You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-office-365/apivendorecosystem.md
+12-12Lines changed: 12 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,12 +37,12 @@ This article outlines the goals, benefits, and deployment considerations for org
37
37
38
38
Integration features are available to customers with Microsoft Defender for Office 365 Plan 2 (P2) or Microsoft 365 E5 licenses.
39
39
40
-
Must be licensed with one of the following third-party solutions:
40
+
-Must be licensed with one of the following third-party solutions:
41
41
42
-
KnowBe4 Defend
43
-
44
-
Darktrace
45
-
42
+
- Darktrace/EMAIL
43
+
44
+
- KnowBe4 Defend Platform
45
+
46
46
## Getting Started
47
47
48
48
**Check License Eligibility**
@@ -63,7 +63,7 @@ Must be licensed with one of the following third-party solutions:
63
63
64
64
## Understanding the Integration
65
65
66
-
The integration works by allowing the third-party to pass in details on a specific message regarding the verdict, confidence level, and any threat details they would like to share via a private Microsoft Graph API. Microsoft Defender for Office 365 will then acknowledge the verdict provided and determine what the highest verdict on a message was. MDO will update the message and/or logs with the verdict information, moving the message to the user policy-specified location. You'll then be able to see the results of this integration in multiple unified experiences, including Reporting, Advanced Hunting, Email Entity, Quarantine, and Threat Explorer.
66
+
The integration works by allowing the third-party to pass in details on a specific message regarding the verdict, confidence level, and any threat details they would like to share via a private Microsoft Graph API. Microsoft Defender for Office 365 acknowledges the verdict provided and determine what the highest verdict on a message was. MDO updates the message and/or logs with the verdict information, moving the message to the user policy-specified location. You'll be able to see the results of this integration in multiple unified experiences, including Reporting, Advanced Hunting, Email Entity, Quarantine, and Threat Explorer.
67
67
68
68
## Configuring your Policies
69
69
@@ -119,7 +119,7 @@ EmailEvents
119
119
120
120
The Microsoft 365 Defender portal provides a centralized reporting experience that consolidates telemetry from both Microsoft Defender for Office 365 (MDO) and integrated third-party vendors. This unified view enables security teams to assess the effectiveness of their entire email security stack in one place.
121
121
122
-
The following dashboards will display this information:
122
+
The following dashboards display this information:
123
123
124
124
**Detection totals**
125
125
@@ -135,17 +135,17 @@ The following dashboards will display this information:
135
135
136
136
**Post-delivery catch by non-Microsoft solutions**
137
137
138
-
- Shows the verdict types that the third-party provided on messages. This is a breakdown of the Non-Microsoft Post-delivery blocks field in the Detection Totals report.
138
+
- Shows the verdict types that the third-party provided on messages. This report is a breakdown of the Non-Microsoft Post-delivery blocks field in the Detection Totals report.
139
139
140
140
## Frequently Asked Questions
141
141
142
142
**I have multiple ICES/CAPES solutions. How does that work?**
143
143
144
-
You can use this integration with multiple ICES/CAPES vendors as long as they're part of the API Vendor Ecosystem partnership. The integration will work the same, where each third-party will be able to provide verdicts on the messages in your mailboxes. You'll see the third-party catch and be able to identify which third-party the catch is attributed to, within the security portal experiences. If multiple third parties send verdicts on the same message, both third-party verdicts and explainability will be logged. The highest verdict between the third-party verdicts will determine what action is taken on the message.
144
+
You can use this integration with multiple ICES/CAPES vendors as long as they're part of the API Vendor Ecosystem partnership. The integration will work the same, where each third-party is able to provide verdicts on the messages in your mailboxes. You'll see the third-party catch and be able to identify which third-party the catch is attributed to, within the security portal experiences. If multiple third parties send verdicts on the same message, both third-party verdicts and explainability will be logged. The highest verdict between the third-party verdicts determines what action is taken on the message.
145
145
146
146
**Which verdict takes precedence?**
147
147
148
-
The "highest" verdict will take precedence. The precedence should be as follows (highest to lowest precedence):
148
+
The "highest" verdict takes precedence. The precedence should be as follows (highest to lowest precedence):
149
149
150
150
Malware
151
151
@@ -165,15 +165,15 @@ Clean or Not Spam
165
165
166
166
**What if I utilize a different third-party application?**
167
167
168
-
Currently, this integration only works for authorized partners which are Darktrace and KnowBe4. If you utilize a different ICES/CAPES vendor, you will not be able to take advantage of this integration.
168
+
Currently, this integration only works for authorized partners which are Darktrace and KnowBe4. If you utilize a different ICES/CAPES vendor, you won't be able to take advantage of this integration.
169
169
170
170
**Will I be charged for the third-party verdict data and actioning by MDO policies?**
171
171
172
172
No, there is no charge for the integration. The integration and Graph API support are included as part of your Microsoft Defender for Office 365 Plan 2 licenses.
173
173
174
174
**Why do I not see the Detection Totals and Post-delivery catch by non-Microsoft solutions reports?**
175
175
176
-
The reports will only show if you have had activity from one of the authorized third-party partners in the past 90 days.
176
+
The reports only show if you have activity from one of the authorized third-party partners in the past 90 days.
0 commit comments