Skip to content

Commit b664694

Browse files
committed
upload guidebook - Yuval
1 parent a84cf64 commit b664694

File tree

1 file changed

+2
-11
lines changed

1 file changed

+2
-11
lines changed

defender-xdr/security-upload-guide.md

Lines changed: 2 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ This guide outlines how to upload your organization's specific guidelines to Mic
3030

3131
## Prerequisites
3232

33-
- You must have appropriate permissions to upload files in the Microsoft Defender portal. Typically, this requires being assigned a role such as Security Administrator.
33+
- You must be at least a security administrator to upload, approve or delete files. Security operators can review the guidebooks but not manage them.
3434
- Your organization-specific guidelines should be in a supported format (PDF, DOCX, TXT) and should not exceed the maximum file size limit of 3 MB.
3535

3636
## Steps to upload organization-specific guidelines
@@ -52,20 +52,11 @@ Then follow these steps:
5252
1. Browse to the file location, choose the file, and then select **Generate**.
5353
1. After the file is uploaded, go to the **Pending review** tab.
5454

55-
:::image type="content" source="{source}" alt-text="{alt-text}":::
56-
57-
1. The pending review tab shows the new recommendations based on the uploaded guidebook. Review the file to ensure it meets your organization's standards. Select the guidebook name and review the suggested generated tasks.
58-
59-
6055
:::image type="content" source="./media/security-upload-guide/pending-review.png" alt-text="Screenshot of the pending review tab for uploaded guidebooks.":::
6156

57+
1. The pending review tab shows the new recommendations based on the uploaded guidebook. Review the file to ensure it meets your organization's standards. Select the guidebook name and review the suggested generated tasks.
6258
1. If the guidebook meets your standards, select **Approve and activate** to make it available for use in guided responses. If it does not meet your standards, select **Delete** to remove it.
6359

6460
:::image type="content" source="./media/security-upload-guide/approve-guidebook.png" alt-text="Screenshot of the approve and activate button for uploaded guidebooks.":::
6561

6662
Copilot uses the most relevant guidance it has for each incident. A banner shows which guidebook is being used for the current recommendation.
67-
68-
## Considerations and limitations
69-
70-
- You must be at least a security administrator to upload, approve or delete files. Security operators can review the guidebooks but not manage them.
71-
-

0 commit comments

Comments
 (0)