Skip to content

Commit e4694c7

Browse files
authored
Merge pull request #767 from MicrosoftDocs/GA-chrisda
GA updates
2 parents 5ff3fa1 + 7217d41 commit e4694c7

5 files changed

+15
-6
lines changed

defender-office-365/anti-malware-protection-for-spo-odfb-teams-about.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,10 +58,13 @@ For instructions, see [Use SharePoint Online PowerShell to prevent users from do
5858

5959
## Can admins bypass *DisallowInfectedFileDownload* and extract infected files?
6060

61-
SharePoint admins and global admins are allowed to do forensic file extractions of malware-infected files in SharePoint Online PowerShell with the [Get-SPOMalwareFileContent](/powershell/module/sharepoint-online/get-spomalwarefilecontent) cmdlet. Admins don't need access to the site that hosts the infected content. As long as the file is marked as malware, admins can use **Get-SPOMalwareFileContent** to extract the file.
61+
SharePoint admins and global admins<sup>\*</sup> are allowed to do forensic file extractions of malware-infected files in SharePoint Online PowerShell with the [Get-SPOMalwareFileContent](/powershell/module/sharepoint-online/get-spomalwarefilecontent) cmdlet. Admins don't need access to the site that hosts the infected content. As long as the file is marked as malware, admins can use **Get-SPOMalwareFileContent** to extract the file.
6262

6363
For more information about the infected file, admins can use the **[Get-SPOMalwareFile](/powershell/module/sharepoint-online/get-spomalwarefile)** cmdlet to see the type of malware that was detected and the status of the infection.
6464

65+
> [!IMPORTANT]
66+
> <sup>\*</sup> Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
67+
6568
## What happens when the OneDrive sync client tries to sync an infected file?
6669

6770
When a malicious file is uploaded to OneDrive, the file is synced to the local machine before being marked as malware. After the file is marked as malware, the user can't open the synced file from their local machine.

defender-office-365/mdo-usage-card-about.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ For members of **Billing Administrator** and **Global Administrator**<sup>\*</su
5555
These items aren't available for member of **Global Reader**, **Security Administrator**, **Security Operator**, or **Security Reader** roles.
5656

5757
> [!IMPORTANT]
58-
> <sup>\*</sup> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
58+
> <sup>\*</sup> Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
5959
6060
## Understand usage details
6161

@@ -80,7 +80,7 @@ The details flyout that opens contains the following information from the last 2
8080
**See licensing details** is available for members of the **Security Operator** and **Global Administrators**<sup>\*</sup> roles in [Microsoft Entra permissions](/entra/identity/role-based-access-control/manage-roles-portal).
8181

8282
> [!IMPORTANT]
83-
> <sup>\*</sup> Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
83+
> <sup>\*</sup> Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
8484
8585
## Frequently asked questions
8686

defender-office-365/siem-integration-with-office-365-ti.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ The following table summarizes the values of **AuditLogRecordType** that are rel
6060
> [!IMPORTANT]
6161
> You must have either the Global Administrator<sup>\*</sup> or Security Administrator role assigned to set up SIEM integration with Microsoft Defender for Office 365. For more information, see [Permissions in the Microsoft Defender portal](mdo-portal-permissions.md).
6262
>
63-
> <sup>\*</sup>Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
63+
> <sup>\*</sup>Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
6464
>
6565
> Audit logging must be turned on for your Microsoft 365 environment (it's on by default). To verify that audit logging is turned on or to turn it on, see [Turn auditing on or off](/purview/audit-log-enable-disable).
6666

defender-office-365/step-by-step-guides/deploy-and-configure-the-report-message-add-in.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,9 +33,12 @@ Depending on whether you're licensed for Defender for Office 365, you also get a
3333
## What you need
3434

3535
- Exchange Online Protection (some features require Defender for Office 365 Plan 2).
36-
- Sufficient permissions (Global admin for add-in deployment, security admin for customization).
36+
- Sufficient permissions (Global Administrator<sup>\*</sup> for add-in deployment, Security Administrator for customization).
3737
- 5-10 minutes to perform the steps in this article.
3838

39+
> [!IMPORTANT]
40+
> <sup>\*</sup> Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
41+
3942
## Deploy the add-in for users
4043

4144
1. **Login** to the Microsoft 365 admin center at <https://admin.microsoft.com>.

defender-office-365/step-by-step-guides/how-to-enable-dmarc-reporting-for-microsoft-online-email-routing-address-moera-and-parked-domains.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,9 +30,12 @@ This guide is designed to help you configure DMARC for domains not covered by th
3030
## What you need
3131

3232
- Microsoft 365 admin center and access to your DNS provider hosting your domains.
33-
- Sufficient permissions as Global Admin to make the appropriate changes in the Microsoft 365 admin center.
33+
- Sufficient permissions as a Global Administrator<sup>\*</sup> to make the appropriate changes in the Microsoft 365 admin center.
3434
- 10 minutes to complete the steps in this article.
3535

36+
> [!IMPORTANT]
37+
> <sup>\*</sup> Microsoft recommends that you use roles with the fewest permissions. Using lower permissioned accounts helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
38+
3639
## Activate DMARC for MOERA Domain
3740

3841
1. Open the Microsoft 365 admin center at <https://admin.microsoft.com>.

0 commit comments

Comments
 (0)