Skip to content

Commit c023506

Browse files
authored
Merge pull request #2253 from MicrosoftDocs/main
Published main to live, Tuesday 5:00 PM IST, 12/24
2 parents a44c32d + 8069352 commit c023506

File tree

3 files changed

+16
-14
lines changed

3 files changed

+16
-14
lines changed

defender-xdr/defender-experts-scoped-coverage.md

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 12/20/2024
20+
ms.date: 12/24/2024
2121
---
2222

2323
# Scoped coverage in Microsoft Defender Experts for XDR
@@ -34,17 +34,19 @@ Devices and users that are out of scope won't be supported by Defender Experts.
3434

3535
## Using Defender Experts scoped coverage
3636

37-
You can create a predefined Microsoft Defender for Endpoint device group or a Microsoft Entra ID user group in the Microsoft Defender portal to which you can add devices and users, respectively. The default name assigned to the created device or user group is:
37+
You can create a predefined Microsoft Defender for Endpoint device group or a Microsoft Entra ID user group in the Microsoft Defender portal to which you can add devices and users, respectively. The name assigned to the created device or user group should be the following:
3838

3939
- **Defender_Experts_Scoped_Coverage_Devices**
4040
- **Defender_Experts_Scoped_Coverage_Users**
4141

42-
The devices and users you add to these groups are then considered as the set of assets that are in scope for this service.
43-
4442
:::image type="content" source="media/defender_scoped_devices.png" alt-text="Screenshot of Defender Experts Scoped devices." lightbox="media/defender_scoped_devices.png":::
4543

44+
:::image type="content" source="media/defender-experts-scoped-users.png" alt-text="Screenshot of Defender Experts Scoped users." lightbox="media/defender-experts-scoped-users.png":::
45+
46+
The devices and users you add to these groups are then considered as the set of assets that are in scope for this service.
47+
4648
> [!NOTE]
47-
> Defender Experts need **Security admin** permissions to create the device and user groups. [Learn more about granting permissions to our experts](get-started-xdr.md#grant-permissions-to-our-experts).
49+
> You need **Security admin** permissions to create the device and user groups. [Learn more about granting permissions to our experts](get-started-xdr.md#grant-permissions-to-our-experts).
4850
4951
> [!TIP]
5052
> The device group should be in the highest order of priority for the devices under it, to be considered in scope. This is a known product limitation.
@@ -54,8 +56,8 @@ Currently, the service doesn't offer support to rename these predefined groups,
5456
The following section lists down questions that you or your SOC team might have regarding scoped coverage:
5557

5658
1. **What aspects of the XDR service remain consistent with Defender Experts scoped coverage?**
57-
- This service doesn't change our pricing structure. You still pay for Defender Experts service based on E5 (Microsoft Defender for Servers) for your desired user base.
58-
- This service doesn't scope according to individual Microsoft Defender products and services (such as Defender for Endpoint, Microsoft Defender for Office 365, or Microsoft Defender for Cloud). That is, the minimum baseline for scoped coverage is still the E5 license.
59+
- This service doesn't change our pricing structure. You still pay for Defender Experts service based on [E5](before-you-begin-xdr.md#eligibility-and-licensing) and Microsoft Defender for Endpoint for Servers for your desired user base.
60+
- This service doesn't scope according to individual Microsoft Defender products and services (such as Microsoft Defender for Endpoint, Microsoft Defender for Office 365, or Microsoft Defender for Cloud). That is, the minimum baseline for scoped coverage is still the E5 license.
5961
- There's no change in permissions for analysts in Defender Experts for XDR. Defender Experts analysts will still have access to your entire tenant and not just the scoped assets.
6062

6163
2. **Can I change the scoped assets later?**

defender-xdr/experts-on-demand.md

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ ms.collection:
2121
- essentials-manage
2222
ms.topic: conceptual
2323
search.appverid: met150
24-
ms.date: 12/20/2024
24+
ms.date: 12/24/2024
2525
---
2626

2727
# Collaborate with experts on demand
@@ -85,7 +85,7 @@ The option to **Ask Defender Experts** is available in several places throughout
8585

8686
### In portal
8787

88-
You can view responses to inquiries submitted to Ask Defender Experts from up to six months ago by navigating to **Reports** > **Defender Experts messages**. You'll also be able to ask follow-up questions or reply with more information to Defender Experts from this page.
88+
You can view responses to inquiries submitted to Ask Defender Experts from up to six months ago by navigating to **Reports** > **Defender Experts messages**. You can also ask follow-up questions or reply with more information to Defender Experts from this page.
8989

9090
:::image type="content" source="media/inportal-managed-response.png" alt-text="Screenshot of in-portal managed response." lightbox="media/inportal-managed-response.png":::
9191

@@ -124,22 +124,22 @@ If you included contact email addresses when submitting your inquiry, they'll re
124124

125125
## Services that aren't in scope for Defender Experts
126126

127-
Ask Defender Experts is focused on products that are only included in Microsoft Defender XDR, i.e., Microsoft Defender for Endpoint, Microsoft Defender for Office, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity.
127+
Ask Defender Experts is focused on products that are only included in Microsoft Defender XDR, that is, Microsoft Defender for Endpoint, Microsoft Defender for Office, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity.
128128

129129
The service doesn't cover the following scenarios:
130130

131-
- Inquiries related to custom detections in the above products can't be handled in Ask Defender Experts because our experts typically don't have access to such telemetry or visibility into how these custom policies were set up. Examples of such policies include:
131+
- **Inquiries related to custom detections**- Inquiries related to custom detections in the above products can't be handled in Ask Defender Experts because our experts typically don't have access to such telemetry or visibility into how these custom policies were set up. Examples of such policies include:
132132

133133
- **Alerts with policy source** = **Custom**
134134
- **Detection source** = **Custom TI**
135135
- **Alert title** = **Anomaly Indicator**
136136
- **Threat family** = **Custom Enterprise Block Only**
137137

138-
- Defender Experts won't be able to handle inquiries on non-Defender XDR products such as Microsoft Defender for Cloud, Microsoft Defender for IoT, Microsoft Sentinel, Microsoft Purview, Microsoft Priva, and other third-party cybersecurity products.
138+
- **Inquiries related to non-Microsoft Defender XDR products**- Defender Experts don't handle inquiries on non-Defender XDR products such as Microsoft Defender for Cloud, Microsoft Defender for IoT, Microsoft Sentinel, Microsoft Purview, Microsoft Priva, and other third-party cybersecurity products.
139139

140-
- Defender Experts won't be able to assist you with inquiries regarding bugs in your product experience in the Defender XDR portal, such as, missing data on the alert or incident page or a recommended action not completing when you action it. You can reach out to Microsoft Support via the [Services Hub](https://serviceshub.microsoft.com/home) regarding such issues.
140+
- **Inquiries regarding bugs**- Defender Experts don't handle inquiries regarding bugs in your product experience in the Defender XDR portal, such as, missing data on the alert or incident page or a recommended action not completing when you action it. You can reach out to Microsoft Support via the [Services Hub](https://serviceshub.microsoft.com/home) regarding such issues.
141141

142-
- Ask Defender Experts isn't a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
142+
- **Inquiries related to security incident response issues**- Ask Defender Experts isn't a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
143143

144144
### Next step
145145

133 KB
Loading

0 commit comments

Comments
 (0)