You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: unified-secops-platform/overview-plan.md
+14-9Lines changed: 14 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -48,6 +48,7 @@ Other services supported in the Microsoft Defender portal as part of Microsoft's
48
48
|[**Microsoft Defender for Cloud**](/azure/defender-for-cloud/)| Protects multi-cloud and hybrid environments with advanced threat detection and response. |
49
49
|[**Microsoft Defender Threat Intelligence**](/defender/threat-intelligence/what-is-microsoft-defender-threat-intelligence-defender-ti)| Streamlines threat intelligence workflows by aggregating and enriching critical data sources to correlate indicators of compromise (IOCs) with related articles, actor profiles, and vulnerabilities. |
50
50
|[**Microsoft Entra ID Protection**](/entra/id-protection/overview-identity-protection)| Evaluates risk data from sign-in attempts to evaluate the risk of each sign-in to your environment. |
51
+
|**Microsoft Purview Insider Risk Management**|[Learn about Insider Risk Management](/purview/insider-risk-management)|
51
52
52
53
## Review service prerequisites
53
54
@@ -71,6 +72,7 @@ Before you deploy Microsoft's unified security operations platform, review the p
71
72
| Microsoft Defender for Cloud |[Start planning multicloud protection](/azure/defender-for-cloud/plan-multicloud-security-get-started) and other articles in the same section. |
72
73
| Microsoft Defender Threat Intelligence |[Prerequisites for Defender Threat Intelligence](/defender/threat-intelligence/learn-how-to-access-microsoft-defender-threat-intelligence-and-make-customizations-in-your-portal#prerequisites)|
73
74
| Microsoft Entra ID Protection |[Prerequisites for Microsoft Entra ID Protection](/entra/id-protection/how-to-deploy-identity-protection#prerequisites)|
75
+
| Microsoft Purview Insider Risk Management |[Get started with insider risk management](/purview/insider-risk-management-configure?tabs=purview-portal)|
74
76
75
77
## Review data security and privacy practices
76
78
@@ -94,6 +96,7 @@ Before you deploy Microsoft's unified security operations platform, make sure th
94
96
| Microsoft Defender for Cloud |[Microsoft Defender for Cloud data security](/azure/defender-for-cloud/data-security)|
95
97
| Microsoft Defender Threat Intelligence |[Data security and retention in Microsoft Defender XDR](/defender-xdr/data-privacy)|
96
98
| Microsoft Entra ID Protection |[Microsoft Entra data retention](/entra/identity/monitoring-health/reference-reports-data-retention)|
99
+
| Microsoft Purview Insider Risk Management |[Microsoft Purview Insider Risk Management and Communication Compliance privacy guide](/purview/insider-risk-solution-privacy) <br><br> [Messaging Records Management (MRM) and Retention Policies in Microsoft 365](/microsoft-365/troubleshoot/retention/mrm-and-retention-policy)|
97
100
98
101
## Plan your Log Analytics workspace architecture
99
102
@@ -156,20 +159,20 @@ Microsoft security portals include:
156
159
157
160
| Portal name | Description | Link |
158
161
|---|---|---|
159
-
| Microsoft Defender portal | Monitor and respond to threat activity and strengthen security posture across your identities, email, data, endpoints, and apps with Microsoft Defender XDR](../defender-xdr/microsoft-365-defender.md)|[security.microsoft.com](https://security.microsoft.com/) <br/><br/>The Microsoft Defender portal is where you view and manage alerts, incidents, settings, and more. |
160
-
| Defender for Cloud portal | Use [Microsoft Defender for Cloud](/azure/security-center/security-center-intro) to strengthen the security posture of your data centers and your hybrid workloads in the cloud |[portal.azure.com/#blade/Microsoft_Azure_Security](https://portal.azure.com/#blade/Microsoft_Azure_Security/SecurityMenuBlade/0)|
161
-
| Microsoft Security Intelligence portal | Get security intelligence updates for Microsoft Defender for Endpoint, submit samples, and explore the threat encyclopedia |[microsoft.com/wdsi](https://microsoft.com/wdsi)|
162
+
|**Microsoft Defender portal**| Monitor and respond to threat activity and strengthen security posture across your identities, email, data, endpoints, and apps with Microsoft Defender XDR](../defender-xdr/microsoft-365-defender.md)|[security.microsoft.com](https://security.microsoft.com/) <br/><br/>The Microsoft Defender portal is where you view and manage alerts, incidents, settings, and more. |
163
+
|**Defender for Cloud portal**| Use [Microsoft Defender for Cloud](/azure/security-center/security-center-intro) to strengthen the security posture of your data centers and your hybrid workloads in the cloud |[portal.azure.com/#blade/Microsoft_Azure_Security](https://portal.azure.com/#blade/Microsoft_Azure_Security/SecurityMenuBlade/0)|
164
+
|**Microsoft Security Intelligence portal**| Get security intelligence updates for Microsoft Defender for Endpoint, submit samples, and explore the threat encyclopedia |[microsoft.com/wdsi](https://microsoft.com/wdsi)|
162
165
163
166
The following table describes portals for other workloads that can impact your security. Visit these portals to manage identities, permissions, device settings, and data handling policies.
164
167
165
168
| Portal name | Description | Link |
166
169
|---|---|---|
167
-
| Microsoft Entra admin center | Access and administer the [Microsoft Entra](/entra) family to protect your business with decentralized identity, identity protection, governance, and more, in a multicloud environment|[entra.microsoft.com](https://entra.microsoft.com/)|
168
-
| Azure portal | View and manage all your [Azure resources](/azure/azure-resource-manager/management/overview)|[portal.azure.com](https://portal.azure.com/)|
169
-
| Microsoft Purview portal | Manage data handling policies and ensure [compliance with regulations](/compliance/regulatory/offering-home)|[purview.microsoft.com](https://purview.microsoft.com/)|
170
-
| Microsoft 365 admin center | Configure Microsoft 365 services; manage roles, licenses, and track updates to your Microsoft 365 services |[admin.microsoft.com](https://go.microsoft.com/fwlink/p/?linkid=2166757)|
171
-
| Microsoft Intune admin center | Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to manage and secure devices. Can also combine Intune and Configuration Manager capabilities. |[intune.microsoft.com](https://intune.microsoft.com/)|
172
-
| Microsoft Intune portal | Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to deploy device policies and monitor devices for compliance |[intune.microsoft.com](https://intune.microsoft.com/#blade/Microsoft_Intune_DeviceSettings/DevicesMenu/overview)|
170
+
|**Microsoft Entra admin center**| Access and administer the [Microsoft Entra](/entra) family to protect your business with decentralized identity, identity protection, governance, and more, in a multicloud environment|[entra.microsoft.com](https://entra.microsoft.com/)|
171
+
|**Azure portal**| View and manage all your [Azure resources](/azure/azure-resource-manager/management/overview)|[portal.azure.com](https://portal.azure.com/)|
172
+
|**Microsoft Purview portal**| Manage data handling policies and ensure [compliance with regulations](/compliance/regulatory/offering-home)|[purview.microsoft.com](https://purview.microsoft.com/)|
173
+
|**Microsoft 365 admin center**| Configure Microsoft 365 services; manage roles, licenses, and track updates to your Microsoft 365 services |[admin.microsoft.com](https://go.microsoft.com/fwlink/p/?linkid=2166757)|
174
+
|**Microsoft Intune admin center**| Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to manage and secure devices. Can also combine Intune and Configuration Manager capabilities. |[intune.microsoft.com](https://intune.microsoft.com/)|
175
+
|**Microsoft Intune portal**| Use [Microsoft Intune](/mem/intune/fundamentals/what-is-intune) to deploy device policies and monitor devices for compliance |[intune.microsoft.com](https://intune.microsoft.com/#blade/Microsoft_Intune_DeviceSettings/DevicesMenu/overview)|
173
176
174
177
## Plan roles and permissions
175
178
@@ -194,6 +197,7 @@ For the following services, use the different roles available, or create custom
194
197
|**Other services supported in the Microsoft Defender portal**||
195
198
| Microsoft Security Exposure Management |[Permissions for Microsoft Security Exposure Management](/security-exposure-management/prerequisites)|
196
199
| Microsoft Defender for Cloud |[User roles and permissions](/azure/defender-for-cloud/permissions)|
200
+
| Microsoft Purview Insider Risk Management |[Enable permissions for insider risk management](/purview/insider-risk-management-configure?tabs=purview-portal#step-1-required-enable-permissions-for-insider-risk-management)|
197
201
198
202
## Plan Zero Trust activities
199
203
@@ -219,6 +223,7 @@ For more information about implementing Zero Trust principles in Microsoft's uni
219
223
-[Microsoft Defender for Cloud](/azure/defender-for-cloud/zero-trust?toc=/unified-secops-platform/toc.json&bc=/unified-secops-platform/breadcrumb/toc.json)
0 commit comments