You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/configure-asset-rules.md
+16-7Lines changed: 16 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.collection:
12
12
- tier2
13
13
ms.topic: conceptual
14
14
search.appverid: met150
15
-
ms.date: 07/11/2023
15
+
ms.date: 09/04/2024
16
16
---
17
17
18
18
# Asset rule management - Dynamic rules for devices
@@ -37,24 +37,31 @@ Dynamic rules can help manage device context by assigning tags and device values
37
37
38
38
A rule can be based on device name, domain, OS platform, internet facing status, onboarding status and manual device tags. You can select or create a tag that will be applied based on the conditions you've set.
39
39
40
+
> [!IMPORTANT]
41
+
> Use of [dynamic device tagging](/defender-xdr/configure-asset-rules) capabilities in Defender for Endpoint to tag devices with `MDE-Management` isn't currently supported with security settings management. Devices tagged through this capability don't successfully enroll. This is currently under investigation.
42
+
40
43
The following steps guide you on how to create a new dynamic rule in Microsoft Defender XDR:
41
44
42
45
1. Sign in to the [Microsoft Defender portal](https://security.microsoft.com) as a user who can view and perform actions on all devices.
46
+
43
47
2. In the navigation pane, select **Settings**\>**Microsoft Defender XDR**\>**Asset Rule Management**.
48
+
44
49
3. Select **Create a new rule**.
50
+
45
51
4. Enter a **Rule name** and **Description***.
52
+
46
53
5. Select **Next** to choose the conditions you want to assign:
47
54
48
-
:::image type="content" source="/defender/media/defender/rule-conditions.png" alt-text="Screenshot of the Rule conditions page" lightbox="/defender/media/defender/rule-conditions.png":::
55
+
:::image type="content" source="/defender/media/defender/rule-conditions.png" alt-text="Screenshot of the Rule conditions page" lightbox="/defender/media/defender/rule-conditions.png":::
49
56
50
57
6. Select **Next** and choose the tag to apply to this rule.
51
58
52
-
:::image type="content" source="/defender/media/defender/actions-to-apply.png" alt-text="Screenshot of the actions page" lightbox="/defender/media/defender/actions-to-apply.png":::
59
+
:::image type="content" source="/defender/media/defender/actions-to-apply.png" alt-text="Screenshot of the actions page" lightbox="/defender/media/defender/actions-to-apply.png":::
53
60
54
61
7. Select **Next** to review and finish creating the rule and then select **Submit**.
55
62
56
-
>[!Note]
57
-
> It may take up to 1 hour for changes to be reflected in the portal.
63
+
>[!NOTE]
64
+
> It may take up to 1 hour for changes to be reflected in the portal.
58
65
59
66
### Dynamic tags in the Device Inventory
60
67
@@ -63,13 +70,15 @@ You can see the dynamic tags assigned in the Device Inventory view.
63
70
To see tags on individual devices:
64
71
65
72
1. Select **Devices** from the **Assets** navigation menu in the [Microsoft Defender portal](https://security.microsoft.com).
73
+
66
74
2. In the **Device Inventory** page, select the device name that you want to view.
75
+
67
76
3. Select **Manage tags**.
68
77
69
-
:::image type="content" source="/defender/media/defender/manage-machine-tags.png" alt-text="Screenshot of the machine tags page" lightbox="/defender/media/defender/manage-machine-tags.png":::
78
+
:::image type="content" source="/defender/media/defender/manage-machine-tags.png" alt-text="Screenshot of the machine tags page" lightbox="/defender/media/defender/manage-machine-tags.png":::
70
79
71
80
### Updating rules
72
81
73
-
Dynamic tags and device values set by dynamic rules can't be manually updated. To edit, delete or turn off a rule, in the **Asset Rule Management** page select the rule and choose the action you wish to take:
82
+
Dynamic tags and device values set by dynamic rules can't be manually updated. To edit, delete or turn off a rule, in the **Asset Rule Management** page select the rule and choose an action.
74
83
75
84
:::image type="content" source="/defender/media/defender/update-rule.png" alt-text="Screenshot of the rule details page" lightbox="/defender/media/defender/update-rule.png":::
> Ask Defender Experts is included in your Defender Experts for Hunting subscription with [monthly allocations](before-you-begin-defender-experts.md#eligibility-and-licensing). However, it's not a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
34
+
> Ask Defender Experts is included in your Defender Experts for Hunting subscription with [quarterly allocations](before-you-begin-defender-experts.md#eligibility-and-licensing). However, it's not a security incident response service. It's intended to provide a better understanding of complex threats affecting your organization. Engage with your own security incident response team to address urgent security incident response issues. If you don't have your own security incident response team and would like Microsoft's help, create a support request in the [Premier Services Hub](/services-hub/).
35
35
36
36
Select **Ask Defender Experts** directly inside the Microsoft 365 security portal to get swift and accurate responses to all your threat hunting questions. Experts can provide insight to better understand the complex threats your organization might face. Ask Defender Experts can help:
37
37
38
38
- Gather additional information on alerts and incidents, including root causes and scope
39
39
- Gain clarity into suspicious devices, alerts, or incidents and take next steps if faced with an advanced attacker
40
40
- Determine risks and available protections related to threat actors, campaigns, or emerging attacker techniques
41
41
42
-
### Required permissions for submitting inquiries in the Ask Defender Experts panel
42
+
:::image type="content" source="media/ask-defender-expert-dialog.png" alt-text="Screenshot of the Ask Defender Experts dialog box." lightbox="media/ask-defender-expert-dialog.png":::
43
43
44
-
You need to select one of the following permissions before submitting inquires to our Defender experts. For more details about role-based access control (RBAC) permissions, see: [Microsoft Defender for Endpoint and Microsoft Defender XDR RBAC permissions](compare-rbac-roles.md#map-defender-for-endpoint-and-defender-vulnerability-management-permissions-to-the-microsoft-defender-xdr-rbac-permissions).
44
+
### Required permissions for using Ask Defender Experts
45
45
46
-
|Product name|Product RBAC permission|
46
+
You need to select one of the following Microsoft Defender XDR Unified RBAC permissions before submitting inquiries to our Defender experts.
47
+
48
+
|Permission name|Level|
47
49
|---|---|---|
48
-
| Microsoft Defender for Endpoint RBAC | Manage security settings in the Security Center|
49
-
| Microsoft Defender XDR Unified RBAC | Authorization and settings \ Security settings \ Core security settings (manage)</br>Authorization and settings \ Security settings \ Detection tuning (manage) |
50
+
| Security data basics | Read|
51
+
| Alerts | Manage |
52
+
| Response | Manage |
53
+
54
+
To learn more about Unified RBAC permissions, see: [Microsoft Defender XDR Unified RBAC permission details](custom-permissions-details.md#microsoft-defender-xdr-unified-rbac-permission-details).
50
55
51
-
### Where to find Ask Defender Experts
56
+
### Where to submit inquiries to Ask Defender Experts
52
57
53
58
The option to **Ask Defender Experts** is available in several places throughout the portal:
54
59
@@ -68,6 +73,23 @@ The option to **Ask Defender Experts** is available in several places throughout
68
73
69
74
:::image type="content" source="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png" alt-text="Screenshot of the Ask Defender Experts menu option in the Incidents page actions menu in the Microsoft Defender portal.." lightbox="/defender/media/mte/defenderexperts/incidents-page-actions-menu.png":::
70
75
76
+
### Where to view responses from Defender Experts
77
+
78
+
#### In portal
79
+
80
+
You can view responses to inquiries submitted to Ask Defender Experts from up to six months ago by navigating to **Reports** > **Defender Experts messages**. You will also be able to ask follow-up questions or reply with more information to Defender Experts from this page.
81
+
82
+
:::image type="content" source="media/inportal-managed-response.png" alt-text="Screenshot of in-portal managed response." lightbox="media/inportal-managed-response.png":::
83
+
84
+
#### Email
85
+
86
+
If you included contact email addresses when submitting your inquiry, they will receive an email notification when a response from Defender Experts is posted.
87
+
88
+
:::image type="content" source="media/email-based-managed-response.png" alt-text="Screenshot of email based managed response." lightbox="media/email-based-managed-response.png":::
89
+
90
+
> [!NOTE]
91
+
> Defender Experts will not be able to assist you with inquiries regarding bugs or issues in your product experience in the Microsoft Defender XDR portal. You can reach out to Microsoft Support via the [Services Hub](https://serviceshub.microsoft.com/home) regarding such inquiries.
92
+
71
93
### Sample questions you can ask from Defender Experts
Copy file name to clipboardExpand all lines: defender-xdr/preview.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -62,7 +62,7 @@ Turn on preview features to be among the first to try new features. Your feedbac
62
62
63
63
In Microsoft Defender XDR, select **Settings > Microsoft Defender XDR > General > Preview features**, and select to turn on preview features.
64
64
65
-
(Preview) If you already have preview features turned on, and you're a Microsoft Defender for Business, Microsoft Defender for Endpoint, or Microsoft Defender for Cloud Apps customer, you can also select to turn preview features on and off for specific services only. For example:
65
+
If you already have preview features turned on, and you're a Microsoft Defender for Business, Microsoft Defender for Endpoint, or Microsoft Defender for Cloud Apps customer, you can also select to turn preview features on and off for specific services only. For example:
66
66
67
67
:::image type="content" source="media/preview-features-settings.png" alt-text="Screenshot of the preview features settings.":::
0 commit comments