Skip to content

Commit aed5e53

Browse files
committed
Learn Editor: Update apivendorecosystem.md
1 parent e61b214 commit aed5e53

File tree

1 file changed

+12
-12
lines changed

1 file changed

+12
-12
lines changed

defender-office-365/apivendorecosystem.md

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -37,12 +37,12 @@ This article outlines the goals, benefits, and deployment considerations for org
3737

3838
Integration features are available to customers with Microsoft Defender for Office 365 Plan 2 (P2) or Microsoft 365 E5 licenses.
3939

40-
Must be licensed with one of the following third-party solutions:
40+
- Must be licensed with one of the following third-party solutions:
4141

42-
KnowBe4 Defend
43-
44-
Darktrace
45-
42+
- Darktrace/EMAIL
43+
44+
- KnowBe4 Defend Platform
45+
4646
## Getting Started
4747

4848
**Check License Eligibility**
@@ -63,7 +63,7 @@ Must be licensed with one of the following third-party solutions:
6363

6464
## Understanding the Integration
6565

66-
The integration works by allowing the third-party to pass in details on a specific message regarding the verdict, confidence level, and any threat details they would like to share via a private Microsoft Graph API. Microsoft Defender for Office 365 will then acknowledge the verdict provided and determine what the highest verdict on a message was. MDO will update the message and/or logs with the verdict information, moving the message to the user policy-specified location. You'll then be able to see the results of this integration in multiple unified experiences, including Reporting, Advanced Hunting, Email Entity, Quarantine, and Threat Explorer.
66+
The integration works by allowing the third-party to pass in details on a specific message regarding the verdict, confidence level, and any threat details they would like to share via a private Microsoft Graph API. Microsoft Defender for Office 365 acknowledges the verdict provided and determine what the highest verdict on a message was. MDO updates the message and/or logs with the verdict information, moving the message to the user policy-specified location. You'll be able to see the results of this integration in multiple unified experiences, including Reporting, Advanced Hunting, Email Entity, Quarantine, and Threat Explorer.
6767

6868
## Configuring your Policies
6969

@@ -119,7 +119,7 @@ EmailEvents
119119

120120
The Microsoft 365 Defender portal provides a centralized reporting experience that consolidates telemetry from both Microsoft Defender for Office 365 (MDO) and integrated third-party vendors. This unified view enables security teams to assess the effectiveness of their entire email security stack in one place.
121121

122-
The following dashboards will display this information:
122+
The following dashboards display this information:
123123

124124
**Detection totals**
125125

@@ -135,17 +135,17 @@ The following dashboards will display this information:
135135

136136
**Post-delivery catch by non-Microsoft solutions**
137137

138-
- Shows the verdict types that the third-party provided on messages. This is a breakdown of the Non-Microsoft Post-delivery blocks field in the Detection Totals report.
138+
- Shows the verdict types that the third-party provided on messages. This report is a breakdown of the Non-Microsoft Post-delivery blocks field in the Detection Totals report.
139139

140140
## Frequently Asked Questions
141141

142142
**I have multiple ICES/CAPES solutions. How does that work?**
143143

144-
You can use this integration with multiple ICES/CAPES vendors as long as they're part of the API Vendor Ecosystem partnership. The integration will work the same, where each third-party will be able to provide verdicts on the messages in your mailboxes. You'll see the third-party catch and be able to identify which third-party the catch is attributed to, within the security portal experiences. If multiple third parties send verdicts on the same message, both third-party verdicts and explainability will be logged. The highest verdict between the third-party verdicts will determine what action is taken on the message.
144+
You can use this integration with multiple ICES/CAPES vendors as long as they're part of the API Vendor Ecosystem partnership. The integration will work the same, where each third-party is able to provide verdicts on the messages in your mailboxes. You'll see the third-party catch and be able to identify which third-party the catch is attributed to, within the security portal experiences. If multiple third parties send verdicts on the same message, both third-party verdicts and explainability will be logged. The highest verdict between the third-party verdicts determines what action is taken on the message.
145145

146146
**Which verdict takes precedence?**
147147

148-
The "highest" verdict will take precedence. The precedence should be as follows (highest to lowest precedence):
148+
The "highest" verdict takes precedence. The precedence should be as follows (highest to lowest precedence):
149149

150150
Malware
151151

@@ -165,15 +165,15 @@ Clean or Not Spam
165165

166166
**What if I utilize a different third-party application?**
167167

168-
Currently, this integration only works for authorized partners which are Darktrace and KnowBe4. If you utilize a different ICES/CAPES vendor, you will not be able to take advantage of this integration.
168+
Currently, this integration only works for authorized partners which are Darktrace and KnowBe4. If you utilize a different ICES/CAPES vendor, you won't be able to take advantage of this integration.
169169

170170
**Will I be charged for the third-party verdict data and actioning by MDO policies?**
171171

172172
No, there is no charge for the integration. The integration and Graph API support are included as part of your Microsoft Defender for Office 365 Plan 2 licenses.
173173

174174
**Why do I not see the Detection Totals and Post-delivery catch by non-Microsoft solutions reports?**
175175

176-
The reports will only show if you have had activity from one of the authorized third-party partners in the past 90 days.
176+
The reports only show if you have activity from one of the authorized third-party partners in the past 90 days.
177177

178178
## Feedback and Support
179179

0 commit comments

Comments
 (0)