You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There are multiple fixes and new changes in this release.
51
+
52
+
- Fixes bug in which infected command-line threat information was not showing correctly in security portal.
53
+
- Fixes a memory leak issue in kernel space due to ebpf maps and progs not getting closed/unloaded whenever ebpf sensor is reloaded. Impacts kernels 3.10x and <= 4.16x.
54
+
- Fixes a bug where disabling a preview feature required a Defender of Endpoint to disable it.
55
+
- Global Exclusions feature using managed JSON is now in Public Preview. available in insiders slow from 101.23092.0012. For more information, see [linux-exclusions](linux-exclusions.md).
56
+
- Updated the Linux default engine version to 1.1.24050.7 and default sigs Version to 1.411.410.0.
Copy file name to clipboardExpand all lines: defender-xdr/api-incident.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -18,7 +18,7 @@ search.appverid:
18
18
- MOE150
19
19
- MET150
20
20
ms.custom: api
21
-
ms.date: 02/08/2024
21
+
ms.date: 07/30/2024
22
22
---
23
23
24
24
# Microsoft Defender XDR incidents API and the incidents resource type
@@ -73,7 +73,7 @@ Refer to the respective method articles for more details on how to construct a r
73
73
| status | Enum | Specifies the current status of the incident. Possible values are: `Active`, `InProgress`, `Resolved`, and `Redirected`. |
74
74
| classification | Enum | Specification of the incident. Possible values are: `TruePositive`, `Informational, expected activity`, and `FalsePositive`. |
75
75
| determination | Enum | Specifies the determination of the incident. <p>Possible determination values for each classification are: <br><li> <b>True positive</b>: `Multistage attack` (MultiStagedAttack), `Malicious user activity` (MaliciousUserActivity), `Compromised account` (CompromisedUser) – consider changing the enum name in public api accordingly, `Malware` (Malware), `Phishing` (Phishing), `Unwanted software` (UnwantedSoftware), and `Other` (Other). <li> <b>Informational, expected activity:</b> `Security test` (SecurityTesting), `Line-of-business application` (LineOfBusinessApplication), `Confirmed activity` (ConfirmedUserActivity) - consider changing the enum name in public api accordingly, and `Other` (Other). <li> <b>False positive:</b> `Not malicious` (Clean) - consider changing the enum name in public api accordingly, `Not enough data to validate` (InsufficientData), and `Other` (Other). |
76
-
| tags | string list | List of Incident tags. |
76
+
| tags | string list | List of Incident tags (customTags only). |
77
77
| comments | List of incident comments | Incident Comment object contains: comment string, createdBy string, and createTime date time. |
78
78
| alerts | alert list | List of related alerts. See examples at [List incidents](api-list-incidents.md) API documentation. |
-[Microsoft Defender for Cloud Apps](/defender-cloud-apps/)
31
31
32
-
Microsoft Defender for Cloud Apps is part of Microsoft Defender XDR, and uses the Microsoft Defender portal to allow security admins to perform their security tasks in one location. The Microsoft Defender portal simplifies workflows and combines functionality from other Microsoft Defender XDR services to Defender for Cloud Apps.
32
+
Microsoft Defender for Cloud Apps is available inside the Microsoft Defender portal. The Defender portal is the home for monitoring and managing security across your Microsoft identities, data, devices, apps, and infrastructure, allowing security admins to perform their security tasks in one location, across multiple Microsoft Defender services.
33
33
34
-
The Microsoft Defender portal is the home for monitoring and managing security across your Microsoft identities, data, devices, apps, and infrastructure. SOC analysts can triage, investigate, and hunt across all Microsoft Defender XDR workloads, including cloud apps. For example, Defender for Cloud Apps alerts appear in Microsoft Defender XDR's incidents queue and alerts queue, with relevant content inside the alert pages, in a unified format with the proper adaptations to each alerts type.
35
-
36
-
All users accessing the classic Microsoft Defender for Cloud Apps portal are automatically rerouted to the Microsoft Defender portal, with no option to opt out. This article is intended for customers moving from the classic Defender for Cloud Apps portal and want to learn more about where to find Defender for Cloud Apps content in the Microsoft Defender portal.
34
+
SOC analysts can triage, investigate, and hunt across all Microsoft Defender XDR workloads, including cloud apps.
37
35
38
36
Take a look in Microsoft Defender XDR at <https://security.microsoft.com>.
39
37
40
38
Learn more about the benefits: [Overview of Microsoft Defender XDR](microsoft-365-defender.md).
41
39
42
-
## Quick reference
43
-
44
-
The images and the tables below list the changes in navigation between Microsoft Defender for Cloud Apps and Microsoft Defender XDR.
45
-
46
-
### Discover
47
-
48
-
> [!div class="mx-imgBorder"]
49
-
> :::image type="content" source="/defender/media/defender-cloud-apps-m365-defender-discover.png" alt-text="The new locations for Cloud Discovery features in the Microsoft Defender portal" lightbox="/defender/media/defender-cloud-apps-m365-defender-discover.png":::
50
-
51
-
| Defender for Cloud Apps | Microsoft Defender XDR |
| Create Cloud Discovery snapshot report | On the Cloud Discovery page, under Actions |
61
-
62
-
### Investigate
63
-
64
-
> [!div class="mx-imgBorder"]
65
-
> :::image type="content" source="/defender/media/defender-cloud-apps-m365-defender-investigate.png" alt-text="The new locations for Investigation features in the Microsoft Defender portal" lightbox="/defender/media/defender-cloud-apps-m365-defender-investigate.png":::
66
-
67
-
| Defender for Cloud Apps | Microsoft Defender XDR |
68
-
|---------|---------|
69
-
| Activity log | Cloud apps -> Activity log |
70
-
| Files | Cloud apps -> Files |
71
-
| Users and accounts | Assets -> Identities |
72
-
| Security configuration | available in [Microsoft Defender for Cloud](/azure/defender-for-cloud/defender-for-cloud-introduction)|
> :::image type="content" source="/defender/media/defender-cloud-apps-m365-defender-control.png" alt-text="The new locations for Control features in the Microsoft Defender portal" lightbox="/defender/media/defender-cloud-apps-m365-defender-control.png":::
81
-
82
-
| Defender for Cloud Apps | Microsoft Defender XDR |
83
-
|---------|---------|
84
-
| Policies | Cloud apps -> Policy management. Note: Microsoft Entra ID Protection policies will be removed gradually from the Cloud apps policies list. To configure alerts from these policies, see [Configure Microsoft Entra IP alert service](investigate-alerts.md#configure-aad-ip-alert-service)|
85
-
| Templates | Cloud apps -> Policy templates |
86
-
87
-
### Settings
88
-
89
-
> [!div class="mx-imgBorder"]
90
-
> :::image type="content" source="/defender/media/defender-cloud-apps-m365-defender-settings.png" alt-text="The new locations for Settings in the Microsoft Defender portal" lightbox="/defender/media/defender-cloud-apps-m365-defender-settings.png":::
91
-
92
-
| Defender for Cloud Apps | Microsoft Defender XDR |
| Conditional Access App Control | Settings -> Cloud apps -> Connected apps -> Conditional Access App Control apps |
106
-
| IP address ranges | Settings -> Cloud apps |
107
-
| User groups | Settings -> Cloud apps |
108
-
109
-
The capabilities on the following pages are fully integrated into Microsoft Defender XDR, and therefore don't have their own standalone experience in Microsoft Defender XDR:
110
-
111
-
-[Settings > Microsoft Entra ID Protection](investigate-alerts.md)
-[Settings > Microsoft Defender for Identity](/defender-for-identity/deploy-defender-identity)
114
-
115
-
## What's changed
116
-
117
-
Learn about the changes that have come with the integration of Defender for Cloud Apps and Microsoft Defender XDR.
118
-
119
-
### Global search
40
+
## Perform cloud app security tasks
41
+
42
+
Find Defender for Cloud Apps functionality in the Microsoft Defender portal under **Cloud Apps**. For example:
43
+
44
+
:::image type="content" source="media/defender-for-cloud-apps/cloud-apps.png" alt-text="Screenshot that shows the Defender for Cloud Apps Cloud discovery page." lightbox="media/defender-for-cloud-apps/cloud-apps.png":::
45
+
46
+
## Investigate cloud app alerts
47
+
48
+
Defender for Cloud Apps alerts show in the Defender portal's incident and alerts queues, with relevant content inside alert pages for each type of an alert. For more information, see [Investigate incidents in Microsoft Defender XDR](investigate-incidents.md).
49
+
50
+
## Global search for your connected cloud apps
120
51
121
52
Use the Microsoft Defender portal's global search bar at the top of the page to search for connected apps in Defender for Cloud Apps.
122
53
123
-
:::image type="content" source="/defender/media/global-search-apps.png" alt-text="Search for connected apps.":::
54
+
:::image type="content" source="/defender/media/global-search-apps.png" alt-text="Screenshot that shows searching for connected apps." lightbox="/defender/media/global-search-apps.png":::
55
+
56
+
## Assets and identities
124
57
125
-
### Assets and identities
58
+
Use the **Assets > Identities** page to find comprehensive details about entities pulled from connected cloud applications, including a users's activity history and security alerts related to the user. For example:
126
59
127
-
As part of the creation of a dedicated **Assets** section that spans the entire Microsoft Defender XDR experience, the **Users and Accounts** section of Defender for Cloud Apps is rebranded as the **Identities** section. No changes to functionality are expected.
60
+
:::image type="content" source="media/defender-for-cloud-apps/dashboard-top-users.png" alt-text="Screenshot that shows cloud app entities in the Identities page." lightbox="media/defender-for-cloud-apps/dashboard-top-users.png":::
0 commit comments