You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/pilot-deploy-defender-cloud-apps.md
+8-6Lines changed: 8 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
2
title: How do I pilot and deploy Microsoft Defender for Cloud Apps?
3
-
description: How to pilot and deploy Microsoft Defender for Cloud Apps in your production Microsoft 365 tenant.
3
+
description: Learn how to pilot and deploy Microsoft Defender for Cloud Apps as part of Microsoft Defender XDR to enhance your organization's security posture.
4
4
search.appverid: met150
5
5
ms.service: defender-xdr
6
6
f1.keywords:
@@ -18,7 +18,9 @@ ms.collection:
18
18
- zerotrust-solution
19
19
- highpri
20
20
- tier1
21
-
ms.topic: conceptual
21
+
ms.topic: concept-article
22
+
#customerIntent: As a security admin, I want to pilot and deploy Microsoft Defender for Cloud Apps to evaluate it's ability to enhance my organization's security posture and protect against cloud application-based threats.
23
+
22
24
---
23
25
24
26
# Pilot and deploy Microsoft Defender for Cloud Apps
@@ -27,9 +29,9 @@ ms.topic: conceptual
27
29
28
30
- Microsoft Defender XDR
29
31
30
-
This article provides a workflow for piloting and deploying Microsoft Defender for Cloud Apps in your organization. You can use these recommendations to onboard Microsoft Defender for Cloud Apps as an individual cybersecurity tool or as part of an end-to-end solution with Microsoft Defender XDR.
32
+
This article provides a workflow for piloting and deploying Microsoft Defender for Cloud Apps in your organization. Use these recommendations to onboard Microsoft Defender for Cloud Apps as part of an end-to-end solution with Microsoft Defender XDR.
31
33
32
-
This article assumes you have a production Microsoft 365 tenant and are piloting and deploying Microsoft Defender for Cloud Apps in this environment. This practice will maintain any settings and customizations you configure during your pilot for your full deployment.
34
+
This article assumes you have a production Microsoft 365 tenant and are piloting and deploying Microsoft Defender for Cloud Apps in this environment. This practice will maintain any settings and customizations you configure during your pilot for your [full deployment](/defender-cloud-apps/get-started).
33
35
34
36
Defender for Office 365 contributes to a Zero Trust architecture by helping to prevent or reduce business damage from a breach. For more information, see the [Prevent or reduce business damage from a breach](/security/zero-trust/adopt/prevent-reduce-business-damage-breach) business scenario in the Microsoft Zero Trust adoption framework.
35
37
@@ -114,7 +116,7 @@ This article includes guidance for both methods.
114
116
115
117
## Step 1. Access Microsoft Defender for Cloud Apps
116
118
117
-
To verify licensing and to connect to the Defender for Cloud Apps portal, see [Get started with Microsoft Defender for Cloud Apps](/defender-cloud-apps/getting-started-with-defender-cloud-apps).
119
+
To verify licensing and to connect to the Defender for Cloud Apps portal, see [Get started with Microsoft Defender for Cloud Apps](defender-cloud-apps/get-started).
118
120
119
121
If you're not immediately able to connect to the portal, you might need to add the IP address to the allow list of your firewall. For more information, see [Basic setup for Defender for Cloud Apps](/defender-cloud-apps/general-setup).
120
122
@@ -261,7 +263,7 @@ You can integrate Defender for Cloud Apps with Microsoft Sentinel or a generic s
261
263
262
264
:::image type="content" source="./media/eval-defender-xdr/defender-cloud-apps-siem-integration.svg" alt-text="A diagram that shows the architecture for Microsoft Defender for Cloud Apps with SIEM integration." lightbox="./media/eval-defender-xdr/defender-cloud-apps-siem-integration.svg":::
263
265
264
-
Microsoft Sentinel includes a Defender for Cloud Apps connector. This allows you to not only gain visibility into your cloud apps but to also get sophisticated analytics to identify and combat cyberthreats and to control how your data travels. For more information, see [Microsoft Sentinel integration](/defender-cloud-apps/siem-sentinel) and [Stream alerts and Cloud Discovery logs from Defender for Cloud Apps into Microsoft Sentinel](/azure/sentinel/connect-defender-cloud-apps).
266
+
Microsoft Sentinel includes a Defender for Cloud Apps connector. This allows you to not only gain visibility into your cloud apps but to also get sophisticated analytics to identify and combat cyberthreats and to control how your data travels. For more information, see [Microsoft Sentinel integration](/defender-cloud-apps/siem-sentinel) and [Stream alerts and Cloud Discovery logs from Defender for Cloud Apps into Microsoft Sentinel](azure/sentinel/data-connectors/microsoft-defender-for-cloud-apps).
265
267
266
268
For information about integration with third-party SIEM systems, see [Generic SIEM integration](/defender-cloud-apps/siem).
Copy file name to clipboardExpand all lines: defender-xdr/pilot-deploy-defender-identity.md
+14-15Lines changed: 14 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
-
title: How do I pilot and deploy Microsoft Defender for Identity>
3
-
description: How to pilot and deploy Microsoft Defender for Identity in your production Microsoft 365 tenant.
2
+
title: How do I pilot and deploy Microsoft Defender for Identity
3
+
description: Learn how to pilot and deploy Microsoft Defender for Identity as part of Microsoft Defender XDR to enhance your organization's security posture.
4
4
search.appverid: met150
5
5
ms.service: defender-xdr
6
6
f1.keywords:
@@ -18,16 +18,16 @@ ms.collection:
18
18
- zerotrust-solution
19
19
- highpri
20
20
- tier1
21
-
ms.topic: conceptual
21
+
ms.topic: concept-article
22
+
#customerIntent: As a security admin, I want to pilot and deploy Microsoft Defender for Identity to evaluate it's ability to enhance my organization's security posture and protect against identity-based threats.
22
23
---
23
24
24
25
# Pilot and deploy Microsoft Defender for Identity
25
26
26
-
27
27
**Applies to:**
28
28
- Microsoft Defender XDR
29
29
30
-
This article provides a workflow for piloting and deploying Microsoft Defender for Identity in your organization. You can use these recommendations to onboard Microsoft Defender for Identity as an individual cybersecurity tool or as part of an end-to-end solution with Microsoft Defender XDR.
30
+
This article provides a workflow for piloting and deploying Microsoft Defender for Identity in your organization. Use these recommendations to onboard Microsoft Defender for Identity as part of an end-to-end solution with Microsoft Defender XDR.
31
31
32
32
This article assumes you have a production Microsoft 365 tenant and are piloting and deploying Microsoft Defender for Identity in this environment. This practice will maintain any settings and customizations you configure during your pilot for your [full deployment](/defender-for-identity/deploy/deploy-defender-identity).
33
33
@@ -127,11 +127,9 @@ Sign in to the Defender portal to start deploying supported services, including
127
127
128
128
## Step 2: Install your sensors
129
129
130
-
First, Defender for Identity requires some prerequisite work to ensure that your on-premises identity and networking components meet minimum requirements. Use the [Microsoft Defender for Identity prerequisites](/defender-for-identity/prerequisites) article as a checklist to ensure your environment is ready.
131
-
132
-
Next, make sure that you have the necessary permissions and prerequisites in place to install the Defender for Identity sensor in your environment, and plan your capacity requirements. For more information, see [Plan capacity for Microsoft Defender for Identity deployment](/defender-for-identity/deploy/capacity-planning).
130
+
Defender for Identity requires some prerequisite work to ensure that your on-premises identity and networking components meet minimum requirements for you to install the Defender for Identity sensor in your environment.
133
131
134
-
When you're ready, download, install, and configure the Defender for Identity sensor on the domain controllers, AD FS, and AD CS servers in your on-premises environment.
132
+
Once you're sure of your environment's readiness, plan your capacity, and verify connectivity to Defender for Identity. Then when you're ready, download, install, and configure the Defender for Identity sensor on the domain controllers, AD FS, and AD CS servers in your on-premises environment.
135
133
136
134
| Step | Description | More information |
137
135
|---|---|---|
@@ -145,11 +143,11 @@ When you're ready, download, install, and configure the Defender for Identity se
145
143
146
144
## Step 3: Configure event log and proxy settings on machines with the sensor
147
145
148
-
On the machines that you installed the sensor on, configure Windows event log collection and Internet proxy settings to enable and enhance detection capabilities.
146
+
On the machines that you installed the sensor on, configure Windows event log collection to enable and enhance detection capabilities.
149
147
150
148
| Step | Description | More information |
151
149
|---|---|---|
152
-
| 1 | Configure Windows event log collection |[Event collection with Microsoft Defender for Identity](/defender-for-identity/deploy/event-collection-overview)and [Configure audit policies for Windows event logs](/defender-for-identity/deploy/configure-windows-event-collection)|
150
+
| 1 | Configure Windows event log collection |[Event collection with Microsoft Defender for Identity](/defender-for-identity/deploy/event-collection-overview)<br><br>[Configure audit policies for Windows event logs](/defender-for-identity/deploy/configure-windows-event-collection)|
153
151
154
152
<aname="step-4"></a>
155
153
@@ -185,13 +183,14 @@ For more information, see:
185
183
186
184
## SIEM integration
187
185
188
-
You can integrate Defender for Identity with Microsoft Sentinel or a generic security information and event management (SIEM) service to enable centralized monitoring of alerts and activities from connected apps. With Microsoft Sentinel, you can more comprehensively analyze security events across your organization and build playbooks for effective and immediate response.
186
+
You can integrate Defender for Identity with Microsoft Sentinel as part of Microsoft's [unified security operations platform](/unified-secops-platform/)or a generic security information and event management (SIEM) service to enable centralized monitoring of alerts and activities from connected apps. With Microsoft Sentinel, you can more comprehensively analyze security events across your organization and build playbooks for effective and immediate response.
189
187
190
-
:::image type="content" source="./media/eval-defender-xdr/defender-identity-siem-integration.svg" alt-text="A diagram that shows the architecture for Microsoft Defender for Identity with SIEM integration." lightbox="./media/eval-defender-xdr/defender-identity-siem-integration.svg":::
188
+
Microsoft Sentinel includes a Microsoft Defender for XDR data connector to bring all signals from Defender XDR, including Defender for Identity, to Microsoft Sentinel. Use the unified security operations platform in the Defender portal as a single platform for end-to-end security operations (SecOps).
191
189
192
-
Microsoft Sentinel includes a Defender for Identity connector. For more information, see[Microsoft Defender for Identity connector for Microsoft Sentinel](/azure/sentinel/data-connectors/microsoft-defender-for-identity).
190
+
For more information, see:
193
191
194
-
For information about integration with third-party SIEM systems, see [Generic SIEM integration](/cloud-app-security/siem).
192
+
-[Connect Microsoft Sentinel to the Microsoft Defender portal](/defender-xdr/microsoft-sentinel-onboard)
0 commit comments