
5959

6060
| Tile | Description |
6161
|---|---|
62-
| :::image type="content" source="media/android-whatsnew/android-tile-networkprotection.png" alt-text="Screenshot showing the network protection tile for security administrators."::: | **Network protection** <br/>Your security team can see whether a connection is secured or unsecured. |
63-
| :::image type="content" source="media/android-whatsnew/android-tile-webprotection.png" alt-text="Screenshot of a tile that shows whether web protection is enabled on a device."::: | **Web protection** <br/>Your security team can see whether web protection is enabled on a user's device. |
64-
| :::image type="content" source="media/android-whatsnew/android-tile-appsecurity.png" alt-text="Screenshot showing the app security tile."::: | **App security** <br/>Your security team can see whether any threats were found in apps installed on a user's device. |
65-
| :::image type="content" source="media/android-whatsnew/android-tile-globalsecureaccess.png" alt-text="Screenshot showing Global Secure Access status."::: | **Global secure access** <br/>Your security team can see current connection status. |
62+
| :::image type="content" source="media/android-whatsnew/android-tile-networkprotection.png" alt-text="Screenshot showing the network protection tile for security administrators."::: | **Network protection** <br/>The user can see whether a connection is secured or unsecured. |
63+
| :::image type="content" source="media/android-whatsnew/android-tile-webprotection.png" alt-text="Screenshot of a tile that shows whether web protection is enabled on a device."::: | **Web protection** <br/>The user can see whether web protection is enabled on a user's device. |
64+
| :::image type="content" source="media/android-whatsnew/android-tile-appsecurity.png" alt-text="Screenshot showing the app security tile."::: | **App security** <br/>The user can see whether any threats were found in apps installed on a user's device. |
65+
| :::image type="content" source="media/android-whatsnew/android-tile-globalsecureaccess.png" alt-text="Screenshot showing Global Secure Access status."::: | **Global secure access** <br/>The user can see current connection status. |
6666

6767
## Android low-touch onboarding is now GA
6868

@@ -125,7 +125,7 @@ Read the announcement [Tech Community Blog: Defender for Endpoint is now availab
125125

126126
## Privacy controls
127127

128-
Microsoft Defender for Endpoint on Android enables privacy controls for both administrators and end users, and includes controls for enrolled (MDM) and unenrolled (MAM) devices. Administrators can configure the privacy in the alert report while End Users can configure the information shared to their organization. For more information, see [privacy controls(MDM)](android-configure.md#privacy-controls) and [privacy controls (MAM)](android-configure-mam.md#configure-privacy-controls).
128+
Microsoft Defender for Endpoint on Android enables privacy controls for both administrators and end users, and includes controls for enrolled (MDM) and unenrolled (MAM) devices. Administrators can configure the privacy in the alert report while End Users can configure the information shared to their organization. For more information, see [privacy controls (MDM)](android-configure.md#privacy-controls) and [privacy controls (MAM)](android-configure-mam.md#configure-privacy-controls).
129129

130130
## Optional permissions and the ability to disable web protection
131131

defender-endpoint/api/export-firmware-hardware-assessment.md

Lines changed: 10 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.topic: reference
1515
ms.subservice: reference
1616
ms.custom: api
1717
search.appverid: met150
18-
ms.date: 11/24/2022
18+
ms.date: 01/08/2025
1919
---
2020

2121
# Export Hardware and firmware assessment inventory per device
@@ -153,39 +153,31 @@ Delegated (work or school account)|Software.Read|'Read Threat and Vulnerability
153153
GET /api/machines/HardwareFirmwareInventoryExport
154154
```
155155

156-
### 2.4 Parameters
157-
158-
- sasValidHours: The number of hours that the download URLs will be valid for (Maximum 24 hours).
159-
160-
### 2.5 Properties (JSON response)
156+
### 2.4 Properties (JSON response)
161157

162158
> [!NOTE]
163-
> The files are gzip compressed & in multiline Json format.
164-
>
165-
> The download URLs are only valid for 3 hours; otherwise, you can use the parameter.
166-
>
167-
> To maximize download speeds, make sure you are downloading the data from the same Azure region where your data resides.
168159
>
169-
> Each record is approximately 1KB of data. You should take this into account when choosing the pageSize parameter that works for you.
170-
>
171-
> Some additional columns might be returned in the response. These columns are temporary and might be removed. Only use the documented columns.
160+
> - The files are gzip compressed & in multiline Json format.
161+
> - The download URLs are only valid for 1 hour.
162+
> - To maximize download speeds, make sure you are downloading the data from the same Azure region where your data resides.
163+
> - Each record is approximately 1KB of data. You should take this into account when choosing the pageSize parameter that works for you.
164+
> - Some additional columns might be returned in the response. These columns are temporary and might be removed. Only use the documented columns.
172165
173166
Property (ID)|Data type|Description
174167
:---|:---|:---
175168
|Export files|String[array]|A list of download URLs for files holding the current snapshot of the organization.
176169
|GeneratedTime|DateTime|The time the export was generated.
177170

178171

172+
## 2.5 Examples
179173

180-
## 2.6 Example
181-
182-
### 2.6.1 Request example
174+
### 2.5.1 Request example
183175

184176
```http
185177
GET https://api.security.microsoft.com/api/machines/HardwareFirmwareInventoryExport
186178
```
187179

188-
### 2.6.2 Response example
180+
### 2.5.2 Response example
189181

190182
```json
191183
{

defender-endpoint/api/export-security-baseline-assessment.md

Lines changed: 10 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.topic: reference
1515
ms.subservice: reference
1616
ms.custom: api
1717
search.appverid: met150
18-
ms.date: 05/02/2022
18+
ms.date: 01/08/2025
1919
---
2020

2121
# Export security baselines assessment per device
@@ -158,35 +158,29 @@ Returns all security baselines assessments for all devices, on a per-device basi
158158
GET /api/machines/BaselineComplianceAssessmentExport
159159
```
160160

161-
### 2.4 Parameters
162-
163-
- sasValidHours: The number of hours that the download URLs will be valid for (Maximum 24 hours).
164-
165-
### 2.5 Properties (via files)
161+
### 2.4 Properties (via files)
166162

167163
> [!NOTE]
168-
> The files are gzip compressed & in multiline Json format.
169-
>
170-
> The download URLs are only valid for 3 hours; otherwise you can use the parameter.
171-
>
172-
> To maximize download speeds, make sure you are downloading the data from the same Azure region where your data resides.
173-
>
174-
> Some additional columns might be returned in the response. These columns are temporary and might be removed. Only use the documented columns.
164+
>
165+
> - The files are gzip compressed & in multiline Json format.
166+
> - The download URLs are only valid for 1 hours.
167+
> - To maximize download speeds, make sure you are downloading the data from the same Azure region where your data resides.
168+
> - Some additional columns might be returned in the response. These columns are temporary and might be removed. Only use the documented columns.
175169

176170
Property (ID)|Data type|Description
177171
:---|:---|:---
178172
|Export files|array[string]|A list of download URLs for files holding the current snapshot of the organization.
179173
|GeneratedTime|String|The time that the export was generated.
180174

181-
## 2.6 Example
175+
## 2.5 Examples
182176

183-
### 2.6.1 Request example
177+
### 2.5.1 Request example
184178

185179
```http
186180
GET https://api.securitycenter.microsoft.com/api/machines/BaselineComplianceAssessmentExport
187181
```
188182

189-
### 2.6.2 Response example
183+
### 2.5.2 Response example
190184

191185
```json
192186
{

0 commit comments

Comments
 (0)