Skip to content

Commit ef67bc4

Browse files
authored
Merge branch 'main' into WI366423-add-important-note-about-urbac
2 parents 6943ffa + d481d44 commit ef67bc4

File tree

195 files changed

+1480
-1998
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

195 files changed

+1480
-1998
lines changed

.openpublishing.redirection.defender-endpoint.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,15 @@
11
{
22
"redirections": [
3+
{
4+
"source_path": "defender-endpoint/threat-analytics-analyst-reports.md",
5+
"redirect_url": "/defender-xdr/threat-analytics-analyst-reports",
6+
"redirect_document_id": false
7+
},
8+
{
9+
"source_path": "defender-endpoint/threat-analytics.md",
10+
"redirect_url": "/defender-xdr/threat-analytics",
11+
"redirect_document_id": false
12+
},
313
{
414
"source_path": "defender-endpoint/configure-microsoft-threat-experts.md",
515
"redirect_url": "/defender-xdr/defender-experts-for-hunting",

.openpublishing.redirection.defender-xdr.json

Lines changed: 46 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -259,6 +259,51 @@
259259
"source_path": "defender-xdr/microsoft-sentinel-onboard.md",
260260
"redirect_url": "/unified-secops-platform/microsoft-sentinel-onboard",
261261
"redirect_document_id": false
262-
}
262+
},
263+
{
264+
"source_path": "defender-xdr/first-incident-path-phishing.md",
265+
"redirect_url": "/security/operations/incident-response-playbook-phishing",
266+
"redirect_document_id": false
267+
},
268+
{
269+
"source_path": "defender-xdr/first-incident-path-identity.md",
270+
"redirect_url": "/defender-for-identity/manage-security-alerts",
271+
"redirect_document_id": false
272+
},
273+
{
274+
"source_path": "defender-xdr/incident-response-overview.md",
275+
"redirect_url": "/defender-xdr/incidents-overview",
276+
"redirect_document_id": true
277+
},
278+
{
279+
"source_path": "defender-xdr/respond-first-incident-analyze.md",
280+
"redirect_url": "/defender-xdr/investigate-incidents",
281+
"redirect_document_id": true
282+
},
283+
{
284+
"source_path": "defender-xdr/respond-first-incident-365-defender.md",
285+
"redirect_url": "/defender-xdr/manage-incidents",
286+
"redirect_document_id": true
287+
},
288+
{
289+
"source_path": "defender-xdr/export-incidents-queue.md",
290+
"redirect_url": "/defender-xdr/incident-queue",
291+
"redirect_document_id": true
292+
},
293+
{
294+
"source_path": "defender-xdr/respond-first-incident-remediate.md",
295+
"redirect_url": "/defender-xdr/incidents-overview",
296+
"redirect_document_id": false
297+
},
298+
{
299+
"source_path": "defender-xdr/m365d-time-zone.md",
300+
"redirect_url": "/defender-xdr/m365d-enable-faq",
301+
"redirect_document_id": true
302+
},
303+
{
304+
"source_path": "defender-xdr/feedback.md",
305+
"redirect_url": "/defender-xdr/m365d-enable-faq",
306+
"redirect_document_id": false
307+
},
263308
]
264309
}

ATPDocs/deploy/activate-capabilities.md

Lines changed: 14 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -88,12 +88,16 @@ Activate the Defender for Identity from the [Microsoft Defender portal](https://
8888

8989
The Activation page lists servers discovered in Device Inventory and identified as eligible domain controllers.
9090

91-
2. Select the domain controller where you want to activate the Defender for Identity capabilities and then select **Activate**. Confirm your selection when prompted.
91+
1. Select the domain controller where you want to activate the Defender for Identity capabilities and then select **Activate**. Confirm your selection when prompted.
92+
93+
:::image type="content" source="media/activate-capabilities/1.jpg" lightbox="media/activate-capabilities/1.jpg" alt-text="Screenshot that shows how to activate the new sensor.":::
9294

9395
> [!NOTE]
9496
> You can choose to activate eligible domain controllers either automatically, where Defender for Identity activates them as soon as they're discovered, or manually, where you select specific domain controllers from the list of eligible servers.
9597
96-
3. When the activation is complete, a green success banner shows. In the banner, select **Click here to see the onboarded servers** to jump to the **Settings > Identities > Sensors** page, where you can check your sensor health.
98+
1. When the activation is complete, a green success banner shows. In the banner, select **Click here to see the onboarded servers** to jump to the **Settings > Identities > Sensors** page, where you can check your sensor health.
99+
100+
:::image type="content" source="media/activate-capabilities/2.jpg" lightbox="media/activate-capabilities/2.jpg" alt-text="Screenshot that shows how to seethe onboarded servers.":::
97101

98102
## Onboarding Confirmation
99103

@@ -104,7 +108,7 @@ To confirm the sensor has been onboarded:
104108
2. Check that the onboarded domain controller is listed.
105109

106110
> [!NOTE]
107-
> The activation doesn't require a restart/reboot. The first time you activate Defender for Identity capabilities on your domain controller, it may take up to an hour for the first sensor to show as **Running** on the **Sensors** page. Subsequent activations are shown within five minutes.
111+
> The activation doesn't require a restart/reboot. The first time you activate Defender for Identity capabilities on your domain controller, it may take up to an hour for the first sensor to show as **Running** on the **Sensors** page. Subsequent activations are shown within five minutes.
108112
109113
## Test activated capabilities
110114

@@ -126,7 +130,6 @@ In the Defender portal, select **Identities** > **Dashboard**, and review the de
126130

127131
For more information, see [Work with Defender for Identity's ITDR dashboard](../dashboard.md).
128132

129-
130133
### Confirm entity page details
131134

132135
Confirm that entities, such as domain controllers, users, and groups, are populated as expected.
@@ -139,7 +142,7 @@ In the Defender portal, check for the following details:
139142

140143
- **Group entities**: Use the global search to find a user group, or pivot from a user or device details page where group details are shown. Check for details of group membership, view group users, and group timeline data.
141144

142-
If no event data is found on the group timeline, you may need to create some manually. For example, do this by adding and removing users from the group in Active Directory.
145+
If no event data is found on the group timeline, you may need to create some manually. For example, do this by adding and removing users from the group in Active Directory.
143146

144147
For more information, see [Investigate assets](../investigate-assets.md).
145148

@@ -205,18 +208,20 @@ Test remediation actions on a test user. For example:
205208
206209
1. In the Defender portal, go to the user details page for a test user.
207210
208-
1. From the **Options** menu, select any of the available remediation actions.
211+
2. From the **Options** menu, select any of the available remediation actions.
209212
210-
1. Check Active Directory for the expected activity.
213+
3. Check Active Directory for the expected activity.
211214
212215
For more information, see [Remediation actions in Microsoft Defender for Identity](../remediation-actions.md).
213216
214217
## Deactivate Defender for Identity capabilities on your domain controller
215218
216219
If you want to deactivate Defender for Identity capabilities on your domain controller, delete it from the **Sensors** page:
217220
218-
1. In the Defender portal, select **Settings > Identities > Sensors**.
219-
1. Select the domain controller where you want to deactivate Defender for Identity capabilities, select **Delete**, and confirm your selection.
221+
1. In the Defender portal, select **Settings** > **Identities** > **Sensors**.
222+
2. Select the domain controller where you want to deactivate Defender for Identity capabilities, select **Delete**, and confirm your selection.
223+
224+
:::image type="content" source="media/activate-capabilities/3.jpg" lightbox="media/activate-capabilities/3.jpg" alt-text="Screenshot that shows how to deactivate a server.":::
220225
221226
Deactivating Defender for Identity capabilities from your domain controller doesn't remove the domain controller from Defender for Endpoint. For more information, see [Defender for Endpoint documentation](/microsoft-365/security/defender-endpoint/).
222227
186 KB
Loading
144 KB
Loading
169 KB
Loading

ATPDocs/role-groups.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ The following table details the specific permissions required for Defender for I
4444
| ------------------- | ---------------------- |
4545
| **Onboard Defender for Identity** (create workspace) | [Security Administrator](/entra/identity/role-based-access-control/permissions-reference) |
4646
| **Configure Defender for Identity settings** | One of the following Microsoft Entra roles:<br>- [Security Administrator](/entra/identity/role-based-access-control/permissions-reference)<br>- [Security Operator](/entra/identity/role-based-access-control/permissions-reference)<br> **Or** <br>The following [Unified RBAC permissions](#unified-role-based-access-control-rbac):<br />- `Authorization and settings/Security settings/Read`<br/>- `Authorization and settings/Security settings/All permissions`<br/>- `Authorization and settings/System settings/Read`<br/>- `Authorization and settings/System settings/All permissions` |
47-
|**View Defender for Identity settings** | One of the following Microsoft Entra roles:<br>- [Global Reader](/entra/identity/role-based-access-control/permissions-reference)<br>- [Security Reader](/entra/identity/role-based-access-control/permissions-reference) <br> **Or** <br>The following [Unified RBAC permissions](#unified-role-based-access-control-rbac):<br />- `Authorization and settings/Security settings/Read` <br/>- `Authorization and settings/System settings/Read`|
47+
|**View Defender for Identity settings** | Microsoft Entra roles:<br>- [Security Reader](/entra/identity/role-based-access-control/permissions-reference) <br> **Or** <br>The following [Unified RBAC permissions](#unified-role-based-access-control-rbac):<br />- `Authorization and settings/Security settings/Read` <br/>- `Authorization and settings/System settings/Read`|
4848
|**Manage Defender for Identity security alerts and activities** | One of the following Microsoft Entra roles:<br>- [Security Operator](/entra/identity/role-based-access-control/permissions-reference)<br> **Or** <br>The following [Unified RBAC permissions](#unified-role-based-access-control-rbac):<br />- `Security operations/Security data/Alerts (Manage)`<br/>- `Security operations/Security data /Security data basics (Read)` |
4949
| **View Defender for Identity security assessments** <br> (now part of Microsoft Secure Score) | [Permissions](/microsoft-365/security/defender/microsoft-secure-score#required-permissions) to access Microsoft Secure Score <br> **And** <br> The following [Unified RBAC permissions](#unified-role-based-access-control-rbac): `Security operations/Security data /Security data basics (Read)`|
5050
|**View the Assets / Identities page**|[Permissions](/defender-cloud-apps/manage-admins) to access Defender for Cloud Apps <br> **Or** <br> One of the Microsoft Entra roles required by [Microsoft Defender XDR](/microsoft-365/security/defender/m365d-permissions) |

ATPDocs/security-assessment.md

Lines changed: 14 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,13 +9,13 @@ ms.topic: how-to
99

1010
Typically, organizations of all sizes have limited visibility into whether or not their on-premises apps and services could introduce a security vulnerability to their organization. The problem of limited visibility is especially true regarding use of unsupported or outdated components.
1111

12-
While your company may invest significant time and effort on hardening identities and identity infrastructure (such as Active Directory, Active Directory Connect) as an on-going project, it's easy to remain unaware of common misconfigurations and use of legacy components that represent one of the greatest threat risks to your organization.
12+
While your company might invest significant time and effort on hardening identities and identity infrastructure (such as Active Directory, Active Directory Connect) as an ongoing project, it's easy to remain unaware of common misconfigurations and use of legacy components that represent one of the greatest threat risks to your organization.
1313

1414
Microsoft security research reveals that most identity attacks utilize common misconfigurations in Active Directory and continued use of legacy components (such as NTLMv1 protocol) to compromise identities and successfully breach your organization. To combat this effectively, Microsoft Defender for Identity now offers proactive identity security posture assessments to detect and recommend actions across your on-premises Active Directory configurations.
1515

1616
## What do Defender for Identity security assessments provide?
1717

18-
Defender for Identity's security posture assessments are available in [Microsoft Secure Score](/microsoft-365/security/defender/microsoft-secure-score), and provide:
18+
Defender for Identity security posture assessments are available in [Microsoft Secure Score](/microsoft-365/security/defender/microsoft-secure-score), and provide:
1919

2020
- **Detections and contextual data** on known exploitable components and misconfigurations, along with relevant paths for remediation.
2121

@@ -25,11 +25,21 @@ Defender for Identity's security posture assessments are available in [Microsoft
2525

2626
Microsoft Secure Score is a measurement of an organization's security posture, with a higher number indicating more recommended actions taken. It can be found at <https://security.microsoft.com/securescore> in the [Microsoft Defender portal](/microsoft-365/security/defender/microsoft-365-defender).
2727

28+
### Categorization of Defender for Identity security posture assessments
29+
30+
Defender for Identity security posture assessments have five key categories. Each category addresses specific identity security risks and provides remediation guidance.
31+
32+
- **Hybrid security**: Identifies misconfigurations in environments that integrate on-premises (e.g., Active Directory) and cloud-based identity providers (e.g., Entra ID, Okta). Assesses risks related to synchronization, authentication, and authorization across platforms.
33+
- **Identity infrastructure**: Detects misconfigurations and vulnerabilities in core identity components, including domain controllers.
34+
- **Certificates**: Assesses Active Directory Certificate Services (AD CS) for security gaps, such as misconfigured certificate templates or weak certificate authority settings. Identifying and addressing these issues helps prevent unauthorized access that could arise from certificate-related vulnerabilities.
35+
- **Group policy**: Analyzes Group Policy configurations to identify settings that might allow privilege escalation or unauthorized lateral movement within the network. Ensuring secure Group Policy settings helps maintain proper access controls and system configurations.
36+
- **Accounts**: Reviews users, devices, and groups to pinpoint security risks such as weak passwords, inactive accounts, or improper permissions.
37+
2838
## Access Defender for Identity security posture assessments
2939

40+
> [!NOTE]
3041
You must have a Defender for Identity license to view Defender for Identity security posture assessments in Microsoft Secure Score.
31-
32-
While *certificate template* assessments are available to all customers that have AD CS installed on their environment, *certificate authority* assessments are available only to customers who've installed a sensor on an AD CS server. For more information, see [Configuring sensors for AD FS and AD CS](deploy/active-directory-federation-services.md).
42+
While *certificate template* assessments are available to all customers with AD CS installed in their environment, *certificate authority* assessments are available only to customers who have installed a sensor on an AD CS server. For more information, see [Configuring sensors for AD FS and AD CS](deploy/active-directory-federation-services.md).
3343

3444
**To access identity security posture assessments**:
3545

0 commit comments

Comments
 (0)