Skip to content

Commit cca5e3a

Browse files
authored
Merge branch 'main' into batamig-patch-3
2 parents cab2b07 + 8e27a1f commit cca5e3a

34 files changed

+211
-259
lines changed

defender-business/get-defender-business.md

Lines changed: 7 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -5,17 +5,14 @@ search.appverid: MET150
55
author: siosulli
66
ms.author: siosulli
77
manager: deniseb
8-
98
audience: Admin
109
ms.topic: overview
1110
ms.service: defender-business
1211
ms.localizationpriority: medium
13-
ms.date: 09/07/2023
12+
ms.date: 06/07/2024
1413
ms.reviewer: efratka
1514
f1.keywords: NOCSH
16-
1715
ms.collection:
18-
1916
- SMB
2017
- m365-security
2118
- tier1
@@ -34,9 +31,6 @@ Sections include:
3431
- **[Portals that you use](#portals-you-use-for-setup-and-management)** to set up, configure, and manage Defender for Business
3532
- **[Next steps](#next-step)**, such as adding users and assigning licenses.
3633

37-
> [!IMPORTANT]
38-
> You should be a global administrator to complete the tasks described in this article. The person who signs your company up for Microsoft 365 is a global administrator. [Learn more about admin roles in the Microsoft 365 admin center](/Microsoft-365/admin/add-users/about-admin-roles).
39-
4034
## How to get Microsoft Defender for Business
4135

4236
To get Defender for Business, you can choose from several options:
@@ -107,7 +101,7 @@ Microsoft has a list of solution providers who are authorized to sell offerings,
107101

108102
Microsoft Defender for Business servers is an add-on to Defender for Business that enables you to secure your server operating systems with the same protection that you get for client devices in Defender for Business.
109103

110-
1. Go to the Microsoft 365 admin center ([https://admin.microsoft.com/](https://admin.microsoft.com/)), and sign in.
104+
1. Go to the [Microsoft 365 admin center](https://admin.microsoft.com), and sign in.
111105

112106
2. In the navigation pane, choose **Billing** > **Purchase services**.
113107

@@ -118,7 +112,6 @@ Microsoft Defender for Business servers is an add-on to Defender for Business th
118112
> [!IMPORTANT]
119113
>
120114
> - In order to add on Microsoft Defender for Business servers, you'll need at least one paid license for [Defender for Business](mdb-overview.md) (standalone) or [Microsoft 365 Business Premium](/Microsoft-365/business-premium/m365bp-overview).
121-
>
122115
> - There's a limit of 60 Microsoft Defender for Business servers licenses per subscription to Microsoft 365 Business Premium or Defender for Business.
123116
> - If preferred, you could use [Microsoft Defender for Servers Plan 1 or Plan 2](/azure/defender-for-cloud/plan-defender-for-servers) instead to onboard your servers. To learn more, see [What happens if I have a mix of Microsoft endpoint security subscriptions](mdb-faq.yml#what-happens-if-i-have-a-mix-of-microsoft-endpoint-security-subscriptions)?
124117
@@ -133,10 +126,12 @@ If your subscription also includes Microsoft Intune, you use the Intune admin ce
133126

134127
|Portal|Description|
135128
|---|---|
136-
|The Microsoft 365 admin center ([https://admin.microsoft.com/](https://admin.microsoft.com/))|Use the Microsoft 365 admin center to activate your trial and sign in for the first time. You can also use the Microsoft 365 admin center to: <br/>- Add or remove users.<br/>- Assign user licenses.<br/>- View your products and services.<br/>- Complete setup tasks for your Microsoft 365 subscription.<br/><br/>To learn more, see [Overview of the Microsoft 365 admin center](/Microsoft-365/admin/admin-overview/admin-center-overview).|
137-
|The Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com))|Use the Microsoft Defender portal to set up and configure Defender for Business, and to monitor your devices and threat detections. You use the Microsoft Defender portal to: <br/>- View your devices and device protection policies.<br/>- View detected threats and take action.<br/>- View security recommendations and manage your security settings.<br/><br/>To learn more, see [Get started using the Microsoft Defender portal](mdb-get-started.md).|
138-
|The Intune admin center ([https://intune.microsoft.com/](https://intune.microsoft.com/))|Use the Intune admin center to set up multifactor authentication (MFA), onboard iOS and Android devices, and configure certain capabilities, such as [attack surface reduction rules](mdb-asr.md).<br/><br/>To learn more about Intune, see [Microsoft Intune is an MDM and MAM provider for your devices](/mem/intune/fundamentals/what-is-intune).|
129+
|The [Microsoft 365 admin center](https://admin.microsoft.com/)|Use the Microsoft 365 admin center to activate your trial and sign in for the first time. You can also use the Microsoft 365 admin center to: <br/>- Add or remove users.<br/>- Assign user licenses.<br/>- View your products and services.<br/>- Complete setup tasks for your Microsoft 365 subscription.<br/><br/>To learn more, see [Overview of the Microsoft 365 admin center](/Microsoft-365/admin/admin-overview/admin-center-overview).|
130+
|The [Microsoft Defender portal](https://security.microsoft.com)|Use the Microsoft Defender portal to set up and configure Defender for Business, and to monitor your devices and threat detections. You use the Microsoft Defender portal to: <br/>- View your devices and device protection policies.<br/>- View detected threats and take action.<br/>- View security recommendations and manage your security settings.<br/><br/>To learn more, see [Get started using the Microsoft Defender portal](mdb-get-started.md).|
131+
|The [Intune admin center](https://intune.microsoft.com/)|Use the Intune admin center to set up multifactor authentication (MFA), onboard iOS and Android devices, and configure certain capabilities, such as [attack surface reduction rules](mdb-asr.md).<br/><br/>To learn more about Intune, see [Microsoft Intune is an MDM and MAM provider for your devices](/mem/intune/fundamentals/what-is-intune).|
139132

140133
## Next step
141134

135+
- [Assign administrator roles](/microsoft-365/admin/add-users/assign-admin-roles)
136+
142137
- Proceed to [Step 2: Add users and assign licenses in Microsoft Defender for Business](mdb-add-users.md).

defender-business/mdb-add-users.md

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ audience: Admin
99
ms.topic: conceptual
1010
ms.service: defender-business
1111
ms.localizationpriority: medium
12-
ms.date: 05/01/2023
12+
ms.date: 06/07/2024
1313
ms.collection:
1414
- m365-security
1515
- tier1
@@ -25,10 +25,7 @@ As soon as you have signed up for Defender for Business, your first step is to a
2525

2626
## Add users and assign licenses
2727

28-
> [!IMPORTANT]
29-
> You must be a global administrator to perform this task. The person who signed up your company for Microsoft 365 or for Defender for Business is a global administrator by default.
30-
31-
1. Go to the Microsoft 365 admin center at [https://admin.microsoft.com](https://admin.microsoft.com) and sign in.
28+
1. Go to the [Microsoft 365 admin center](https://admin.microsoft.com) and sign in.
3229

3330
2. Go to **Users** > **Active users**, and then select **Add a user**.
3431

@@ -50,9 +47,6 @@ As soon as you have signed up for Defender for Business, your first step is to a
5047

5148
One good way to make sure MFA is enabled for all users is by using [security defaults](/azure/active-directory/fundamentals/concept-fundamentals-security-defaults). If your tenant was created on or after October 22, 2019, security defaults might be enabled automatically in your tenant. Use the following procedure to confirm or enable security defaults.
5249

53-
> [!IMPORTANT]
54-
> You must be a security administrator, Conditional Access administrator, or Global Administrator to perform this task.
55-
5650
1. Go to the Azure portal ([https://portal.azure.com/](https://portal.azure.com/)) and sign in.
5751

5852
2. Under **Manage Microsoft Entra ID**, select **View**.

defender-business/mdb-asr.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Get an overview of attack surface reduction capabilities, including
44
author: siosulli
55
ms.author: siosulli
66
manager: deniseb
7-
ms.date: 11/30/2023
7+
ms.date: 06/07/2024
88
ms.topic: conceptual
99
ms.service: defender-business
1010
ms.localizationpriority: medium
@@ -38,7 +38,7 @@ These rules help protect your network and devices but shouldn't cause disruption
3838

3939
## Set up ASR rules using Intune
4040

41-
1. As a global administrator, in the Microsoft Intune admin center ([https://intune.microsoft.com/](https://intune.microsoft.com/)), go to **Endpoint security** > **Attack surface reduction**.
41+
1. In the [Microsoft Intune admin center](https://intune.microsoft.com/), go to **Endpoint security** > **Attack surface reduction**.
4242

4343
2. Choose **Create policy** to create a new policy.
4444

@@ -70,7 +70,7 @@ These rules help protect your network and devices but shouldn't cause disruption
7070

7171
Defender for Business includes an attack surface reduction report that shows how attack surface reduction rules are working for you.
7272

73-
1. As a global administrator, in the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)), in the navigation pane, choose **Reports**.
73+
1. In the [Microsoft Defender portal](https://security.microsoft.com), in the navigation pane, choose **Reports**.
7474

7575
2. Under **Endpoints**, choose **Attack surface reduction rules**. The report opens and includes three tabs:
7676

defender-business/mdb-attack-disruption.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Learn about automatic attack disruption in Microsoft Defender for B
44
author: siosulli
55
ms.author: siosulli
66
manager: deniseb
7-
ms.date: 10/12/2023
7+
ms.date: 06/07/2024
88
ms.topic: conceptual
99
ms.service: defender-business
1010
ms.localizationpriority: medium
@@ -41,8 +41,8 @@ Automated response actions include:
4141
- Containing a user account by disconnecting current user connections at the device level
4242

4343
> [!IMPORTANT]
44-
> - To view information about a detected advanced attack, you must have the Security Reader, Security Administrator, or Global Administrator role assigned.
45-
> - To take remediation actions, release a contained device/user, or re-enable a user account, you must have either the Security Administrator or Global Administrator role assigned.
44+
> - To view information about a detected advanced attack, you must have an appropriate role, such as Security Reader or Security Administrator assigned.
45+
> - To take remediation actions, release a contained device/user, or re-enable a user account, you must have the Security Administrator role assigned.
4646
> - See [Security roles and permissions in Defender for Business](mdb-roles-permissions.md).
4747
4848
<a name='view-details-about-an-attack-in-the-microsoft-365-defender-portal'></a>

defender-business/mdb-controlled-folder-access.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Get an overview of attack surface reduction capabilities in Microso
44
author: siosulli
55
ms.author: siosulli
66
manager: deniseb
7-
ms.date: 08/21/2023
7+
ms.date: 06/07/2024
88
ms.topic: conceptual
99
ms.service: defender-business
1010
ms.localizationpriority: medium
@@ -23,7 +23,7 @@ Controlled folder access allows only trusted apps to access protected folders on
2323

2424
## Set up controlled folder access
2525

26-
1. As a global administrator, in the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), go to **Endpoint security** > **Attack surface reduction**.
26+
1. In the [Microsoft Intune admin center](https://go.microsoft.com/fwlink/?linkid=2109431), go to **Endpoint security** > **Attack surface reduction**.
2727

2828
2. Select an existing policy, or choose **Create policy** to create a new policy.
2929

defender-business/mdb-manage-devices.md

Lines changed: 2 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ audience: Admin
99
ms.topic: how-to
1010
ms.service: defender-business
1111
ms.localizationpriority: medium
12-
ms.date: 05/10/2023
12+
ms.date: 06/07/2024
1313
ms.reviewer: nehabha
1414
f1.keywords: NOCSH
1515
ms.collection:
@@ -33,13 +33,6 @@ In Defender for Business, you can manage devices as follows:
3333

3434
:::image type="content" source="/defender/media/defender-business/mdb-device-inventory.png" alt-text="Screenshot of device inventory":::
3535

36-
> [!IMPORTANT]
37-
> In order to view the list of onboarded devices, you must have one of the following [roles](mdb-roles-permissions.md) assigned:
38-
>
39-
> - Global Administrator
40-
> - Security Administrator
41-
> - Security Reader
42-
4336
1. Go to the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)) and sign in.
4437

4538
2. In the navigation pane, go to **Assets** > **Devices**.
@@ -50,13 +43,7 @@ In Defender for Business, you can manage devices as follows:
5043

5144
## Take action on a device that has threat detections
5245

53-
:::image type="content" source="/defender/media/defender-business/mdb-selected-device.png" alt-text="Screenshot of a selected device with details and actions available":::
54-
55-
> [!IMPORTANT]
56-
> In order to take action on a device with detected threats, you must have one of the following [roles](mdb-roles-permissions.md) assigned:
57-
>
58-
> - Global Administrator
59-
> - Security Administrator
46+
:::image type="content" source="/defender/media/defender-business/mdb-selected-device.png" alt-text="Screenshot of a selected device with details and actions available.":::
6047

6148
1. In the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)), in the navigation pane, go to **Assets** > **Devices**.
6249

defender-business/mdb-manage-subscription.md

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -29,10 +29,6 @@ This article describes how to apply either Defender for Business or Defender for
2929
- You should have active trial or paid licenses for both Defender for Business and Defender for Endpoint Plan 2.
3030

3131
- If you're using Defender for Business only, you can continue using it. In this case, no changes are needed. But if you're considering switching to Defender for Endpoint Plan 2, follow the guidance in this article.
32-
- To access license information, you must have one of the following roles assigned in Microsoft Entra ID:
33-
34-
- Global Admin
35-
- Security Admin
3632

3733
## View and manage your endpoint security subscription settings
3834

@@ -64,11 +60,6 @@ The license usage report is estimated based on sign-in activities on the device.
6460

6561
To reduce management overhead, there's no requirement for device-to-user mapping and assignment. Instead, the license report provides a utilization estimation that is calculated based on device usage seen across your organization. It might take up to one day for your usage report to reflect the active usage of your devices.
6662

67-
> [!IMPORTANT]
68-
> To access license information, you must have one of the following roles assigned in Microsoft Entra ID:
69-
> - Security Admin
70-
> - Global Admin
71-
7263
1. Go to the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)) and sign in.
7364

7465
2. Choose **Settings** > **Endpoints** > **Licenses**.

defender-business/mdb-onboard-devices.md

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ audience: Admin
99
ms.topic: overview
1010
ms.service: defender-business
1111
ms.localizationpriority: medium
12-
ms.date: 08/08/2023
12+
ms.date: 06/07/2024
1313
ms.reviewer: efratka, nehabha, muktaagarwal
1414
f1.keywords: NOCSH
1515
ms.collection:
@@ -358,9 +358,6 @@ You can use the following methods to onboard an instance of Linux Server to Defe
358358

359359
## View a list of onboarded devices
360360

361-
> [!IMPORTANT]
362-
> You must be assigned an appropriate role, such as Global Administrator, Security Administrator, or Security Reader to perform the following procedure. For more information, see [Roles in Defender for Business](mdb-roles-permissions.md#roles-in-defender-for-business).
363-
364361
1. Go to the Microsoft Defender portal ([https://security.microsoft.com](https://security.microsoft.com)), and sign in.
365362

366363
2. In the navigation pane, go to **Assets** > **Devices**. The **Device inventory** view opens.

0 commit comments

Comments
 (0)