Skip to content

Commit e46d64e

Browse files
Learn Build Service GitHub AppLearn Build Service GitHub App
authored andcommitted
Merging changes synced from https://github.com/MicrosoftDocs/defender-docs-pr (branch live)
2 parents af0534a + d3303c3 commit e46d64e

19 files changed

+335
-99
lines changed

.acrolinx-config.edn

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ If you need a scoring exception for content in this PR, add the *Sign off* and t
3535
- Escalate the exception request to the Acrolinx Review Team for review.
3636
- Approve the exception and work with the GitHub Admin Team to merge the PR to the default branch.
3737
38-
For more information about the exception criteria and exception process, see [Minimum Acrolinx topic scores for publishing](https://review.docs.microsoft.com/en-us/office-authoring-guide/acrolinx-min-score?branch=main).
38+
For more information about the exception criteria and exception process, see [Minimum Acrolinx topic scores for publishing](https://review.learn.microsoft.com/en-us/office-authoring-guide/acrolinx-min-score?branch=main).
3939
4040
Select the total score link to review all feedback on clarity, consistency, tone, brand, terms, spelling, grammar, readability, and inclusive language. _You should fix all spelling errors regardless of your total score_. Fixing spelling errors helps maintain customer trust in overall content quality.
4141
@@ -54,7 +54,7 @@ Select the total score link to review all feedback on clarity, consistency, tone
5454
- [Install Acrolinx locally for VSCode for Magic](https://review.learn.microsoft.com/office-authoring-guide/acrolinx-vscode?branch=main)
5555
- [False positives or issues](https://aka.ms/acrolinxbug)
5656
- [Request a new Acrolinx term](https://microsoft.sharepoint.com/teams/M365Dev2/SitePages/M365-terminology.aspx)
57-
- [Troubleshooting issues with Acrolinx](https://review.learn.microsoft.com/help/platform/acrolinx-troubleshoot?branch)
57+
- [Troubleshooting issues with Acrolinx](https://review.learn.microsoft.com/help/platform/acrolinx-troubleshoot?branch=main)
5858
5959
"
6060
}

CloudAppSecurityDocs/discovered-apps.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,7 +67,7 @@ You also might want to identify specific app instances that are in use by invest
6767
:::image type="content" source="media/discovered-apps/subdomains-image.png" alt-text="Subdomain filter.":::
6868

6969
> [!NOTE]
70-
> The feature of discovered subdomains will be deprecated by Sep 31st, 2025. Post this, no support for discovery subdomains will be provided.
70+
> The feature of discovered subdomains will be deprecated by Dec 31st, 2025. Post this, no support for discovery subdomains will be provided.
7171
>
7272
> Deep dives into discovered apps are supported only in firewalls and proxies that contain target URL data. For more information, see [Supported firewalls and proxies](set-up-cloud-discovery.md#supported-firewalls-and-proxies).
7373
>

defender-xdr/TOC.yml

Lines changed: 12 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -365,10 +365,14 @@
365365
href: access-den-graph-api.md
366366
- name: Ask Defender Experts
367367
href: experts-on-demand.md
368+
- name: Understand Defender Experts for Hunting reports
369+
href: defender-experts-report.md
368370
- name: Frequently asked questions
369-
href: faq-defender-experts-hunting.md
370-
- name: Understand Defender Experts for Hunting reports
371-
href: defender-experts-report.md
371+
items:
372+
- name: General information
373+
href: faq-defender-experts-hunting.md
374+
- name: Server and cloud workload coverage
375+
href: faq-cloud-coverage-defender-experts.md
372376
- name: Collaborate with Microsoft Defender Experts for XDR
373377
items:
374378
- name: Overview
@@ -383,10 +387,12 @@
383387
href: managed-detection-and-response-xdr.md
384388
- name: Scoped coverage
385389
href: defender-experts-scoped-coverage.md
386-
- name: Communicate with Defender Experts for XDR
390+
- name: Communicate with Defender Experts
387391
href: communicate-defender-experts-xdr.md
388392
- name: Reports
389393
href: reports-xdr.md
394+
- name: Third-party enrichment
395+
href: third-party-enrichment-defender-experts.md
390396
- name: Defender Experts for Hunting
391397
href: defender-experts-for-hunting.md
392398
- name: Auditing
@@ -399,6 +405,8 @@
399405
href: faq-incident-notifications-xdr.md
400406
- name: Managed response
401407
href: faq-managed-response.md
408+
- name: Server and cloud workload coverage
409+
href: faq-cloud-coverage-defender-experts.md
402410
- name: Additional information on Defender Experts for XDR
403411
items:
404412
- name: Important considerations

defender-xdr/auditing.md

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
---
22
title: How to search the audit logs for actions performed by Defender Experts
33
ms.reviewer:
4-
description: As a tenant administrator, you can use Microsoft Purview to search the audit logs for the actions Microsoft Defender Experts did in your tenant to perform their investigations
4+
description: As a tenant administrator, you can use Microsoft Purview to search the audit logs for the actions Microsoft Defender Experts did in your tenant to perform their investigations.
55
ms.service: defender-experts-for-xdr
6-
ms.author: vpattnaik
7-
author: vpattnai
6+
ms.author: pauloliveria
7+
author: poliveria
88
ms.localizationpriority: medium
9-
manager: dansimp
9+
manager: orspodek
1010
audience: ITPro
1111
ms.collection:
1212
- m365-security
@@ -17,14 +17,15 @@ ms.custom:
1717
- cx-ti
1818
- cx-dex
1919
search.appverid: met150
20-
ms.date: 01/14/2025
20+
ms.date: 08/01/2025
2121
---
2222

2323
# Auditing
2424

2525
**Applies to:**
2626

27-
- [Microsoft Defender XDR](microsoft-365-defender.md)
27+
- [Microsoft Defender Experts for XDR](dex-xdr-overview.md)
28+
- Microsoft Defender Experts for Servers
2829

2930
As a tenant administrator, you can use Microsoft Purview to search the audit logs for the times Microsoft Defender Experts signed into your tenant and the actions they did there to perform their investigations. You can also search the audit logs for the changes done by your tenant administrators to the Defender Experts settings.
3031

defender-xdr/before-you-begin-defender-experts.md

Lines changed: 28 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,10 @@ title: Before you begin using the Microsoft Defender Experts for Hunting service
33
ms.reviewer:
44
description: To enable us to get started with the defender experts managed service, we require the following prerequisites
55
ms.service: defender-experts-for-hunting
6-
ms.author: vpattnaik
7-
author: vpattnai
6+
ms.author: pauloliveria
7+
author: poliveria
88
ms.localizationpriority: medium
9-
manager: dansimp
9+
manager: orspodek
1010
audience: ITPro
1111
ms.collection:
1212
- m365-security
@@ -18,7 +18,7 @@ ms.custom:
1818
- cx-ti
1919
- cx-ean
2020
search.appverid: met150
21-
ms.date: 04/24/2025
21+
ms.date: 08/01/2025
2222
---
2323

2424
# Before you begin using Defender Experts for Hunting
@@ -28,7 +28,6 @@ ms.date: 04/24/2025
2828
**Applies to:**
2929

3030
- [Microsoft Defender XDR](microsoft-365-defender.md)
31-
- [Microsoft Defender Experts for XDR](dex-xdr-overview.md)
3231

3332
[Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md) is a managed service that provides hunting capabilities for novel emerging threats that aren't yet well known in the industry. The analysts for the hunting service review trends in the threat actor evolution based on world-renowned Microsoft Threat Intelligence and Research. They then apply the insights they gather to hunt for emerging attack vectors within the customer ecosystem.
3433

@@ -38,12 +37,14 @@ With deep product expertise powered by threat intelligence, we're uniquely posit
3837
1. Get detailed, step-by-step, and actionable guidance from our experts so you can respond to these emerging threats.
3938
1. [Seek assistance](#ask-defender-experts) from Defender Experts.
4039

41-
This document outlines the key infrastructure requirements you must meet and important information on data access and compliance you must know before purchasing the Microsoft Defender Experts for Hunting service. Microsoft understands that customers who use our managed services entrust us with their most valued asset, their data.
40+
This document outlines the key infrastructure requirements you must meet and important information on data access and compliance you must know before purchasing the **Microsoft Defender Experts for Hunting - XDR** service and its add-on, **Microsoft Defender Experts for Hunting - Servers**. Microsoft understands that customers who use our managed services entrust us with their most valued asset, their data.
4241

4342
## Eligibility and licensing
4443

4544
Defender Experts for Hunting is a separate service from your existing Microsoft Defender products. Before enrolling in this service, make sure that you have the necessary license and access.
4645

46+
**Microsoft Defender Experts for Hunting – XDR**
47+
4748
We require the following licensing prerequisites to enable us to get started with this threat hunting service:
4849

4950
- Microsoft Defender for Endpoint P2 must be licensed and enabled on eligible devices
@@ -60,20 +61,33 @@ The following product is **not** covered by this service:
6061
- Microsoft Defender for IoT
6162
- Other Microsoft services not mentioned in the previous lists
6263

64+
**Microsoft Defender Experts for Hunting - Servers**
65+
66+
Customers who wish to have Defender Experts hunting coverage for Microsoft Defender for Cloud servers must have the following:
67+
68+
- Defender Experts for Hunting - XDR service enrollment
69+
- Defender for Servers Plan 1 or Plan 2 in Microsoft Defender for Cloud
70+
6371
> [!NOTE]
64-
> Licensing for Microsoft Defender Experts for Hunting is applied at the tenant level and all identities and devices will be included in your license.
72+
> Defender Experts for Hunting coverage is applied at the tenant level and all identities and devices will be included.
6573
6674
### Defender Experts for Hunting coverage
6775

68-
Defender Experts for Hunting relies on event signals from Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Identity. It also relies on proprietary Microsoft Threat Intelligence sources.
76+
**Microsoft Defender Experts for Hunting – XDR**
77+
78+
Defender Experts for Hunting - XDR relies on event signals from Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Identity. It also relies on proprietary Microsoft Threat Intelligence sources.
6979

70-
This service also covers servers—whether on premises or on a hyperscale cloud service provider—that have Defender for Endpoint deployed on them with a Microsoft Defender for Endpoint for Servers license.
80+
This service also covers servers that have Defender for Endpoint deployed on them with a **Microsoft Defender for Endpoint for Servers** license.
7181

7282
Any detection that's not from Microsoft Defender products (for example, detections from other security vendors) isn't within the scope of Defender Experts for Hunting.
7383

84+
**Microsoft Defender Experts for Hunting - Servers**
85+
86+
Defender Experts for Hunting – Servers provides add-on server coverage, including hybrid and multicloud servers from Defender for Servers.
87+
7488
### Ask Defender Experts
7589

76-
[Ask Defender Experts](experts-on-demand.md) is intended to provide a better understanding of complex threats affecting your organization. It focuses on products included in Microsoft Defender XDR (Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, and Defender for Identity). [See sample questions you can ask Defender Experts](experts-on-demand.md#sample-questions-you-can-ask-from-defender-experts).
90+
[Ask Defender Experts](experts-on-demand.md) is intended to provide a better understanding of complex threats affecting your organization. It focuses on products included in Microsoft Defender Experts services. [See sample questions you can ask Defender Experts](experts-on-demand.md#sample-questions-you-can-ask-from-defender-experts).
7791

7892
Defender Experts for Hunting customers are assigned 10 Ask Defender Experts credits, which you can use to submit questions, at the start of each calendar quarter. Unused credits from the current quarter roll up to the next one. You can use up to 20 credits only per quarter. All unused credits expire by the end of the calendar year or at the end of your subscription term, whichever comes first.
7993

@@ -87,7 +101,7 @@ You might need certain roles and permissions to fully access the service capabil
87101

88102
## Service availability and data protection
89103

90-
Defender Experts for Hunting is a managed threat hunting service that proactively hunts for threats across endpoints, email, identity, and cloud apps. To carry out hunting on your behalf, Microsoft experts need access to your Microsoft Defender XDR advanced hunting data. Enrolling in this service means you're granting permission to Microsoft experts to access the said data.
104+
Defender Experts for Hunting - XDR and Defender Experts for Hunting - Servers are managed threat hunting services that proactively hunts for threats across endpoints, email, identity, cloud apps, and servers. To carry out hunting on your behalf, Microsoft experts need access to your Microsoft Defender XDR advanced hunting data. Enrolling in this service means you're granting permission to Microsoft experts to access the said data.
91105

92106
The following sections enumerate additional information about the service's data usage, compliance, and availability. For more information about Microsoft's commitment in valuing and protecting your data, visit the [Trust Center](https://www.microsoft.com/trust-center/product-overview) then scroll down to **Additional products and services** > **Managed Security Services** > **Microsoft Defender Experts**.
93107

@@ -99,6 +113,9 @@ Defender Experts for Hunting operational data, such as case tickets and analyst
99113

100114
Microsoft experts hunt over [advanced hunting logs](advanced-hunting-schema-tables.md) in Microsoft Defender XDR advanced hunting tables. The data in these tables depend on the set of Defender services the customer is enabled for (for example, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID). Experts also use a large set of internal threat intelligence data to inform their hunting and automation.
101115

116+
> [!NOTE]
117+
> Microsoft Defender for Cloud is integrated with Microsoft Defender XDR. This integration allows security teams to access Defender for Cloud alerts and incidents within the Microsoft Defender portal. The Defender Experts for Hunting - Servers add-on service accesses data through the Defender portal, so the same data collection, usage, and retention policies apply to this service.
118+
102119
### Security and compliance
103120

104121
When you purchase and onboard to Defender Experts for Hunting, you're granting permission to Microsoft experts to access your advanced hunting data.

0 commit comments

Comments
 (0)