You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Content distribution helps you manage content at scale, across tenants in multi-tenant management in Microsoft Defender XDR. In content distribution, you can create tenant groups to copy existing content, like custom detection rules, from the source tenant to the target tenants you assign during tenant group creation. The content then runs on the target tenant's devices or device groups that you set in the tenant group scope.
24
+
Content distribution helps you manage content at scale, across tenants in multitenant management in Microsoft Defender XDR. In content distribution, you can create tenant groups to copy existing content, like custom detection rules, from the source tenant to the target tenants you assign during tenant group creation. The content then runs on the target tenant's devices or device groups that you set in the tenant group scope.
25
25
26
26
Distributing content in this manner, across tenants, enables you to organize tenants and content based on categories like business groups or location.
27
27
28
28
> [!NOTE]
29
-
> Multi-tenant management currently supports adding custom detection rules to a tenant group. Additional content types will be added in the future.
29
+
> Multitenant management currently supports adding custom detection rules to a tenant group. Additional content types will be added in the future.
30
30
31
31
## Requirements
32
32
33
-
The following table lists the requirements for content distribution in multi-tenant management in Microsoft Defender XDR.
33
+
The following table lists the requirements for content distribution in multitenant management in Microsoft Defender XDR.
34
34
35
35
| Requirement | Description |
36
36
|:---|:---|
37
37
|Microsoft Defender XDR license |To use content distribution, your organization must have a subscription to Microsoft 365 E5 or Office E5.|
38
-
|Permissions |Users must be assigned the correct roles and permission at the individual tenant level to view and manage the associated data in multi-tenant management. <br/> Access to content distribution is granted through the Security settings (manage) or Security Data Basic (read) permission in [Microsoft 365 Defender Unified role-based access control (URBAC)](manage-rbac.md). Both of these roles are assigned to the Security Administrator and Security Reader Microsoft Entra built-in roles by default.|
38
+
|Permissions |Users must be assigned the correct roles and permission at the individual tenant level to view and manage the associated data in multitenant management. <br/> Access to content distribution is granted through the Security settings (manage) or Security Data Basic (read) permission in [Microsoft 365 Defender Unified role-based access control (URBAC)](manage-rbac.md). Both of these roles are assigned to the Security Administrator and Security Reader Microsoft Entra built-in roles by default.|
39
39
|Delegate access |Delegated access via [Azure B2B](/entra/external-id/add-users-administrator) or [GDAP (CSP Parters only)](/microsoft-365/lighthouse/m365-lighthouse-setup-gdap) must be obtained for at least one other tenant.|
40
40
41
41
## Create tenant groups
42
42
43
43
To create a new tenant group:
44
44
45
-
1. Go to the [Tenant groups page](https://mto.security.microsoft.com/tenantgroups) in multi-tenant management in Microsoft Defender XDR.
45
+
1. Go to the [Tenant groups page](https://mto.security.microsoft.com/tenantgroups) in multitenant management in Microsoft Defender XDR.
46
46
2. Select **Create tenant group**:
47
47
48
48
:::image type="content" source="/defender-xdr/media/multi-tenant/tenant-groups/tenant-groups-add-small.png" alt-text="Screenshot of the tenant group creation wizard." lightbox="/defender-xdr/media/multi-tenant/tenant-groups/tenant-groups-add.png":::
@@ -51,7 +51,7 @@ To create a new tenant group:
51
51
4. Select **Add** to add custom detection rules.
52
52
53
53
> [!NOTE]
54
-
> Multi-tenant management currently only supports adding custom detection rules to a tenant group. Additional content types will be added in the future.
54
+
> Multitenant management currently only supports adding custom detection rules to a tenant group. Additional content types will be added in the future.
55
55
56
56
5. The **Source tenant** column displays the tenant the detection rule comes from. Choose the detection rules you want to add to the assignment.
Copy file name to clipboardExpand all lines: defender-xdr/whats-new.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -31,7 +31,7 @@ You can also get product updates and important notifications through the [messag
31
31
32
32
## June 2024
33
33
34
-
- (Preview) **[Content distribution in multi-tenant management](mto-tenantgroups.md)** is now available. Content distribution helps you manage content at scale, across tenants in multi-tenant management in Microsoft Defender XDR. In content distribution, you can create tenant groups to copy existing content, like custom detection rules, from the source tenant to the target tenants you assign during tenant group creation. The content then runs on the target tenant's devices or device groups that you set in the tenant group scope.
34
+
- (Preview) **[Content distribution through tenant groups in multitenant management](mto-tenantgroups.md)** is now available. Content distribution helps you manage content at scale, across tenants in multitenant management in Microsoft Defender XDR. In content distribution, you can create tenant groups to copy existing content, like custom detection rules, from the source tenant to the target tenants you assign during tenant group creation. The content then runs on the target tenant's devices or device groups that you set in the tenant group scope.
35
35
36
36
- (Preview) You can now filter your Microsoft Defender for Cloud alerts by the associated **alert subscription ID** in the Incidents and Alerts queues. For more information, see [Microsoft Defender for Cloud in Microsoft Defender XDR](microsoft-365-security-center-defender-cloud.md).
0 commit comments