Skip to content

Commit a7933a4

Browse files
authored
Merge branch 'main' into WI353984-update-file-policies-article
2 parents 49e1bc1 + 238278b commit a7933a4

File tree

40 files changed

+303
-161
lines changed

40 files changed

+303
-161
lines changed
Lines changed: 85 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,85 @@
1+
---
2+
title: Identity Security Initiative
3+
description: Learn how to enhance your organization's identity security using the Identity Security Initiative in Microsoft Defender XDR.
4+
ms.topic: overview
5+
ms.date: 04/05/2025
6+
---
7+
8+
# Identity Security Initiative (Preview)
9+
10+
Identity security is the practice of protecting the digital identities of individuals and organizations. This includes protecting passwords, usernames, and other credentials that can be used to access sensitive data or systems. Identity security is essential for protecting against a wide range of cyber threats, including phishing, malware, and data breaches.
11+
12+
## Prerequisites
13+
14+
- Your organization must have a Microsoft Defender for Identity license.
15+
- [Review prerequisites and permissions needed](/security-exposure-management/prerequisites) for working with Security Exposure Management.
16+
17+
## View Identity Security Initiatives
18+
1. Navigate to the [Microsoft Defender portal](https://security.microsoft.com/).
19+
1. From the Exposure management section on the navigation bar, select **Exposure insights** **>** **Initiatives** to open the Identity Security page.
20+
21+
:::image type="content" source="media/identity-security-initiative/screenshot-of-the-identity-security-initiative-page.png" alt-text="Screenshot showing the Identity security initiative page." lightbox="media/identity-security-initiative/screenshot-of-the-identity-security-initiative-page.png":::
22+
23+
## Review security metrics
24+
25+
Metrics in security initiatives help you to measure exposure risk for different areas within the initiative. Each metric gathers together one or more recommendations for similar assets.
26+
Metrics can be associated with one or more initiatives.
27+
28+
On the **Metrics** tab of an initiative, or in the Metrics section of Exposure Insights, you can see the metric state, its effect, and relative importance in an initiative, and recommendations to improve the metric.
29+
We recommend that you prioritize metrics with the highest impact on Initiative Score level. This composite measure considers both the weight value of each recommendation and the percentage of noncompliant recommendations.
30+
31+
:::image type="content" source="media/identity-security-initiative/screenshot-of-the-security-metrics-page.png" alt-text="Screenshot showing the security metrics page." lightbox="media/identity-security-initiative/screenshot-of-the-security-metrics-page.png":::
32+
33+
34+
|Metric property |Description |
35+
|---------|---------|
36+
|**Metric name** | The name of the metric. |
37+
|**Progress** |Shows the improvement of the exposure level for the metric from 0 (high exposure) to 100 (no exposure). |
38+
|**State** | Shows if the metric needs attention or if the target was met. |
39+
|**Total assets** | Total number of assets under the metric scope. |
40+
|**Recommendations** | Security recommendations associated with the metric. |
41+
|**Weight** | The relative weight (importance) of the metric within the initiative, and its effect on the initiative score. Shown as High, Medium, and Low. It can also be defined as Risk accepted. |
42+
|**14-day trend** | Shows the metric value changes over the last 14 days. |
43+
|**Last updated** | Shows a timestamp of when the metric was last updated.
44+
45+
> [!NOTE]
46+
> The Affected assets experience isn't fully supported during the Preview phase.
47+
48+
## View Identity security recommendations
49+
50+
The Security recommendations tab displays a list of prioritized remediation actions related to your identity security posture. Each recommendation is evaluated for compliance and mapped to its corresponding risk impact, workload, and domain. This view helps you triage and take action based on urgency and business relevance.
51+
52+
:::image type="content" source="media/identity-security-initiative/screenshot-showing-the-security-recommendations-page.png" alt-text="Showing showing the security recommendations page." lightbox="media/identity-security-initiative/screenshot-showing-the-security-recommendations-page.png":::
53+
54+
Sort the recommendations by any of the headings or filter them based on your task needs.
55+
56+
| **Column** | **Description** |
57+
|------------------------|---------------------------------------------------------------------------------|
58+
| **Name** | The name of the recommended action (for example, *Configure VPN integration*, *Enable MFA*). |
59+
| **State** | Indicates whether the recommendation is *Compliant* or *Not Compliant*. |
60+
| **Impact** | The security impact level (Low, Medium, or High) of implementing the recommendation. |
61+
| **Workload** | The Microsoft service area the recommendation applies to (for example, Defender for Identity, Microsoft Entra ID). |
62+
| **Domain** | The security domain (for example, identity, apps) associated with the recommendation. |
63+
| **Last calculated** | The most recent time the recommendation's status was evaluated. |
64+
| **Last state change** | When the recommendation’s compliance state last changed. |
65+
| **Related initiatives**| Number of security initiatives impacted by this recommendation. |
66+
| **Related metrics** | Number of security metrics that this recommendation contributes to. |
67+
68+
Security Exposure Management categorizes recommendations by compliance status, as follows:
69+
70+
- **Compliant**: Indicates that the recommendation was implemented successfully.
71+
- **Not complaint**: Indicates that the recommendation wasn't fixed.
72+
73+
## Set target score
74+
75+
You can set a customized target score for the initiative, taking your organization’s unique set of circumstances, priorities, and risk appetite into account.
76+
77+
To set a target store, select the initiative, and then select **Set target score** from the top of the initiative pane.
78+
79+
:::image type="content" source="media/identity-security-initiative/set-target-score.png" alt-text="Screenshot showing the set target score button." lightbox="media/identity-security-initiative/set-target-score.png":::
80+
81+
## Related content
82+
83+
- [Review security initiatives](/security-exposure-management/initiatives)
84+
85+
- [Investigate security initiative metrics](/security-exposure-management/security-metrics)
138 KB
Loading
109 KB
Loading
127 KB
Loading
196 KB
Loading

ATPDocs/toc.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -257,6 +257,8 @@ items:
257257
href: security-assessment-unsecure-account-attributes.md
258258
- name: Weak cipher usage assessment
259259
href: security-assessment-weak-cipher.md
260+
- name: Identity security initiative (Preview)
261+
href: identity-security-initiative.md
260262
- name: Reference
261263
items:
262264
- name: Operations guide

CloudAppSecurityDocs/caac-known-issues.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,9 @@ Session policies don't protect external business-to-business (B2B) collaboration
5454
## Session Controls with Non-Interactive Tokens
5555
Some applications utilize non-interactive access tokens to facilitate seamless redirection between apps within the same suite or realm. When one application is onboarded to Conditional Access App Control and the other is not, session controls may not be enforced as expected. For example, if the Teams client retrieves a non-interactive token for SharePoint Online (SPO), it can initiate an active session in SPO without prompting the user for reauthentication. As a result, the session control mechanism cannot intercept or enforce policies on these sessions. To ensure consistent enforcement, it's recommended to onboard all relevant applications, such as Teams, alongside SPO.
5656

57+
## IPv6 limitations
58+
Access and session policies support IPv4 only. If a request is made over IPv6, IP-based policy rules are not applied. This limitation applies when using both reverse proxy and Edge in-browser protection.
59+
5760
## Limitations for sessions that the reverse proxy serves
5861

5962
The following limitations apply only on sessions that the reverse proxy serves. Users of Microsoft Edge can benefit from in-browser protection instead of using the reverse proxy, so these limitations don't affect them.
@@ -98,6 +101,7 @@ The following table lists example results when you define the **Block upload of
98101

99102
The following limitations apply only on sessions that are served with Edge in-browser protection.
100103

104+
101105
### Deep link is lost when user switches to Edge by clicking 'Continue in Edge'
102106

103107
A user who starts a session in a browser other than Edge, is prompted to switch to Edge by clicking the ‘Continue in Edge’ button.

CloudAppSecurityDocs/troubleshooting-proxy-url.md

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ For example, Contoso protects its environment using conditional access app contr
2020
So even though Fabrikam doesn't actually use Defender for Cloud Apps, they see the DNS entry or certificate because Contoso does.
2121

2222
> [!NOTE]
23-
> You may also see the following domains in the transparency logs:
23+
> You might also see the following domains in the transparency logs:
2424
>
2525
> - `*.admin-rs-mcas.ms`
2626
> - `*.rs-mcas.ms`
@@ -39,11 +39,12 @@ So even though Fabrikam doesn't actually use Defender for Cloud Apps, they see t
3939
> - `*.admin-mcas-gov-df.ms`
4040
> - `*.mcas-gov-df.ms`
4141
42+
4243
## Here's why you see `*.mcas.ms`, `*.mcas-gov.us`, or `*.mcas-gov.ms` in your URL
4344

4445
This kind of URL is expected and indicates that your organization applies extra security controls to protect business-critical data.
4546

46-
They do this by using Defender for Cloud Apps, a solution for protecting your organization's cloud environment, to replace all relevant URLs and cookies relating to cloud apps that you use.
47+
They do this by using Defender for Cloud Apps, a solution for protecting your organization's cloud environment, to replace all relevant URLs, and cookies relating to cloud apps that you use.
4748

4849
So when you try accessing a cloud app such as Salesforce, SharePoint Online, or AWS, you notice that its URL is suffixed with `.mcas.ms`, `.mcas-gov.us`, or `.mcas-gov.ms`. For example, when using the XYZ app, the URL you're used to seeing changes from `XYZ.com` to `XYZ.com.mcas.ms`.
4950

@@ -52,10 +53,11 @@ If the URL doesn't exactly match one of the replacement patterns, such as `<app_
5253
If you don't recognize the remaining portion of the URL, such as **myurl.com**.mcas.ms, as associated with any of your business apps, we recommend that you investigate the issue further and consider blocking the URL to avoid any potential security risks.
5354

5455
> [!NOTE]
55-
> Microsoft Edge users benefit from in-browser protection, and are not redirected to a reverse proxy. Your URLs retain their original syntax in Microsoft Edge, even when access and sessions are protected by Defender for Cloud Apps. For more information, see [In-browser protection with Microsoft Edge for Business (Preview)](in-browser-protection.md).
56+
> Microsoft Edge users benefit from in-browser protection, and aren't redirected to a reverse proxy. Your URLs retain their original syntax in Microsoft Edge, even when access and sessions are protected by Defender for Cloud Apps. For more information, see [In-browser protection with Microsoft Edge for Business (Preview)](in-browser-protection.md).
5657
5758
## Related content
5859

60+
- [Known limitations in Conditional Access app control](caac-known-issues.md)
5961
- [Protect apps with Microsoft Defender for Cloud Apps Conditional Access app control](proxy-intro-aad.md)
6062
- [Troubleshooting access and session controls for admin users](troubleshooting-proxy.md)
61-
- [Troubleshooting access and session controls for end-users](troubleshooting-proxy-end-users.md)
63+
- [Troubleshooting access and session controls for end-users](troubleshooting-proxy-end-users.md)

defender-endpoint/behavior-monitor.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ ms.topic: conceptual
1010
ms.service: defender-endpoint
1111
ms.subservice: ngp
1212
ms.localizationpriority: medium
13-
ms.date: 03/25/2025
13+
ms.date: 04/29/2025
1414
search.appverid: met150
1515
---
1616

@@ -69,7 +69,7 @@ The following table shows the different ways to configure behavior monitoring.
6969
| CSP | AllowBehaviorMonitoring | [Defender Policy CSP](/mem/intune/protect/antivirus-microsoft-defender-settings-windows#real-time-protection) |
7070
| Configuration Manager Tenant Attach | Turn on behavior monitoring | [Windows Antivirus policy settings from Microsoft Defender Antivirus for tenant attached devices](/mem/intune/protect/antivirus-microsoft-defender-settings-windows-tenant-attach#real-time-protection) |
7171
| Group Policy | Turn on behavior monitoring | [Download Group Policy Settings Reference Spreadsheet for Windows 11 2023 Update (23H2)](https://www.microsoft.com/download/details.aspx?id=105668) |
72-
| PowerShell | Set-Preference -DisableBehaviorMonitoring | [Set-MpPreference](/powershell/module/defender/set-mppreference#-disablebehaviormonitoring) |
72+
| PowerShell | Set-MpPreference -DisableBehaviorMonitoring | [Set-MpPreference](/powershell/module/defender/set-mppreference#-disablebehaviormonitoring) |
7373
| WMI | boolean DisableBehaviorMonitoring; | [MSFT\_MpPreference class](/previous-versions/windows/desktop/defender/msft-mppreference) |
7474

7575
If you use Microsoft Defender for Business, see [Review or edit your next-generation protection policies in Microsoft Defender for Business](/defender-business/mdb-next-generation-protection).

defender-endpoint/ios-configure-features.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -318,10 +318,10 @@ Defender for Endpoint on iOS enables admins to configure custom indicators on iO
318318

319319
> [!NOTE]
320320
> Defender for Endpoint on iOS supports creating custom indicators only for URLs and domains. IP based custom indicators aren't supported on iOS.
321+
> > IP `245.245.0.1` is an internal Defender IP and shouldn't be included in custom indicators by customers to avoid any functionality issues.
322+
> > For iOS, no alerts are generated in the Microsoft Defender portal when the URL or domain set in the indicator is accessed.
321323
>
322-
> IP `245.245.0.1` is an internal Defender IP and shouldn't be included in custom indicators by customers to avoid any functionality issues.
323-
>
324-
> For iOS, no alerts are generated in the Microsoft Defender portal when the URL or domain set in the indicator is accessed.
324+
> MDE portal Timeline doesn't display the URL for Custom URL Indicator Blocks for unsupervised devices, instead it marks hidden for privacy.
325325
326326
## Configure vulnerability assessment of apps
327327

@@ -374,7 +374,7 @@ Defender for Endpoint on iOS supports vulnerability assessments of OS and apps.
374374
- The privacy approval screen appears only for unsupervised devices.
375375
- Only if end-user approves the privacy, the app information is sent to the Defender for Endpoint console.
376376

377-
:::image type="content" source="media/tvm-user-privacy2.png" alt-text="Screenshot of the end user privacy screen." lightbox="media/tvm-user-privacy2.png":::
377+
:::image type="content" source="media/tvm-user-privacy2.png" alt-text="Screenshot of the end user privacy screen.":::
378378

379379
Once the client versions are deployed to target iOS devices, processing starts. Vulnerabilities found on those devices start showing up in the Defender Vulnerability Management dashboard. The processing might take few hours (max 24 hours) to complete. This time frame is especially true for the entire list of apps to show up in the software inventory.
380380

0 commit comments

Comments
 (0)