You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/deception-overview.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -47,7 +47,7 @@ The following table lists the requirements to enable the deception capability in
47
47
> |Requirement|Details|
48
48
> |-------------|----------|
49
49
> |Subscription requirements|One of these subscriptions:</br> - Microsoft 365 E5</br> - Microsoft Security E5</br> - Microsoft Defender for Endpoint Plan 2|
50
-
> |Deployment requirements|Requirements:</br> - Defender for Endpoint is the primary EDR solution</br> - [Automated investigation and response capabilities in Defender for Endpoint](/defender-endpoint/configure-automated-investigations-remediation) is configured</br> - Devices are [joined](/entra/identity/devices/concept-directory-join/) or [hybrid joined](/entra/identity/devices/concept-hybrid-join/) in Microsoft Entra</br> - PowerShell is enabled on the devices</br> - The deception feature covers clients operating on Windows 10 RS5 and later in preview|
50
+
> |Deployment requirements|Requirements:</br> - Defender for Endpoint is the primary EDR solution</br> - [Automated investigation and response capabilities in Defender for Endpoint](/defender-endpoint/configure-automated-investigations-remediation) is configured</br> - Devices are [joined](/entra/identity/devices/concept-directory-join/) or [hybrid joined](/entra/identity/devices/concept-hybrid-join/) in Microsoft Entra</br> - PowerShell is enabled on the devices (in non-restricted/non-constrained mode)</br> - The deception feature covers clients operating on Windows 10 RS5 and later in preview|
51
51
> |Permissions|You must have one of the following roles assigned in the [Microsoft Entra admin center](https://entra.microsoft.com) or in the [Microsoft 365 admin center](https://admin.microsoft.com) to configure deception capabilities:</br> - Global administrator</br> - Security administrator</br> - Manage portal system settings|
Copy file name to clipboardExpand all lines: unified-secops-platform/overview-plan.md
+31-1Lines changed: 31 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ author: batamig
5
5
ms.author: bagol
6
6
ms.service: unified-secops-platform
7
7
ms.topic: concept-article #Don't change.
8
-
ms.date: 12/02/2024
8
+
ms.date: 02/09/2025
9
9
ms.collection:
10
10
- usx-security
11
11
@@ -48,6 +48,7 @@ Other services supported in the Microsoft Defender portal as part of Microsoft's
48
48
|[**Microsoft Defender for Cloud**](/azure/defender-for-cloud/)| Protects multi-cloud and hybrid environments with advanced threat detection and response. |
49
49
|[**Microsoft Defender Threat Intelligence**](/defender/threat-intelligence/what-is-microsoft-defender-threat-intelligence-defender-ti)| Streamlines threat intelligence workflows by aggregating and enriching critical data sources to correlate indicators of compromise (IOCs) with related articles, actor profiles, and vulnerabilities. |
50
50
|[**Microsoft Entra ID Protection**](/entra/id-protection/overview-identity-protection)| Evaluates risk data from sign-in attempts to evaluate the risk of each sign-in to your environment. |
51
+
|**[Microsoft Purview Insider Risk Management](/purview/insider-risk-management)**| Correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage and security violations. |
51
52
52
53
## Review service prerequisites
53
54
@@ -71,6 +72,7 @@ Before you deploy Microsoft's unified security operations platform, review the p
71
72
| Microsoft Defender for Cloud |[Start planning multicloud protection](/azure/defender-for-cloud/plan-multicloud-security-get-started) and other articles in the same section. |
72
73
| Microsoft Defender Threat Intelligence |[Prerequisites for Defender Threat Intelligence](/defender/threat-intelligence/learn-how-to-access-microsoft-defender-threat-intelligence-and-make-customizations-in-your-portal#prerequisites)|
73
74
| Microsoft Entra ID Protection |[Prerequisites for Microsoft Entra ID Protection](/entra/id-protection/how-to-deploy-identity-protection#prerequisites)|
75
+
| Microsoft Purview Insider Risk Management |[Get started with insider risk management](/purview/insider-risk-management-configure?tabs=purview-portal)|
74
76
75
77
## Review data security and privacy practices
76
78
@@ -94,6 +96,7 @@ Before you deploy Microsoft's unified security operations platform, make sure th
94
96
| Microsoft Defender for Cloud |[Microsoft Defender for Cloud data security](/azure/defender-for-cloud/data-security)|
95
97
| Microsoft Defender Threat Intelligence |[Data security and retention in Microsoft Defender XDR](/defender-xdr/data-privacy)|
96
98
| Microsoft Entra ID Protection |[Microsoft Entra data retention](/entra/identity/monitoring-health/reference-reports-data-retention)|
99
+
| Microsoft Purview Insider Risk Management |[Microsoft Purview Insider Risk Management and Communication Compliance privacy guide](/purview/insider-risk-solution-privacy) <br><br> [Messaging Records Management (MRM) and Retention Policies in Microsoft 365](/microsoft-365/troubleshoot/retention/mrm-and-retention-policy)|
97
100
98
101
## Plan your Log Analytics workspace architecture
99
102
@@ -148,6 +151,29 @@ Plan your Microsoft Sentinel budget, considering cost implications for each plan
148
151
-[Log retention plans in Microsoft Sentinel](/azure/sentinel/log-plans)
149
152
-[Plan costs and understand Microsoft Sentinel pricing and billing](/azure/sentinel/billing?tabs=simplified%2Ccommitment-tiers)
150
153
154
+
## Understand Microsoft security portals and admin centers
155
+
156
+
While the Microsoft Defender portal is the home for monitoring and managing security across your identities, data, devices, and apps, you need to access various portals for certain specialized tasks.
157
+
158
+
Microsoft security portals include:
159
+
160
+
| Portal name | Description | Link |
161
+
|---|---|---|
162
+
|**Microsoft Defender portal**| Monitor and respond to threat activity and strengthen security posture across your identities, email, data, endpoints, and apps with Microsoft Defender XDR](../defender-xdr/microsoft-365-defender.md)|[security.microsoft.com](https://security.microsoft.com/) <br/><br/>The Microsoft Defender portal is where you view and manage alerts, incidents, settings, and more. |
163
+
|**Defender for Cloud portal**| Use [Microsoft Defender for Cloud](/azure/security-center/security-center-intro) to strengthen the security posture of your data centers and your hybrid workloads in the cloud |[portal.azure.com/#blade/Microsoft_Azure_Security](https://portal.azure.com/#blade/Microsoft_Azure_Security/SecurityMenuBlade/0)|
164
+
|**Microsoft Security Intelligence portal**| Get security intelligence updates for Microsoft Defender for Endpoint, submit samples, and explore the threat encyclopedia |[microsoft.com/wdsi](https://microsoft.com/wdsi)|
165
+
166
+
The following table describes portals for other workloads that can impact your security. Visit these portals to manage identities, permissions, device settings, and data handling policies.
167
+
168
+
| Portal name | Description | Link |
169
+
|---|---|---|
170
+
|**Microsoft Entra admin center**| Access and administer the [Microsoft Entra](/entra) family to protect your business with decentralized identity, identity protection, governance, and more, in a multicloud environment|[entra.microsoft.com](https://entra.microsoft.com/)|
171
+
|**Azure portal**| View and manage all your [Azure resources](/azure/azure-resource-manager/management/overview)|[portal.azure.com](https://portal.azure.com/)|
172
+
|**Microsoft Purview portal**| Manage data handling policies and ensure [compliance with regulations](/compliance/regulatory/offering-home)|[purview.microsoft.com](https://purview.microsoft.com/)|
173
+
|**Microsoft 365 admin center**| Configure Microsoft 365 services; manage roles, licenses, and track updates to your Microsoft 365 services |[admin.microsoft.com](https://go.microsoft.com/fwlink/p/?linkid=2166757)|
174
+
|**Microsoft Intune admin center**| Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to manage and secure devices. Can also combine Intune and Configuration Manager capabilities. |[intune.microsoft.com](https://intune.microsoft.com/)|
175
+
|**Microsoft Intune portal**| Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to deploy device policies and monitor devices for compliance |[intune.microsoft.com](https://intune.microsoft.com/#blade/Microsoft_Intune_DeviceSettings/DevicesMenu/overview)|
176
+
151
177
## Plan roles and permissions
152
178
153
179
Use Microsoft Entra role based access control (RBAC) to create and assign roles within your security operations team to grant appropriate access to services included in Microsoft's unified SecOps platform.
@@ -171,6 +197,7 @@ For the following services, use the different roles available, or create custom
171
197
|**Other services supported in the Microsoft Defender portal**||
172
198
| Microsoft Security Exposure Management |[Permissions for Microsoft Security Exposure Management](/security-exposure-management/prerequisites)|
173
199
| Microsoft Defender for Cloud |[User roles and permissions](/azure/defender-for-cloud/permissions)|
200
+
| Microsoft Purview Insider Risk Management |[Enable permissions for insider risk management](/purview/insider-risk-management-configure?tabs=purview-portal#step-1-required-enable-permissions-for-insider-risk-management)|
174
201
175
202
## Plan Zero Trust activities
176
203
@@ -196,9 +223,12 @@ For more information about implementing Zero Trust principles in Microsoft's uni
196
223
-[Microsoft Defender for Cloud](/azure/defender-for-cloud/zero-trust?toc=/unified-secops-platform/toc.json&bc=/unified-secops-platform/breadcrumb/toc.json)
0 commit comments