Skip to content

Commit d636bd3

Browse files
committed
fixing pilot and deploy
1 parent d256d15 commit d636bd3

File tree

3 files changed

+22
-21
lines changed

3 files changed

+22
-21
lines changed
23.5 KB
Loading

defender-xdr/pilot-deploy-defender-cloud-apps.md

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: How do I pilot and deploy Microsoft Defender for Cloud Apps?
3-
description: How to pilot and deploy Microsoft Defender for Cloud Apps in your production Microsoft 365 tenant.
3+
description: Learn how to pilot and deploy Microsoft Defender for Cloud Apps as part of Microsoft Defender XDR to enhance your organization's security posture.
44
search.appverid: met150
55
ms.service: defender-xdr
66
f1.keywords:
@@ -18,7 +18,9 @@ ms.collection:
1818
- zerotrust-solution
1919
- highpri
2020
- tier1
21-
ms.topic: conceptual
21+
ms.topic: concept-article
22+
#customerIntent: As a security admin, I want to pilot and deploy Microsoft Defender for Cloud Apps to evaluate it's ability to enhance my organization's security posture and protect against cloud application-based threats.
23+
2224
---
2325

2426
# Pilot and deploy Microsoft Defender for Cloud Apps
@@ -27,9 +29,9 @@ ms.topic: conceptual
2729

2830
- Microsoft Defender XDR
2931

30-
This article provides a workflow for piloting and deploying Microsoft Defender for Cloud Apps in your organization. You can use these recommendations to onboard Microsoft Defender for Cloud Apps as an individual cybersecurity tool or as part of an end-to-end solution with Microsoft Defender XDR.
32+
This article provides a workflow for piloting and deploying Microsoft Defender for Cloud Apps in your organization. Use these recommendations to onboard Microsoft Defender for Cloud Apps as part of an end-to-end solution with Microsoft Defender XDR.
3133

32-
This article assumes you have a production Microsoft 365 tenant and are piloting and deploying Microsoft Defender for Cloud Apps in this environment. This practice will maintain any settings and customizations you configure during your pilot for your full deployment.
34+
This article assumes you have a production Microsoft 365 tenant and are piloting and deploying Microsoft Defender for Cloud Apps in this environment. This practice will maintain any settings and customizations you configure during your pilot for your [full deployment](/defender-cloud-apps/get-started).
3335

3436
Defender for Office 365 contributes to a Zero Trust architecture by helping to prevent or reduce business damage from a breach. For more information, see the [Prevent or reduce business damage from a breach](/security/zero-trust/adopt/prevent-reduce-business-damage-breach) business scenario in the Microsoft Zero Trust adoption framework.
3537

@@ -114,7 +116,7 @@ This article includes guidance for both methods.
114116

115117
## Step 1. Access Microsoft Defender for Cloud Apps
116118

117-
To verify licensing and to connect to the Defender for Cloud Apps portal, see [Get started with Microsoft Defender for Cloud Apps](/defender-cloud-apps/getting-started-with-defender-cloud-apps).
119+
To verify licensing and to connect to the Defender for Cloud Apps portal, see [Get started with Microsoft Defender for Cloud Apps](defender-cloud-apps/get-started).
118120

119121
If you're not immediately able to connect to the portal, you might need to add the IP address to the allow list of your firewall. For more information, see [Basic setup for Defender for Cloud Apps](/defender-cloud-apps/general-setup).
120122

@@ -261,7 +263,7 @@ You can integrate Defender for Cloud Apps with Microsoft Sentinel or a generic s
261263

262264
:::image type="content" source="./media/eval-defender-xdr/defender-cloud-apps-siem-integration.svg" alt-text="A diagram that shows the architecture for Microsoft Defender for Cloud Apps with SIEM integration." lightbox="./media/eval-defender-xdr/defender-cloud-apps-siem-integration.svg":::
263265

264-
Microsoft Sentinel includes a Defender for Cloud Apps connector. This allows you to not only gain visibility into your cloud apps but to also get sophisticated analytics to identify and combat cyberthreats and to control how your data travels. For more information, see [Microsoft Sentinel integration](/defender-cloud-apps/siem-sentinel) and [Stream alerts and Cloud Discovery logs from Defender for Cloud Apps into Microsoft Sentinel](/azure/sentinel/connect-defender-cloud-apps).
266+
Microsoft Sentinel includes a Defender for Cloud Apps connector. This allows you to not only gain visibility into your cloud apps but to also get sophisticated analytics to identify and combat cyberthreats and to control how your data travels. For more information, see [Microsoft Sentinel integration](/defender-cloud-apps/siem-sentinel) and [Stream alerts and Cloud Discovery logs from Defender for Cloud Apps into Microsoft Sentinel](azure/sentinel/data-connectors/microsoft-defender-for-cloud-apps).
265267

266268
For information about integration with third-party SIEM systems, see [Generic SIEM integration](/defender-cloud-apps/siem).
267269

defender-xdr/pilot-deploy-defender-identity.md

Lines changed: 14 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: How do I pilot and deploy Microsoft Defender for Identity>
3-
description: How to pilot and deploy Microsoft Defender for Identity in your production Microsoft 365 tenant.
2+
title: How do I pilot and deploy Microsoft Defender for Identity
3+
description: Learn how to pilot and deploy Microsoft Defender for Identity as part of Microsoft Defender XDR to enhance your organization's security posture.
44
search.appverid: met150
55
ms.service: defender-xdr
66
f1.keywords:
@@ -18,16 +18,16 @@ ms.collection:
1818
- zerotrust-solution
1919
- highpri
2020
- tier1
21-
ms.topic: conceptual
21+
ms.topic: concept-article
22+
#customerIntent: As a security admin, I want to pilot and deploy Microsoft Defender for Identity to evaluate it's ability to enhance my organization's security posture and protect against identity-based threats.
2223
---
2324

2425
# Pilot and deploy Microsoft Defender for Identity
2526

26-
2727
**Applies to:**
2828
- Microsoft Defender XDR
2929

30-
This article provides a workflow for piloting and deploying Microsoft Defender for Identity in your organization. You can use these recommendations to onboard Microsoft Defender for Identity as an individual cybersecurity tool or as part of an end-to-end solution with Microsoft Defender XDR.
30+
This article provides a workflow for piloting and deploying Microsoft Defender for Identity in your organization. Use these recommendations to onboard Microsoft Defender for Identity as part of an end-to-end solution with Microsoft Defender XDR.
3131

3232
This article assumes you have a production Microsoft 365 tenant and are piloting and deploying Microsoft Defender for Identity in this environment. This practice will maintain any settings and customizations you configure during your pilot for your [full deployment](/defender-for-identity/deploy/deploy-defender-identity).
3333

@@ -127,11 +127,9 @@ Sign in to the Defender portal to start deploying supported services, including
127127

128128
## Step 2: Install your sensors
129129

130-
First, Defender for Identity requires some prerequisite work to ensure that your on-premises identity and networking components meet minimum requirements. Use the [Microsoft Defender for Identity prerequisites](/defender-for-identity/prerequisites) article as a checklist to ensure your environment is ready.
131-
132-
Next, make sure that you have the necessary permissions and prerequisites in place to install the Defender for Identity sensor in your environment, and plan your capacity requirements. For more information, see [Plan capacity for Microsoft Defender for Identity deployment](/defender-for-identity/deploy/capacity-planning).
130+
Defender for Identity requires some prerequisite work to ensure that your on-premises identity and networking components meet minimum requirements for you to install the Defender for Identity sensor in your environment.
133131

134-
When you're ready, download, install, and configure the Defender for Identity sensor on the domain controllers, AD FS, and AD CS servers in your on-premises environment.
132+
Once you're sure of your environment's readiness, plan your capacity, and verify connectivity to Defender for Identity. Then when you're ready, download, install, and configure the Defender for Identity sensor on the domain controllers, AD FS, and AD CS servers in your on-premises environment.
135133

136134
| Step | Description | More information |
137135
|---|---|---|
@@ -145,11 +143,11 @@ When you're ready, download, install, and configure the Defender for Identity se
145143

146144
## Step 3: Configure event log and proxy settings on machines with the sensor
147145

148-
On the machines that you installed the sensor on, configure Windows event log collection and Internet proxy settings to enable and enhance detection capabilities.
146+
On the machines that you installed the sensor on, configure Windows event log collection to enable and enhance detection capabilities.
149147

150148
| Step | Description | More information |
151149
|---|---|---|
152-
| 1 | Configure Windows event log collection | [Event collection with Microsoft Defender for Identity](/defender-for-identity/deploy/event-collection-overview) and [Configure audit policies for Windows event logs](/defender-for-identity/deploy/configure-windows-event-collection) |
150+
| 1 | Configure Windows event log collection | [Event collection with Microsoft Defender for Identity](/defender-for-identity/deploy/event-collection-overview) <br><br>[Configure audit policies for Windows event logs](/defender-for-identity/deploy/configure-windows-event-collection) |
153151

154152
<a name="step-4"></a>
155153

@@ -185,13 +183,14 @@ For more information, see:
185183

186184
## SIEM integration
187185

188-
You can integrate Defender for Identity with Microsoft Sentinel or a generic security information and event management (SIEM) service to enable centralized monitoring of alerts and activities from connected apps. With Microsoft Sentinel, you can more comprehensively analyze security events across your organization and build playbooks for effective and immediate response.
186+
You can integrate Defender for Identity with Microsoft Sentinel as part of Microsoft's [unified security operations platform](/unified-secops-platform/) or a generic security information and event management (SIEM) service to enable centralized monitoring of alerts and activities from connected apps. With Microsoft Sentinel, you can more comprehensively analyze security events across your organization and build playbooks for effective and immediate response.
189187

190-
:::image type="content" source="./media/eval-defender-xdr/defender-identity-siem-integration.svg" alt-text="A diagram that shows the architecture for Microsoft Defender for Identity with SIEM integration." lightbox="./media/eval-defender-xdr/defender-identity-siem-integration.svg":::
188+
Microsoft Sentinel includes a Microsoft Defender for XDR data connector to bring all signals from Defender XDR, including Defender for Identity, to Microsoft Sentinel. Use the unified security operations platform in the Defender portal as a single platform for end-to-end security operations (SecOps).
191189

192-
Microsoft Sentinel includes a Defender for Identity connector. For more information, see [Microsoft Defender for Identity connector for Microsoft Sentinel](/azure/sentinel/data-connectors/microsoft-defender-for-identity).
190+
For more information, see:
193191

194-
For information about integration with third-party SIEM systems, see [Generic SIEM integration](/cloud-app-security/siem).
192+
- [Connect Microsoft Sentinel to the Microsoft Defender portal](/defender-xdr/microsoft-sentinel-onboard)
193+
- [Generic SIEM integration](/cloud-app-security/siem)
195194

196195
## Next step
197196

0 commit comments

Comments
 (0)