Skip to content

Commit d54f870

Browse files
authored
new license topic and move retention to prereq
update licenses
2 parents bfb772c + 88ecaf9 commit d54f870

File tree

4 files changed

+95
-58
lines changed

4 files changed

+95
-58
lines changed

exposure-management/TOC.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,9 @@
77
- name: What is Microsoft Security Exposure Management?
88
href: microsoft-security-exposure-management.md
99
- name: What's new
10-
href: whats-new.md
10+
href: whats-new.md
11+
- name: Integration and licensing
12+
href: integration-licensing.md
1113
- name: Compare Secure Score and Security Exposure Management
1214
href: compare-secure-score-security-exposure-management.md
1315
- name: Get started
Lines changed: 74 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,74 @@
1+
---
2+
title: Integration and Licensing for Microsoft Security Exposure Management
3+
description: Learn about integration capabilities, licensing options, and how to get started with Microsoft Security Exposure Management.
4+
author: dlanger
5+
ms.author: dlanger
6+
manager: rayne-wiselman
7+
ms.topic: overview
8+
ms.service: exposure-management
9+
ms.date: 02/24/2025
10+
---
11+
12+
13+
# Integration and licensing for Microsoft Security Exposure Management
14+
15+
Microsoft Security Exposure Management provides a comprehensive consolidation of security posture information from various Microsoft services and external data sources, ensuring robust security management and detailed insights.
16+
17+
18+
19+
## What's integrated into Security Exposure Management?
20+
21+
Currently, Security Exposure Management consolidates security posture information and insights from workloads that include:
22+
23+
- Microsoft Defender for Endpoint
24+
- Microsoft Defender for Identity
25+
- Microsoft Defender for Cloud Apps
26+
- Microsoft Defender for Office
27+
- Microsoft Defender for IoT
28+
- Microsoft Secure Score
29+
- Microsoft Defender Vulnerability Management
30+
- Microsoft Defender for Cloud
31+
- Microsoft Entra ID
32+
- Microsoft Defender External Attack Surface Management (EASM)
33+
34+
In addition to Microsoft services, Security Exposure Management allows you to connect to external data sources to further enrich and extend your security posture management.
35+
For more information on data connectors, see [Data connectors overview](overview-data-connectors.md).
36+
37+
## How do I buy Microsoft Security Exposure Management?
38+
39+
Exposure Management is available in the Microsoft Defender portal at [https://security.microsoft.com](https://security.microsoft.com)
40+
41+
Access to the exposure management blade and features in the Microsoft Defender portal according to the license requirements.
42+
43+
The following licenses allow accessing all Microsoft Security Exposure Management experiences:
44+
45+
- Microsoft 365 E5 or A5
46+
- Microsoft 365 E3 with the Microsoft 365 E5 Security add-on
47+
- Microsoft 365 E3 with the Enterprise Mobility + Security E5 add-on
48+
- Microsoft 365 A3 with the Microsoft 365 A5 Security add-on
49+
- Windows 10 Enterprise E5 or A5
50+
- Windows 11 Enterprise E5 or A5
51+
- Enterprise Mobility + Security (EMS) E5 or A5
52+
- Office 365 E5 or A5
53+
- Microsoft Defender for Endpoint
54+
- Microsoft Defender for Identity
55+
- Microsoft Defender for Cloud Apps or Cloud App Discovery
56+
- Microsoft Defender for Office 365 (Plan 2)
57+
- Microsoft 365 Business Premium
58+
- Microsoft Defender for Business
59+
- Microsoft Defender for Cloud
60+
61+
Integration of data from the above tools and other Microsoft Security tools like Microsoft Defender for Cloud, Microsoft Defender Cloud Security Posture Management, and Microsoft Defender External Attack Surface Management is available with those licenses.
62+
63+
Integration of non-Microsoft security tools will be a consumption-based cost based on number of assets in the connected security tool. The external connectors are free during public preview, and pricing will be announced before starting to bill for external connectors at GA.
64+
65+
The following licenses will allow access to Microsoft Secure Score experience only:
66+
67+
- Microsoft 365 E3
68+
- Microsoft 365 A3
69+
- Microsoft Defender for Endpoint (Plan 2)
70+
- Microsoft Defender for Office 365 (Plan 2)
71+
72+
## Next steps
73+
74+
Review [prerequisites](prerequisites.md) to get started with Security Exposure Management.

exposure-management/microsoft-security-exposure-management.md

Lines changed: 1 addition & 57 deletions
Original file line numberDiff line numberDiff line change
@@ -55,62 +55,6 @@ With Security Exposure Management you can:
5555
- Gain deeper insights into your security posture by integrating data from various environments.
5656
- Simplify the management of security data across different platforms and solutions.
5757

58-
## What's integrated into Security Exposure Management?
59-
60-
Currently, Security Exposure Management consolidates security posture information and insights from workloads that include:
61-
62-
- Microsoft Defender for Endpoint
63-
- Microsoft Defender for Identity
64-
- Microsoft Defender for Cloud Apps
65-
- Microsoft Defender for Office
66-
- Microsoft Defender for IoT
67-
- Microsoft Secure Score
68-
- Microsoft Defender Vulnerability Management
69-
- Microsoft Defender for Cloud
70-
- Microsoft Entra ID
71-
- Microsoft Defender External Attack Surface Management (EASM)
72-
73-
In addition to Microsoft services, Security Exposure Management allows you to connect to external data sources to further enrich and extend your security posture management.
74-
For more information on data connectors, see [Data connectors overview](overview-data-connectors.md).
75-
76-
## How do I buy Microsoft Security Exposure Management?
77-
78-
Exposure Management is available in the Microsoft Defender portal at [https://security.microsoft.com](https://security.microsoft.com)
79-
80-
Access to the exposure management blade and features in the Microsoft Defender portal is available with any of these licenses:
81-
82-
- Microsoft 365 E5 o*r A5*
83-
- Microsoft 365 E3
84-
- Microsoft 365 E3 with the Microsoft Enterprise Mobility + Security E5 add-on
85-
- Microsoft 365 A3 with the Microsoft 365 A5 security add-on
86-
- Microsoft Enterprise Mobility + Security E5 or A5
87-
- Microsoft Defender for Endpoint (Plan 1 and 2)
88-
- Microsoft Defender for Identity
89-
- Microsoft Defender for Cloud Apps
90-
- Microsoft Defender for Office 365 (Plans 1 and 2)
91-
- Microsoft Defender Vulnerability Management
92-
93-
Integration of data from the above tools and other Microsoft Security tools like Microsoft Defender for Cloud, Microsoft Defender Cloud Security Posture Management and Microsoft Defender External Attack Surface Management is available with those licenses.
94-
95-
Integration of non-Microsoft security tools will be a consumption-based cost based on number of assets in the connected security tool. The external connectors are free during public preview, and pricing will be announced before starting to bill for external connectors at GA.
96-
97-
### Data freshness, retention, and related functionality
98-
99-
We currently ingest and process supported data from first-party Microsoft products, making it available within the enterprise exposure graph and applicable Microsoft Security Exposure Management experiences built on top of graph data within 72 hours of its production at the source product.
100-
101-
Microsoft product data is retained for no less than 14 days in the enterprise exposure graph and/or Microsoft Security Exposure Management. Only the latest data snapshot received from Microsoft products is retained; we do not store historical data.
102-
103-
Some enterprise exposure graph and/or Microsoft Security Exposure Management experiences data is available for querying via Advanced Hunting and is subject to Advanced Hunting service limitations.
104-
105-
We reserve the right to modify some or all of these parameters in the future, including:
106-
107-
- Data ingestion frequency and freshness: We may increase the current 72-hour latency (decrease the frequency of data ingestion) for some or all Microsoft data sources.
108-
- Data retention period: We may decrease the current 14-day data retention period.
109-
- Service features and functionality: We may alter, limit, or discontinue specific features, capabilities, or functionalities of the service built on top of the enterprise exposure graph and/or Microsoft Security Exposure Management data.
110-
- Data query limits: We may impose limitations on the number, frequency, or type of data queries that can be performed against enterprise exposure graph or Microsoft Security Exposure Management data.
111-
112-
We will make reasonable efforts to provide advance notice of any significant changes to the service. However, you acknowledge and agree that you are solely responsible for monitoring any such notifications.
113-
11458
## Next steps
11559

116-
Review [prerequisites](prerequisites.md) to get started with Security Exposure Management.
60+
Review [integration and licensing](integration-licensing.md) for Microsoft Security Exposure Management to understand how to access and use the service.

exposure-management/prerequisites.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -106,6 +106,23 @@ C:\Program Files\Windows Defender Advanced Threat Protection. Right-click the fi
106106

107107
``` DeviceInfo | project DeviceName, ClientVersion ```
108108

109+
## Data freshness, retention, and related functionality
110+
111+
We currently ingest and process supported data from first-party Microsoft products, making it available within the enterprise exposure graph and applicable Microsoft Security Exposure Management experiences built on top of graph data within 72 hours of its production at the source product.
112+
113+
Microsoft product data is retained for no less than 14 days in the enterprise exposure graph and/or Microsoft Security Exposure Management. Only the latest data snapshot received from Microsoft products is retained; we do not store historical data.
114+
115+
Some enterprise exposure graph and/or Microsoft Security Exposure Management experiences data is available for querying via Advanced Hunting and is subject to Advanced Hunting service limitations.
116+
117+
We reserve the right to modify some or all of these parameters in the future, including:
118+
119+
- Data ingestion frequency and freshness: We may increase the current 72-hour latency (decrease the frequency of data ingestion) for some or all Microsoft data sources.
120+
- Data retention period: We may decrease the current 14-day data retention period.
121+
- Service features and functionality: We may alter, limit, or discontinue specific features, capabilities, or functionalities of the service built on top of the enterprise exposure graph and/or Microsoft Security Exposure Management data.
122+
- Data query limits: We may impose limitations on the number, frequency, or type of data queries that can be performed against enterprise exposure graph or Microsoft Security Exposure Management data.
123+
124+
We will make reasonable efforts to provide advance notice of any significant changes to the service. However, you acknowledge and agree that you are solely responsible for monitoring any such notifications.
125+
109126
## Getting support
110127

111128
To get support, select the Help question mark icon in the Microsoft Security toolbar.

0 commit comments

Comments
 (0)