Skip to content

Commit d709f1a

Browse files
committed
Merge branch 'main' into maccruz-contextpane
2 parents e89c960 + 36b0035 commit d709f1a

File tree

6 files changed

+47
-16
lines changed

6 files changed

+47
-16
lines changed

defender-xdr/configure-asset-rules.md

Lines changed: 16 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.collection:
1212
- tier2
1313
ms.topic: conceptual
1414
search.appverid: met150
15-
ms.date: 07/11/2023
15+
ms.date: 09/04/2024
1616
---
1717

1818
# Asset rule management - Dynamic rules for devices
@@ -37,24 +37,31 @@ Dynamic rules can help manage device context by assigning tags and device values
3737

3838
A rule can be based on device name, domain, OS platform, internet facing status, onboarding status and manual device tags. You can select or create a tag that will be applied based on the conditions you've set.
3939

40+
> [!IMPORTANT]
41+
> Use of [dynamic device tagging](/defender-xdr/configure-asset-rules) capabilities in Defender for Endpoint to tag devices with `MDE-Management` isn't currently supported with security settings management. Devices tagged through this capability don't successfully enroll. This is currently under investigation.
42+
4043
The following steps guide you on how to create a new dynamic rule in Microsoft Defender XDR:
4144

4245
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) as a user who can view and perform actions on all devices.
46+
4347
2. In the navigation pane, select **Settings** \> **Microsoft Defender XDR** \> **Asset Rule Management**.
48+
4449
3. Select **Create a new rule**.
50+
4551
4. Enter a **Rule name** and **Description***.
52+
4653
5. Select **Next** to choose the conditions you want to assign:
4754

48-
:::image type="content" source="/defender/media/defender/rule-conditions.png" alt-text="Screenshot of the Rule conditions page" lightbox="/defender/media/defender/rule-conditions.png":::
55+
:::image type="content" source="/defender/media/defender/rule-conditions.png" alt-text="Screenshot of the Rule conditions page" lightbox="/defender/media/defender/rule-conditions.png":::
4956

5057
6. Select **Next** and choose the tag to apply to this rule.
5158

52-
:::image type="content" source="/defender/media/defender/actions-to-apply.png" alt-text="Screenshot of the actions page" lightbox="/defender/media/defender/actions-to-apply.png":::
59+
:::image type="content" source="/defender/media/defender/actions-to-apply.png" alt-text="Screenshot of the actions page" lightbox="/defender/media/defender/actions-to-apply.png":::
5360

5461
7. Select **Next** to review and finish creating the rule and then select **Submit**.
5562

56-
>[!Note]
57-
> It may take up to 1 hour for changes to be reflected in the portal.
63+
>[!NOTE]
64+
> It may take up to 1 hour for changes to be reflected in the portal.
5865
5966
### Dynamic tags in the Device Inventory
6067

@@ -63,13 +70,15 @@ You can see the dynamic tags assigned in the Device Inventory view.
6370
To see tags on individual devices:
6471

6572
1. Select **Devices** from the **Assets** navigation menu in the [Microsoft Defender portal](https://security.microsoft.com).
73+
6674
2. In the **Device Inventory** page, select the device name that you want to view.
75+
6776
3. Select **Manage tags**.
6877

69-
:::image type="content" source="/defender/media/defender/manage-machine-tags.png" alt-text="Screenshot of the machine tags page" lightbox="/defender/media/defender/manage-machine-tags.png":::
78+
:::image type="content" source="/defender/media/defender/manage-machine-tags.png" alt-text="Screenshot of the machine tags page" lightbox="/defender/media/defender/manage-machine-tags.png":::
7079

7180
### Updating rules
7281

73-
Dynamic tags and device values set by dynamic rules can't be manually updated. To edit, delete or turn off a rule, in the **Asset Rule Management** page select the rule and choose the action you wish to take:
82+
Dynamic tags and device values set by dynamic rules can't be manually updated. To edit, delete or turn off a rule, in the **Asset Rule Management** page select the rule and choose an action.
7483

7584
:::image type="content" source="/defender/media/defender/update-rule.png" alt-text="Screenshot of the rule details page" lightbox="/defender/media/defender/update-rule.png":::

defender-xdr/experts-on-demand.md

Lines changed: 30 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ ms.collection:
1919
- essentials-get-started
2020
ms.topic: conceptual
2121
search.appverid: met150
22-
ms.date: 08/14/2024
22+
ms.date: 09/05/2024
2323
---
2424

2525
# Collaborate with experts on demand
@@ -31,24 +31,29 @@ ms.date: 08/14/2024
3131
- [Microsoft Defender XDR](microsoft-365-defender.md)
3232

3333
> [!NOTE]
34-
> Ask Defender Experts is included in your Defender Experts for Hunting subscription with [monthly allocations](before-you-begin-defender-experts.md#eligibility-and-licensing). However, it's not a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
34+
> Ask Defender Experts is included in your Defender Experts for Hunting subscription with [quarterly allocations](before-you-begin-defender-experts.md#eligibility-and-licensing). However, it's not a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
3535
3636
Select **Ask Defender Experts** directly inside the Microsoft 365 security portal to get swift and accurate responses to all your threat hunting questions. Experts can provide insight to better understand the complex threats your organization might face. Ask Defender Experts can help:
3737

3838
- Gather additional information on alerts and incidents, including root causes and scope
3939
- Gain clarity into suspicious devices, alerts, or incidents and take next steps if faced with an advanced attacker
4040
- Determine risks and available protections related to threat actors, campaigns, or emerging attacker techniques
4141

42-
### Required permissions for submitting inquiries in the Ask Defender Experts panel
42+
:::image type="content" source="media/ask-defender-expert-dialog.png" alt-text="Screenshot of the Ask Defender Experts dialog box." lightbox="media/ask-defender-expert-dialog.png":::
4343

44-
You need to select one of the following permissions before submitting inquires to our Defender experts. For more details about role-based access control (RBAC) permissions, see: [Microsoft Defender for Endpoint and Microsoft Defender XDR RBAC permissions](compare-rbac-roles.md#map-defender-for-endpoint-and-defender-vulnerability-management-permissions-to-the-microsoft-defender-xdr-rbac-permissions).
44+
### Required permissions for using Ask Defender Experts
4545

46-
|Product name|Product RBAC permission|
46+
You need to select one of the following Microsoft Defender XDR Unified RBAC permissions before submitting inquiries to our Defender experts.
47+
48+
|Permission name|Level|
4749
|---|---|---|
48-
| Microsoft Defender for Endpoint RBAC | Manage security settings in the Security Center|
49-
| Microsoft Defender XDR Unified RBAC | Authorization and settings \ Security settings \ Core security settings (manage)</br>Authorization and settings \ Security settings \ Detection tuning (manage) |
50+
| Security data basics | Read|
51+
| Alerts | Manage |
52+
| Response | Manage |
53+
54+
To learn more about Unified RBAC permissions, see: [Microsoft Defender XDR Unified RBAC permission details](custom-permissions-details.md#microsoft-defender-xdr-unified-rbac-permission-details).
5055

51-
### Where to find Ask Defender Experts
56+
### Where to submit inquiries to Ask Defender Experts
5257

5358
The option to **Ask Defender Experts** is available in several places throughout the portal:
5459

@@ -68,6 +73,23 @@ The option to **Ask Defender Experts** is available in several places throughout
6873

6974
:::image type="content" source="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png" alt-text="Screenshot of the Ask Defender Experts menu option in the Incidents page actions menu in the Microsoft Defender portal.." lightbox="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png":::
7075

76+
### Where to view responses from Defender Experts
77+
78+
#### In portal
79+
80+
You can view responses to inquiries submitted to Ask Defender Experts from up to six months ago by navigating to **Reports** > **Defender Experts messages**. You will also be able to ask follow-up questions or reply with more information to Defender Experts from this page.
81+
82+
:::image type="content" source="media/inportal-managed-response.png" alt-text="Screenshot of in-portal managed response." lightbox="media/inportal-managed-response.png":::
83+
84+
#### Email
85+
86+
If you included contact email addresses when submitting your inquiry, they will receive an email notification when a response from Defender Experts is posted.
87+
88+
:::image type="content" source="media/email-based-managed-response.png" alt-text="Screenshot of email based managed response." lightbox="media/email-based-managed-response.png":::
89+
90+
> [!NOTE]
91+
> Defender Experts will not be able to assist you with inquiries regarding bugs or issues in your product experience in the Microsoft Defender XDR portal. You can reach out to Microsoft Support via the [Services Hub](https://serviceshub.microsoft.com/home) regarding such inquiries.
92+
7193
### Sample questions you can ask from Defender Experts
7294

7395
#### Alert information
574 KB
Loading
40.4 KB
Loading
377 KB
Loading

defender-xdr/preview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ Turn on preview features to be among the first to try new features. Your feedbac
6262

6363
In Microsoft Defender XDR, select **Settings > Microsoft Defender XDR > General > Preview features**, and select to turn on preview features.
6464

65-
(Preview) If you already have preview features turned on, and you're a Microsoft Defender for Business, Microsoft Defender for Endpoint, or Microsoft Defender for Cloud Apps customer, you can also select to turn preview features on and off for specific services only. For example:
65+
If you already have preview features turned on, and you're a Microsoft Defender for Business, Microsoft Defender for Endpoint, or Microsoft Defender for Cloud Apps customer, you can also select to turn preview features on and off for specific services only. For example:
6666

6767
:::image type="content" source="media/preview-features-settings.png" alt-text="Screenshot of the preview features settings.":::
6868

0 commit comments

Comments
 (0)