Skip to content

Commit ed66315

Browse files
authored
Merge branch 'main' into docs-editor/indicator-certificates-1722278144
2 parents d0f7e1b + 4f62f9c commit ed66315

File tree

8 files changed

+81
-97
lines changed

8 files changed

+81
-97
lines changed

defender-endpoint/controlled-folders.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Protect important folders from ransomware from encrypting your files with
33
description: Files in default folders can be protected from being changed by malicious apps. Prevent ransomware from encrypting your files.
44
ms.service: defender-endpoint
55
ms.localizationpriority: medium
6-
ms.date: 03/05/2024
6+
ms.date: 07/30/2024
77
author: siosulli
88
ms.author: siosulli
99
audience: ITPro
@@ -112,7 +112,7 @@ You can query Microsoft Defender for Endpoint data by using [Advanced hunting](/
112112

113113
Example query:
114114

115-
```PowerShell
115+
```
116116
DeviceEvents
117117
| where ActionType in ('ControlledFolderAccessViolationAudited','ControlledFolderAccessViolationBlocked')
118118
```

defender-endpoint/linux-whatsnew.md

Lines changed: 28 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,33 @@ This article is updated frequently to let you know what's new in the latest rele
3232

3333
- [What's new in Defender for Endpoint on macOS](mac-whatsnew.md)
3434
- [What's new in Defender for Endpoint on iOS](ios-whatsnew.md)
35+
36+
<details>
37+
<summary> July-2024 (Build: 101.24062.0001 | Release version: 30.124062.0001.0)</summary>
38+
39+
## July-2024 Build: 101.24062.0001 | Release version: 30.124062.0001.0
40+
41+
&ensp;Released: **July 31, 2024**<br/>
42+
&ensp;Published: **July 31, 2024**<br/>
43+
&ensp;Build: **101.24062.0001**<br/>
44+
&ensp;Release version: **30.124062.0001.0**<br/>
45+
&ensp;Engine version: **1.1.24050.7**<br/>
46+
&ensp;Signature version: **1.411.410.0**<br/>
47+
48+
**What's new**
49+
50+
There are multiple fixes and new changes in this release.
51+
52+
- Fixes bug in which infected command-line threat information was not showing correctly in security portal.
53+
- Fixes a memory leak issue in kernel space due to ebpf maps and progs not getting closed/unloaded whenever ebpf sensor is reloaded. Impacts kernels 3.10x and <= 4.16x.
54+
- Fixes a bug where disabling a preview feature required a Defender of Endpoint to disable it.
55+
- Global Exclusions feature using managed JSON is now in Public Preview. available in insiders slow from 101.23092.0012. For more information, see [linux-exclusions](linux-exclusions.md).
56+
- Updated the Linux default engine version to 1.1.24050.7 and default sigs Version to 1.411.410.0.
57+
- Stability and performance improvements.
58+
- Other bug fixes.
59+
60+
</details>
61+
3562
<details>
3663
<summary> June-2024 (Build: 101.24052.0002 | Release version: 30.24052.0002.0)</summary>
3764

@@ -1430,4 +1457,4 @@ As an alternative approach, follow the instructions to [uninstall](linux-resourc
14301457

14311458
</details>
14321459

1433-
</details><!--This </details> closes "2021 releases"-->
1460+
</details><!--This </details> closes "2021 releases"-->

defender-vulnerability-management/fixed-reported-inaccuracies.md

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,16 @@ The following tables present the relevant vulnerability information organized by
3737
| Inaccuracy report ID | Description | Fix date |
3838
|---|---|---|
3939
| - | Fixed inaccuracy in Microsoft Visio Viewer & SDK 2016 | 01-July-24 |
40+
| 61778 | Fixed inaccuracy in PHP vulnerabilities - CVE-2024-4577, CVE-2024-5458 & CVE-2024-5585 | 05-July-24 |
41+
| - | Fixed inaccuracy in Intel Proset Wireless vulnerabilities - CVE-2023-38417, CVE-2023-38654, CVE-2023-40536 & CVE-2023-47210 | 07-July-24 |
42+
| 58642 | Fixed inaccuracy in Microsoft Visual Studio Code & Progress Fiddler | 10-July-24 |
43+
| 61803 | Fixed inaccuracy in CVE-2023-24592 | 10-July-24 |
44+
| - | Fixed inaccuracy in CVE-2017-3010 & CVE-2017-3124 | 10-July-24 |
45+
| - | Fixed inaccuracy in 7-zip and Zscaler vulnerabilities - CVE-2023-31102, CVE-2023-41972, CVE-2023-41973 & CVE-2023-23463 | 10-July-24 |
46+
| 62958 | Fixed inaccuracy in CVE-2024-26010 | 10-July-24 |
47+
| - | Defender Vulnerability Management doesn't currently support CVE-2013-5387 and CVE-2018-1595 | 14-July-24 |
48+
| 60387 | Fixed inaccuracy in Microsoft Teams by excluding squirrel.exe path | 14-July-24 |
49+
| 61125 | Fixed inaccuracy in Lenovo Mouse Suite | 17-July-24 |
4050

4151

4252
## June 2024

defender-xdr/api-incident.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ search.appverid:
1818
- MOE150
1919
- MET150
2020
ms.custom: api
21-
ms.date: 02/08/2024
21+
ms.date: 07/30/2024
2222
---
2323

2424
# Microsoft Defender XDR incidents API and the incidents resource type
@@ -73,7 +73,7 @@ Refer to the respective method articles for more details on how to construct a r
7373
| status | Enum | Specifies the current status of the incident. Possible values are: `Active`, `InProgress`, `Resolved`, and `Redirected`. |
7474
| classification | Enum | Specification of the incident. Possible values are: `TruePositive`, `Informational, expected activity`, and `FalsePositive`. |
7575
| determination | Enum | Specifies the determination of the incident. <p>Possible determination values for each classification are: <br><li> <b>True positive</b>: `Multistage attack` (MultiStagedAttack), `Malicious user activity` (MaliciousUserActivity), `Compromised account` (CompromisedUser) – consider changing the enum name in public api accordingly, `Malware` (Malware), `Phishing` (Phishing), `Unwanted software` (UnwantedSoftware), and `Other` (Other). <li> <b>Informational, expected activity:</b> `Security test` (SecurityTesting), `Line-of-business application` (LineOfBusinessApplication), `Confirmed activity` (ConfirmedUserActivity) - consider changing the enum name in public api accordingly, and `Other` (Other). <li> <b>False positive:</b> `Not malicious` (Clean) - consider changing the enum name in public api accordingly, `Not enough data to validate` (InsufficientData), and `Other` (Other). |
76-
| tags | string list | List of Incident tags. |
76+
| tags | string list | List of Incident tags (customTags only). |
7777
| comments | List of incident comments | Incident Comment object contains: comment string, createdBy string, and createTime date time. |
7878
| alerts | alert list | List of related alerts. See examples at [List incidents](api-list-incidents.md) API documentation. |
7979

defender-xdr/breadcrumb/toc.yml

Lines changed: 17 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,21 @@
1+
12
- name: 'Microsoft Defender'
23
tocHref: /defender/
34
topicHref: /defender/index
45
items:
5-
- name: 'Microsoft Defender XDR'
6-
tocHref: /defender-xdr/
7-
topicHref: /defender-xdr/index
6+
- name: 'Microsoft Defender XDR'
7+
tocHref: /defender-xdr/
8+
topicHref: /defender-xdr/index
9+
- name: Microsoft Defender XDR
10+
tocHref: /defender-for-identity/
11+
topicHref: /defender-xdr/index
12+
13+
## Azure override
14+
- name: 'Microsoft Defender'
15+
tocHref: /azure/
16+
topicHref: /defender/index
17+
items:
18+
- name: 'Microsoft Defender XDR'
19+
tocHref: /azure/sentinel/
20+
topicHref: /defender-xdr/index
21+
297 KB
Loading
257 KB
Loading

defender-xdr/microsoft-365-security-center-defender-cloud-apps.md

Lines changed: 22 additions & 89 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,14 @@
11
---
2-
title: Microsoft Defender for Cloud Apps in Microsoft Defender XDR
3-
description: Learn about changes from the Microsoft Defender for Cloud Apps to Microsoft Defender XDR.
2+
title: Microsoft Defender for Cloud Apps in the Microsoft Defender portal
3+
description: Learn about using Microsoft Defender for Cloud Apps in the Microsoft Defender portal.
44
ms.service: defender-xdr
55
ms.localizationpriority: medium
66
f1.keywords:
77
- NOCSH
88
ms.author: bagol
99
author: batamig
1010
manager: raynew
11-
ms.date: 06/18/2024
11+
ms.date: 07/31/2024
1212
audience: ITPro
1313
ms.topic: conceptual
1414
search.appverid:
@@ -20,7 +20,7 @@ ms.collection:
2020
ms.custom: admindeeplinkDEFENDER
2121
---
2222

23-
# Microsoft Defender for Cloud Apps in Microsoft Defender XDR
23+
# Microsoft Defender for Cloud Apps in the Microsoft Defender portal
2424

2525
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2626

@@ -29,102 +29,35 @@ ms.custom: admindeeplinkDEFENDER
2929
- [Microsoft Defender XDR](microsoft-365-defender.md)
3030
- [Microsoft Defender for Cloud Apps](/defender-cloud-apps/)
3131

32-
Microsoft Defender for Cloud Apps is part of Microsoft Defender XDR, and uses the Microsoft Defender portal to allow security admins to perform their security tasks in one location. The Microsoft Defender portal simplifies workflows and combines functionality from other Microsoft Defender XDR services to Defender for Cloud Apps.
32+
Microsoft Defender for Cloud Apps is available inside the Microsoft Defender portal. The Defender portal is the home for monitoring and managing security across your Microsoft identities, data, devices, apps, and infrastructure, allowing security admins to perform their security tasks in one location, across multiple Microsoft Defender services.
3333

34-
The Microsoft Defender portal is the home for monitoring and managing security across your Microsoft identities, data, devices, apps, and infrastructure. SOC analysts can triage, investigate, and hunt across all Microsoft Defender XDR workloads, including cloud apps. For example, Defender for Cloud Apps alerts appear in Microsoft Defender XDR's incidents queue and alerts queue, with relevant content inside the alert pages, in a unified format with the proper adaptations to each alerts type.
35-
36-
All users accessing the classic Microsoft Defender for Cloud Apps portal are automatically rerouted to the Microsoft Defender portal, with no option to opt out. This article is intended for customers moving from the classic Defender for Cloud Apps portal and want to learn more about where to find Defender for Cloud Apps content in the Microsoft Defender portal.
34+
SOC analysts can triage, investigate, and hunt across all Microsoft Defender XDR workloads, including cloud apps.
3735

3836
Take a look in Microsoft Defender XDR at <https://security.microsoft.com>.
3937

4038
Learn more about the benefits: [Overview of Microsoft Defender XDR](microsoft-365-defender.md).
4139

42-
## Quick reference
43-
44-
The images and the tables below list the changes in navigation between Microsoft Defender for Cloud Apps and Microsoft Defender XDR.
45-
46-
### Discover
47-
48-
> [!div class="mx-imgBorder"]
49-
> :::image type="content" source="/defender/media/defender-cloud-apps-m365-defender-discover.png" alt-text="The new locations for Cloud Discovery features in the Microsoft Defender portal" lightbox="/defender/media/defender-cloud-apps-m365-defender-discover.png":::
50-
51-
| Defender for Cloud Apps | Microsoft Defender XDR |
52-
|---------|---------|
53-
| Cloud Discover dashboard | Cloud apps -> Cloud discovery |
54-
| Discovered Apps | tab on Cloud Discovery page |
55-
| Discovered resources | tab on Cloud Discovery page |
56-
| IP addresses | tab on Cloud Discovery page |
57-
| Users | tab on Cloud Discovery page |
58-
| Devices | tab on Cloud Discovery page |
59-
| Cloud app catalog | Cloud apps -> Cloud app catalog |
60-
| Create Cloud Discovery snapshot report | On the Cloud Discovery page, under Actions |
61-
62-
### Investigate
63-
64-
> [!div class="mx-imgBorder"]
65-
> :::image type="content" source="/defender/media/defender-cloud-apps-m365-defender-investigate.png" alt-text="The new locations for Investigation features in the Microsoft Defender portal" lightbox="/defender/media/defender-cloud-apps-m365-defender-investigate.png":::
66-
67-
| Defender for Cloud Apps | Microsoft Defender XDR |
68-
|---------|---------|
69-
| Activity log | Cloud apps -> Activity log |
70-
| Files | Cloud apps -> Files |
71-
| Users and accounts | Assets -> Identities |
72-
| Security configuration | available in [Microsoft Defender for Cloud](/azure/defender-for-cloud/defender-for-cloud-introduction) |
73-
| Identity security posture | [Microsoft Defender for Identity's identity security posture assessments](/defender-for-identity/isp-overview) |
74-
| OAuth apps | Cloud apps -> OAuth apps |
75-
| Connected apps | Settings -> Cloud apps -> Connected apps |
76-
77-
### Control
78-
79-
> [!div class="mx-imgBorder"]
80-
> :::image type="content" source="/defender/media/defender-cloud-apps-m365-defender-control.png" alt-text="The new locations for Control features in the Microsoft Defender portal" lightbox="/defender/media/defender-cloud-apps-m365-defender-control.png":::
81-
82-
| Defender for Cloud Apps | Microsoft Defender XDR |
83-
|---------|---------|
84-
| Policies | Cloud apps -> Policy management. Note: Microsoft Entra ID Protection policies will be removed gradually from the Cloud apps policies list. To configure alerts from these policies, see [Configure Microsoft Entra IP alert service](investigate-alerts.md#configure-aad-ip-alert-service) |
85-
| Templates | Cloud apps -> Policy templates |
86-
87-
### Settings
88-
89-
> [!div class="mx-imgBorder"]
90-
> :::image type="content" source="/defender/media/defender-cloud-apps-m365-defender-settings.png" alt-text="The new locations for Settings in the Microsoft Defender portal" lightbox="/defender/media/defender-cloud-apps-m365-defender-settings.png":::
91-
92-
| Defender for Cloud Apps | Microsoft Defender XDR |
93-
|---------|---------|
94-
| Settings | Settings -> Cloud apps |
95-
| Settings/Governance log | Cloud apps -> Governance log |
96-
| Security extensions -> Playbooks | Settings -> Cloud apps |
97-
| Security extensions -> SIEM agents | Settings -> Cloud apps |
98-
| Security extensions -> External DLP | Settings -> Cloud apps |
99-
| Security extensions -> API tokens | Settings -> Cloud apps |
100-
| Manage admin access -> Admin roles | Permissions-> Cloud apps-> Roles |
101-
| Manage admin access -> Activity privacy permissions | Permissions-> Cloud apps-> Activity privacy permissions |
102-
| Exported reports | Reports -> Cloud apps -> Exported reports |
103-
| Scoped deployment and privacy | Settings -> Cloud Apps -> Scoped deployment and privacy |
104-
| Connected Apps / App connectors | Settings -> Cloud Apps -> Connected apps -> App Connectors |
105-
| Conditional Access App Control | Settings -> Cloud apps -> Connected apps -> Conditional Access App Control apps |
106-
| IP address ranges | Settings -> Cloud apps |
107-
| User groups | Settings -> Cloud apps |
108-
109-
The capabilities on the following pages are fully integrated into Microsoft Defender XDR, and therefore don't have their own standalone experience in Microsoft Defender XDR:
110-
111-
- [Settings > Microsoft Entra ID Protection](investigate-alerts.md)
112-
- [Settings > App Governance](/defender-cloud-apps/app-governance-get-started)
113-
- [Settings > Microsoft Defender for Identity](/defender-for-identity/deploy-defender-identity)
114-
115-
## What's changed
116-
117-
Learn about the changes that have come with the integration of Defender for Cloud Apps and Microsoft Defender XDR.
118-
119-
### Global search
40+
## Perform cloud app security tasks
41+
42+
Find Defender for Cloud Apps functionality in the Microsoft Defender portal under **Cloud Apps**. For example:
43+
44+
:::image type="content" source="media/defender-for-cloud-apps/cloud-apps.png" alt-text="Screenshot that shows the Defender for Cloud Apps Cloud discovery page." lightbox="media/defender-for-cloud-apps/cloud-apps.png":::
45+
46+
## Investigate cloud app alerts
47+
48+
Defender for Cloud Apps alerts show in the Defender portal's incident and alerts queues, with relevant content inside alert pages for each type of an alert. For more information, see [Investigate incidents in Microsoft Defender XDR](investigate-incidents.md).
49+
50+
## Global search for your connected cloud apps
12051

12152
Use the Microsoft Defender portal's global search bar at the top of the page to search for connected apps in Defender for Cloud Apps.
12253

123-
:::image type="content" source="/defender/media/global-search-apps.png" alt-text="Search for connected apps.":::
54+
:::image type="content" source="/defender/media/global-search-apps.png" alt-text="Screenshot that shows searching for connected apps." lightbox="/defender/media/global-search-apps.png":::
55+
56+
## Assets and identities
12457

125-
### Assets and identities
58+
Use the **Assets > Identities** page to find comprehensive details about entities pulled from connected cloud applications, including a users's activity history and security alerts related to the user. For example:
12659

127-
As part of the creation of a dedicated **Assets** section that spans the entire Microsoft Defender XDR experience, the **Users and Accounts** section of Defender for Cloud Apps is rebranded as the **Identities** section. No changes to functionality are expected.
60+
:::image type="content" source="media/defender-for-cloud-apps/dashboard-top-users.png" alt-text="Screenshot that shows cloud app entities in the Identities page." lightbox="media/defender-for-cloud-apps/dashboard-top-users.png":::
12861

12962
<a name='redirection-from-the-classic-microsoft-defender-for-cloud-apps-portal-to-microsoft-365-defender'></a>
13063

0 commit comments

Comments
 (0)