Skip to content

Commit c43addd

Browse files
authored
Merge branch 'main' into ueba-anomaly-updates
2 parents e42bb95 + 0476698 commit c43addd

File tree

303 files changed

+2483
-3043
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

303 files changed

+2483
-3043
lines changed

.github/workflows/AutoLabelAssign.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ jobs:
2626
name: Run assign and label
2727
if: github.repository_owner == 'MicrosoftDocs'
2828
needs: [download-payload]
29-
uses: MicrosoftDocs/microsoft-365-docs/.github/workflows/Shared-AutoLabelAssign.yml@workflows-prod
29+
uses: MicrosoftDocs/microsoft-365-docs/.github/workflows/Shared-AutoLabelAssign.yml@workflows-test
3030
with:
3131
PayloadJson: ${{ needs.download-payload.outputs.WorkflowPayload }}
3232
AutoAssignUsers: 1

.github/workflows/AutoPublish.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,8 @@ permissions:
77

88
on:
99
schedule:
10-
- cron: "25 2,5,8,11,14,17,20,22 * * *" # Times are UTC based on Daylight Saving Time. Need to be adjusted for Standard Time. Scheduling at :25 to account for queuing lag.
10+
# - cron: "25 2,5,8,11,14,17,20,22 * * *" # Times are UTC based on Daylight Saving Time (~Mar-Nov). Scheduling at :25 to account for queuing lag.
11+
- cron: "25 3,6,9,12,15,18,21,23 * * *" # Times are UTC based on Standard Time (~Nov-Mar). Scheduling at :25 to account for queuing lag.
1112

1213
workflow_dispatch:
1314

.openpublishing.redirection.defender-endpoint.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -165,5 +165,10 @@
165165
"redirect_url": "/defender-xdr/contact-defender-support",
166166
"redirect_document_id": false
167167
},
168+
{
169+
"source_path": "defender-endpoint/install-defender-endpoint-linux.md",
170+
"redirect_url": "/defender-endpoint/mde-linux-prerequisites",
171+
"redirect_document_id": false
172+
}
168173
]
169174
}

.openpublishing.redirection.defender-identity.json

Lines changed: 246 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -869,6 +869,252 @@
869869
"source_path": "defender-for-identity/support.md",
870870
"redirect_url": "/defender-xdr/contact-defender-support",
871871
"redirect_document_id": false
872+
},
873+
{
874+
"source_path": "defender-for-identity/assign-multi-factor-authentication-okta-privileged-user-accounts.md",
875+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
876+
"redirect_document_id": false
877+
},
878+
{
879+
"source_path": "defender-for-identity/change-okta-password-privileged-user-accounts.md",
880+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
881+
"redirect_document_id": false
882+
},
883+
{
884+
"source_path": "defender-for-identity/high-number-of-okta-accounts-with-privileged-role-assigned.md",
885+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
886+
"redirect_document_id": false
887+
},
888+
{
889+
"source_path": "defender-for-identity/highly-privileged-okta-api-token.md",
890+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
891+
"redirect_document_id": false
892+
},
893+
{
894+
"source_path": "defender-for-identity/limit-number-okta-super-admin-accounts.md",
895+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
896+
"redirect_document_id": false
897+
},
898+
{
899+
"source_path": "defender-for-identity/remove-dormant-okta-privileged-accounts.md",
900+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
901+
"redirect_document_id": false
902+
},
903+
{
904+
"source_path": "defender-for-identity/accounts-with-non-default-pgid.md",
905+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
906+
"redirect_document_id": false
907+
},
908+
{
909+
"source_path": "defender-for-identity/security-assessment-remove-suspicious-access-rights.md",
910+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
911+
"redirect_document_id": false
912+
},
913+
{
914+
"source_path": "defender-for-identity/change-password-krbtgt-account.md",
915+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
916+
"redirect_document_id": false
917+
},
918+
{
919+
"source_path": "defender-for-identity/change-password-domain-administrator-account.md",
920+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
921+
"redirect_document_id": false
922+
},
923+
{
924+
"source_path": "defender-for-identity/security-assessment-dormant-entities.md",
925+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
926+
"redirect_document_id": false
927+
},
928+
{
929+
"source_path": "defender-for-identity/security-assessment-non-admin-accounts-dcsync.md",
930+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
931+
"redirect_document_id": false
932+
},
933+
{
934+
"source_path": "defender-for-identity/ensure-privileged-accounts-with-sensitive-flag.md",
935+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
936+
"redirect_document_id": false
937+
},
938+
{
939+
"source_path": "defender-for-identity/security-assessment-clear-text.md",
940+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
941+
"redirect_document_id": false
942+
},
943+
{
944+
"source_path": "defender-for-identity/security-assessment-laps.md",
945+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
946+
"redirect_document_id": false
947+
},
948+
{
949+
"source_path": "defender-for-identity/remove-discoverable-passwords-active-directory-account-attributes.md",
950+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
951+
"redirect_document_id": false
952+
},
953+
{
954+
"source_path": "defender-for-identity/remove-inactive-service-account.md",
955+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
956+
"redirect_document_id": false
957+
},
958+
{
959+
"source_path": "defender-for-identity/security-assessment-riskiest-lmp.md",
960+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
961+
"redirect_document_id": false
962+
},
963+
{
964+
"source_path": "defender-for-identity/security-assessment-unconstrained-kerberos.md",
965+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
966+
"redirect_document_id": false
967+
},
968+
{
969+
"source_path": "defender-for-identity/security-assessment-unsecure-sid-history-attribute.md",
970+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
971+
"redirect_document_id": false
972+
},
973+
{
974+
"source_path": "defender-for-identity/security-assessment-unsecure-account-attributes.md",
975+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
976+
"redirect_document_id": false
977+
},
978+
{
979+
"source_path": "defender-for-identity/security-assessment-weak-cipher.md",
980+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
981+
"redirect_document_id": false
982+
},
983+
{
984+
"source_path": "defender-for-identity/security-assessment-enforce-encryption-rpc.md",
985+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
986+
"redirect_document_id": false
987+
},
988+
{
989+
"source_path": "defender-for-identity/security-assessment-insecure-adcs-certificate-enrollment.md",
990+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
991+
"redirect_document_id": false
992+
},
993+
{
994+
"source_path": "defender-for-identity/security-assessment-edit-misconfigured-owner.md",
995+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
996+
"redirect_document_id": false
997+
},
998+
{
999+
"source_path": "defender-for-identity/security-assessment-edit-misconfigured-ca-acl.md",
1000+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1001+
"redirect_document_id": false
1002+
},
1003+
{
1004+
"source_path": "defender-for-identity/security-assessment-edit-misconfigured-acl.md",
1005+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1006+
"redirect_document_id": false
1007+
},
1008+
{
1009+
"source_path": "defender-for-identity/security-assessment-edit-misconfigured-enrollment-agent.md",
1010+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1011+
"redirect_document_id": false
1012+
},
1013+
{
1014+
"source_path": "defender-for-identity/security-assessment-edit-overly-permissive-template.md",
1015+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1016+
"redirect_document_id": false
1017+
},
1018+
{
1019+
"source_path": "defender-for-identity/prevent-certificate-enrollment-esc15.md",
1020+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1021+
"redirect_document_id": false
1022+
},
1023+
{
1024+
"source_path": "defender-for-identity/security-assessment-prevent-users-request-certificate.md",
1025+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1026+
"redirect_document_id": false
1027+
},
1028+
{
1029+
"source_path": "defender-for-identity/security-assessment-edit-vulnerable-ca-setting.md",
1030+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1031+
"redirect_document_id": false
1032+
},
1033+
{
1034+
"source_path": "defender-for-identity/gpo-assigns-unprivileged-identities.md",
1035+
"redirect_url": "/defender-for-identity/security-posture-assessments/group-policy",
1036+
"redirect_document_id": false
1037+
},
1038+
{
1039+
"source_path": "defender-for-identity/modified-unprivileged-accounts-gpo.md",
1040+
"redirect_url": "/defender-for-identity/security-posture-assessments/group-policy",
1041+
"redirect_document_id": false
1042+
},
1043+
{
1044+
"source_path": "defender-for-identity/reversible-passwords-group-policy.md",
1045+
"redirect_url": "/defender-for-identity/security-posture-assessments/group-policy",
1046+
"redirect_document_id": false
1047+
},
1048+
{
1049+
"source_path": "defender-for-identity/built-in-active-directory-guest-account-is-enabled.md",
1050+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1051+
"redirect_document_id": false
1052+
},
1053+
{
1054+
"source_path": "defender-for-identity/domain-controller-account-password-change.md",
1055+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1056+
"redirect_document_id": false
1057+
},
1058+
{
1059+
"source_path": "defender-for-identity/security-assessment-print-spooler.md",
1060+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1061+
"redirect_document_id": false
1062+
},
1063+
{
1064+
"source_path": "defender-for-identity/security-assessment-remove-local-admins.md",
1065+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1066+
"redirect_document_id": false
1067+
},
1068+
{
1069+
"source_path": "defender-for-identity/security-assessment-unmonitored-domain-controller.md",
1070+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1071+
"redirect_document_id": false
1072+
},
1073+
{
1074+
"source_path": "defender-for-identity/unmonitored-active-directory-certificate-services-server.md",
1075+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1076+
"redirect_document_id": false
1077+
},
1078+
{
1079+
"source_path": "defender-for-identity/unmonitored-active-directory-federation-services-servers.md",
1080+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1081+
"redirect_document_id": false
1082+
},
1083+
{
1084+
"source_path": "defender-for-identity/unmonitored-entra-connect-servers.md",
1085+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1086+
"redirect_document_id": false
1087+
},
1088+
{
1089+
"source_path": "defender-for-identity/security-assessment-unsecure-domain-configurations.md",
1090+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1091+
"redirect_document_id": false
1092+
},
1093+
{
1094+
"source_path": "defender-for-identity/remove-replication-permissions-microsoft-entra-connect.md",
1095+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1096+
"redirect_document_id": false
1097+
},
1098+
{
1099+
"source_path": "defender-for-identity/remove-unsafe-permissions-sensitive-entra-connect.md",
1100+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1101+
"redirect_document_id": false
1102+
},
1103+
{
1104+
"source_path": "defender-for-identity/replace-entra-connect-default-admin.md",
1105+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1106+
"redirect_document_id": false
1107+
},
1108+
{
1109+
"source_path": "defender-for-identity/change-password-microsoft-entra-seamless-single-sign-on.md",
1110+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1111+
"redirect_document_id": false
1112+
},
1113+
{
1114+
"source_path": "defender-for-identity/rotate-password-microsoft-entra-connect.md",
1115+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1116+
"redirect_document_id": false
8721117
}
1118+
8731119
]
8741120
}

defender-endpoint/TOC.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
items:
99
- name: What is Microsoft Defender for Endpoint?
1010
items:
11-
- name: Defender for Endpoint on Windows
11+
- name: Defender for Endpoint
1212
href: microsoft-defender-endpoint.md
1313
- name: Defender for Endpoint on macOS
1414
href: microsoft-defender-endpoint-mac.md
@@ -263,7 +263,7 @@
263263
items:
264264
- name: Prerequisites
265265
href: mde-linux-prerequisites.md
266-
- name: Choose a deployment method
266+
- name: Choose a deployment method
267267
items:
268268
- name: Enabling deployment to a custom location
269269
href: linux-custom-location-installation.md

defender-endpoint/android-configure.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
ms.topic: how-to
1616
ms.subservice: android
1717
search.appverid: met150
18-
ms.date: 10/23/2025
18+
ms.date: 11/06/2025
1919
appliesto:
2020
- Microsoft Defender for Endpoint Plan 1
2121
- Microsoft Defender for Endpoint Plan 2
@@ -33,7 +33,7 @@ For more information about how to set up Defender for Endpoint on Android and Co
3333
## Configure custom indicators
3434

3535
> [!NOTE]
36-
> Defender for Endpoint on Android only supports creating custom indicators for IP addresses and URLs/domains.
36+
> Defender for Endpoint on Android supports creating custom indicators only for URLs and domains. IP-based custom indicators aren't supported on Android.
3737
>
3838
> IP `245.245.0.1` is an internal Defender IP and should not be included in custom indicators by customers to avoid any functionality issues.
3939
> Also, alerts for custom indicators are currently not supported for Defender for Endpoint on Android.

defender-endpoint/android-new-ux.md

Lines changed: 24 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
ms.topic: reference
1616
ms.subservice: android
1717
search.appverid: met150
18-
ms.date: 09/16/2025
18+
ms.date: 11/06/2025
1919
---
2020

2121
# User experiences in Microsoft Defender for Endpoint on Android
@@ -24,7 +24,29 @@ As part of our ongoing commitment to deliver exceptional user experiences, we're
2424

2525
The new enhancements are designed to improve usability, streamline navigation, and ensure our app meets the evolving needs of our users.
2626

27-
## Key changes - September 2025
27+
## Key changes - November 2025
28+
29+
In this release, we've made it easier for users to share feedback, including logs, to the Microsoft Defender team. The changes include:
30+
31+
- [A new bottom pane that makes it easier for users to share feedback and logs](#bottom-pane-experience)
32+
- [A new **Send logs to Microsoft** option that enables users to quickly send logs to Microsoft](#one-click-send-logs-experience)
33+
34+
35+
### Bottom pane experience
36+
37+
When users select **Help and Feedback** in the left navigation pane (Screen 1, accessible by tapping the profile picture), a new bottom feedback pane opens (Screen 2). This pane has been updated to improve readability and make it easier for users to share feedback.
38+
39+
The **Send feedback** option in the updated bottom pane enables users to share positive or negative feedback, along with Microsoft Defender and authenticator logs, which will be accessible to the Microsoft Defender team. When a user selects **Send feedback**, they are redirected to a new screen (Screen 3) where they can include logs along with their feedback submission.
40+
41+
:::image type="content" source="./media/android-new-ux/bottom-experience-android.png" alt-text="Screenshots showing how to send feedback and logs from the Microsoft Defender mobile app options menu." border="false":::
42+
43+
### One-click *Send Logs* experience
44+
45+
A new **Send logs to Microsoft** option has been added directly to the left navigation pane. This enables users to quickly send logs to Microsoft. It redirects them to the logs submission page (Screen 2). This option is particularly useful when a support case has been created and a support engineer is assigned, providing a convenient way for users to submit logs. Because this option doesn't allow users to include written feedback, the Defender team will not have access to the logs unless an incident ID is explicitly shared via mail or support request. This option collects logs from both the Defender and Authenticator apps.
46+
47+
:::image type="content" source="./media/android-new-ux/one-click-feedback-android.png" alt-text="Screenshots showing how to send logs directly to Microsoft from the Microsoft Defender mobile app options menu." border="false":::
48+
49+
## Key changes - September 2025
2850

2951
We're pleased to introduce the new Onboarding screens that come up when the user starts onboarding after sign-in.
3052

0 commit comments

Comments
 (0)