Skip to content

Commit b30305c

Browse files
authored
Merge branch 'main' into 9e0ed973-0b7e-451c-81db-03b7668e2011_51
2 parents 89877ca + 86c1ea9 commit b30305c

9 files changed

+47
-36
lines changed

ATPDocs/alerts-overview.md

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -98,7 +98,6 @@ The following table lists the mapping between alert names, their corresponding u
9898
| [Suspicious modifications to the AD CS security permissions/settings](persistence-privilege-escalation-alerts.md#suspicious-modifications-to-the-ad-cs-security-permissionssettings--external-id-2435) | 2435 | Medium | Privilege escalation |
9999
| [Account Enumeration reconnaissance (LDAP)](reconnaissance-discovery-alerts.md#account-enumeration-reconnaissance-ldap-external-id-2437-preview) (Preview) | 2437 | Medium | Account Discovery, Domain Account |
100100
| [Directory Services Restore Mode Password Change](other-alerts.md#directory-services-restore-mode-password-change-external-id-2438) | 2438 | Medium | Persistence, Account Manipulation |
101-
| [Honeytoken was queried via SAM-R](reconnaissance-discovery-alerts.md#honeytoken-was-queried-via-sam-r-external-id-2439) | 2439 | Low | Discovery |
102101
|[Group Policy Tampering ](/defender-for-identity/other-alerts)|2440|Medium|Defense evasion|
103102

104103
> [!NOTE]

ATPDocs/reconnaissance-discovery-alerts.md

Lines changed: 0 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -173,25 +173,6 @@ None
173173
|MITRE attack technique | [Account Discovery (T1087)](https://attack.mitre.org/techniques/T1087/), [Indirect Command Execution (T1202)](https://attack.mitre.org/techniques/T1202/), [Permission Groups Discovery (T1069)](https://attack.mitre.org/techniques/T1069/) |
174174
|MITRE attack sub-technique | [Domain Account (T1087.002)](https://attack.mitre.org/techniques/T1087/002/), [Domain Groups (T1069.002)](https://attack.mitre.org/techniques/T1069/002/) |
175175

176-
## Honeytoken was queried via SAM-R (external ID 2439)
177-
178-
**Severity**: Low
179-
180-
**Description**:
181-
182-
User reconnaissance is used by attackers to map the directory structure and target privileged accounts for later steps in their attack. The Security Account Manager Remote (SAM-R) protocol is one of the methods used to query the directory to perform this type of mapping.
183-
In this detection, Microsoft Defender for Identity will trigger this alert for any reconnaissance activities against a pre-configured [honeytoken user](entity-tags.md)
184-
185-
**Learning period**:
186-
187-
None
188-
189-
**MITRE**:
190-
191-
|Primary MITRE tactic |[Discovery (TA0007)](https://attack.mitre.org/tactics/TA0007/) |
192-
|---------|---------|
193-
|MITRE attack technique | [Account Discovery (T1087)](https://attack.mitre.org/techniques/T1087/)|
194-
|MITRE attack sub-technique | [Domain Account (T1087.002)](https://attack.mitre.org/techniques/T1087/002/)|
195176

196177
## Honeytoken was queried via LDAP (external ID 2429)
197178

ATPDocs/remediation-actions.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,8 +39,24 @@ The following Defender for Identity actions can be performed directly on your on
3939

4040
- **Reset user password** – This will prompt the user to change their password on the next logon, ensuring that this account can't be used for further impersonation attempts.
4141

42+
- **Mark User Compromised** - The user’s risk level is set to High
43+
44+
- **Suspend User in Entra ID** - Block new sign-ins and access to cloud resources
45+
46+
- **Require User to Sign In Again** - Revoke a user’s active sessions
47+
4248
Depending on your Microsoft Entra ID roles, you might see additional Microsoft Entra ID actions, such as requiring users to sign in again and confirming a user as compromised. For more information, see [Remediate risks and unblock users](/entra/id-protection/howto-identity-protection-remediate-unblock).
4349

50+
## Roles and Permissions
51+
52+
| Action | XDR RBAC permissions |
53+
| ------------------------------------- | ------------------------------------------------------------ |
54+
|Mark User Compromised | - Global Administrator <br> - Security Administrator|
55+
|Suspend User in Entra ID | - Global Administrator |
56+
|Require User to Sign In Again | - Global Administrator <br> - Security Administrator <br> - Security Operator|
57+
| Disable/Enable User in Active Directory | Refer to [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr)|
58+
| Force Password Reset in Active Directory | Refer to [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr)|
59+
4460

4561
## Related videos
4662

CloudAppSecurityDocs/editions-cloud-app-security-o365.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,8 @@ Office 365 Cloud App Security includes threat detection based on user activity l
2626

2727
|Capability|Feature|Microsoft Defender for Cloud Apps|Office 365 Cloud App Security|
2828
|----|----|----|----|
29-
|Cloud discovery|Discovered apps |31,000 + cloud apps |750+ cloud apps with similar functionality to Office 365|
29+
|App Governance|App Governance|Yes||
30+
|Cloud discovery|Discovered apps |34,000 + cloud apps |750+ cloud apps with similar functionality to Office 365|
3031
||Deployment for discovery analysis|<li> Manual upload <br> <li> Automated upload - Log collector and API <br> <li> Native Defender for Endpoint integration |Manual log upload|
3132
||Log anonymization for user privacy|Yes||
3233
||Access to full cloud app catalog|Yes||
@@ -52,3 +53,4 @@ Office 365 Cloud App Security includes threat detection based on user activity l
5253
Read about the basics in [Getting started with Defender for Cloud Apps](./get-started.md).
5354

5455
[!INCLUDE [Open support ticket](includes/support.md)]
56+
"

defender-endpoint/api/collect-investigation-package.md

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -15,19 +15,19 @@ ms.topic: reference
1515
ms.subservice: reference
1616
ms.custom: api
1717
search.appverid: met150
18-
ms.date: 03/21/2025
18+
ms.date: 06/03/2025
1919
---
2020

2121
# Collect investigation package API
2222

2323
[!INCLUDE [Microsoft Defender XDR rebranding](../../includes/microsoft-defender.md)]
2424

2525
**Applies to:**
26+
2627
- [Microsoft Defender for Endpoint Plan 1](../microsoft-defender-endpoint.md)
2728
- [Microsoft Defender for Endpoint](../microsoft-defender-endpoint.md)
2829
- [Microsoft Defender XDR](/defender-xdr)
2930

30-
3131
> Want to experience Microsoft Defender for Endpoint? [Sign up for a free trial.](https://go.microsoft.com/fwlink/p/?linkid=2225630)
3232
3333
[!include[Microsoft Defender for Endpoint API URIs for US Government](../../includes/microsoft-defender-api-usgov.md)]
@@ -40,11 +40,7 @@ Collect investigation package from a device.
4040

4141
## Limitations
4242

43-
1. Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
44-
45-
> [!IMPORTANT]
46-
>
47-
> - These response actions are only available for devices on Windows 10, version 1703 or later, and on Windows 11.
43+
- Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
4844

4945
## Permissions
5046

defender-office-365/quarantine-policies.md

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ ms.collection:
1616
ms.custom:
1717
description: Admins can learn how to use quarantine policies to control what users are able to do to quarantined messages.
1818
ms.service: defender-office-365
19-
ms.date: 05/29/2025
19+
ms.date: 06/02/2025
2020
appliesto:
2121
- ✅ <a href="https://learn.microsoft.com/defender-office-365/eop-about" target="_blank">Exchange Online Protection</a>
2222
- ✅ <a href="https://learn.microsoft.com/defender-office-365/mdo-about#defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 Plan 1 and Plan 2</a>
@@ -751,10 +751,12 @@ The effect of **No access** permissions (admin only access) on user capabilities
751751
- **In quarantine notifications**: Users receive quarantine notifications, but the only available action is **Review message**.
752752

753753
> [!TIP]
754-
> To enable quarantine notifications while maintaining restricted access, [create a custom quarantine policy](#step-1-create-quarantine-policies-in-the-microsoft-defender-portal) with the following settings:
755754
>
756-
> - **Recipient message access** page: Select **Set specific access (Advanced)**, but leave **Select release action preference** and **Select additional actions recipients can take on quarantined messages** blank/unselected (equivalent to the value 0 for the _EndUserQuarantinePermissionsValue_ parameter on the **New-QuarantinePolicy** cmdlet [in Powershell](#create-quarantine-policies-in-powershell)).
757-
> - **Quarantine notification** page: Select **Enable** and then select **Don't include quarantined messages from blocked sender addresses** (default) or **Include quarantined messages from blocked sender addresses**.
755+
> - To enable quarantine notifications while maintaining restricted access, [create a custom quarantine policy](#step-1-create-quarantine-policies-in-the-microsoft-defender-portal) with the following settings:
756+
> - **Recipient message access** page: Select **Set specific access (Advanced)**, but leave **Select release action preference** and **Select additional actions recipients can take on quarantined messages** blank/unselected (equivalent to the value 0 for the _EndUserQuarantinePermissionsValue_ parameter on the **New-QuarantinePolicy** cmdlet [in Powershell](#create-quarantine-policies-in-powershell)).
757+
> - **Quarantine notification** page: Select **Enable** and then select **Don't include quarantined messages from blocked sender addresses** (default) or **Include quarantined messages from blocked sender addresses**.
758+
>
759+
> - If a sender is blocked and **Don't show blocked senders** is selected (default), messages from those senders are shown on the **Quarantine** page and are included in quarantine notifications when the **Sender address override reason** value is **None**. This behavior occurs because the messages were blocked due to reasons other than sender address overrides.
758760
759761
##### Limited access
760762

defender-office-365/tenant-allow-block-list-email-spoof-configure.md

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,14 +47,19 @@ This article describes how admins can manage entries for email senders in the Mi
4747

4848
- For blocking inbound and outbound email from a domain, any subdomains in that domain, and any email addresses in that domain, create the block entry using the syntax: `*.TLD`, where `TLD` can be any top-level domain, internal domain, or email address domain.
4949

50-
- For blocking inbound and outbound email from a sudomain in a domain and any email addresses in that subdomain, create the block entry using the syntax: `*.SD1.TLD`, `*.SD2.SD1.TLD`, `*.SD3.SD2.SD1.TLD`, etc. for internal domains and email address domains.
50+
- For blocking inbound and outbound email from a subdomain in a domain and any email addresses in that subdomain, create the block entry using the syntax: `*.SD1.TLD`, `*.SD2.SD1.TLD`, `*.SD3.SD2.SD1.TLD`, etc. for internal domains and email address domains.
5151

5252
- For details about the syntax for spoofed sender entries, see the [Domain pair syntax for spoofed sender entries](#domain-pair-syntax-for-spoofed-sender-entries) section later in this article.
5353

5454
- An entry should be active within 5 minutes.
5555

5656
- You need to be assigned permissions before you can do the procedures in this article. You have the following options:
57-
- [Microsoft Defender XDR Unified role based access control (RBAC)](/defender-xdr/manage-rbac) (If **Email & collaboration** \> **Defender for Office 365** permissions is :::image type="icon" source="media/scc-toggle-on.png" border="false"::: **Active**. Affects the Defender portal only, not PowerShell): **Authorization and settings/Security settings/Detection tuning (manage)** or **Authorization and settings/Security settings/Core security settings (read)**.
57+
- [Microsoft Defender XDR Unified role based access control (RBAC)](/defender-xdr/manage-rbac) (If **Email & collaboration** \> **Defender for Office 365** permissions is :::image type="icon" source="media/scc-toggle-on.png" border="false"::: **Active**. Affects the Defender portal only, not PowerShell):
58+
- *Add and remove entries from the Tenant Allow/Block List*: Membership assigned with the following permissions:
59+
- **Authorization and settings/Security settings/Detection tuning (manage)**
60+
- *Read-only access to the Tenant Allow/Block List*:
61+
- **Authorization and settings/Security settings/Read-only**.
62+
- **Authorization and settings/Security settings/Core Security settings (read)**.
5863
- [Exchange Online permissions](/exchange/permissions-exo/permissions-exo):
5964
- *Add and remove entries from the Tenant Allow/Block List*: Membership in one of the following role groups:
6065
- **Organization Management** or **Security Administrator** (Security admin role).

defender-office-365/tenant-allow-block-list-files-configure.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,12 @@ This article describes how admins can manage entries for files in the Microsoft
5454
- An entry should be active within 5 minutes.
5555

5656
- You need to be assigned permissions before you can do the procedures in this article. You have the following options:
57-
- [Microsoft Defender XDR Unified role based access control (RBAC)](/defender-xdr/manage-rbac) (If **Email & collaboration** \> **Exchange Online permissions** permissions is :::image type="icon" source="media/scc-toggle-on.png" border="false"::: **Active**. Affects the Defender portal only, not PowerShell): **Authorization and settings/Security settings/Detection tuning (manage)** or **Authorization and settings/Security settings/Core security settings (read)**.
57+
- [Microsoft Defender XDR Unified role based access control (RBAC)](/defender-xdr/manage-rbac) (If **Email & collaboration** \> **Defender for Office 365** permissions is :::image type="icon" source="media/scc-toggle-on.png" border="false"::: **Active**. Affects the Defender portal only, not PowerShell):
58+
- *Add and remove entries from the Tenant Allow/Block List*: Membership assigned with the following permissions:
59+
- **Authorization and settings/Security settings/Detection tuning (manage)**
60+
- *Read-only access to the Tenant Allow/Block List*:
61+
- **Authorization and settings/Security settings/Read-only**.
62+
- **Authorization and settings/Security settings/Core Security settings (read)**.
5863
- [Exchange Online permissions](/exchange/permissions-exo/permissions-exo):
5964
- _Add and remove entries from the Tenant Allow/Block List_: Membership in one of the following role groups:
6065
- **Organization Management** or **Security Administrator** (Security admin role).

defender-office-365/tenant-allow-block-list-ip-addresses-configure.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,12 @@ This article describes how admins can manage entries for IPv6 addresses in the M
5252
- An entry should be active within 5 minutes.
5353

5454
- You need to be assigned permissions before you can do the procedures in this article. You have the following options:
55-
- [Microsoft Defender XDR Unified role based access control (RBAC)](/defender-xdr/manage-rbac) (If **Email & collaboration** \> **Exchange Online permissions** permissions is :::image type="icon" source="media/scc-toggle-on.png" border="false"::: **Active**. Affects the Defender portal only, not PowerShell): **Authorization and settings/Security settings/Detection tuning (manage)** or **Authorization and settings/Security settings/Core security settings (read)**.
55+
- [Microsoft Defender XDR Unified role based access control (RBAC)](/defender-xdr/manage-rbac) (If **Email & collaboration** \> **Defender for Office 365** permissions is :::image type="icon" source="media/scc-toggle-on.png" border="false"::: **Active**. Affects the Defender portal only, not PowerShell):
56+
- *Add and remove entries from the Tenant Allow/Block List*: Membership assigned with the following permissions:
57+
- **Authorization and settings/Security settings/Detection tuning (manage)**
58+
- *Read-only access to the Tenant Allow/Block List*:
59+
- **Authorization and settings/Security settings/Read-only**.
60+
- **Authorization and settings/Security settings/Core Security settings (read)**.
5661
- [Exchange Online permissions](/exchange/permissions-exo/permissions-exo):
5762
- _Add and remove entries from the Tenant Allow/Block List_: Membership in one of the following role groups:
5863
- **Organization Management** or **Security Administrator** (Security admin role).

0 commit comments

Comments
 (0)