Skip to content

Commit f349887

Browse files
committed
upload guidebook - Yuval
1 parent e15870e commit f349887

File tree

4 files changed

+22
-2
lines changed

4 files changed

+22
-2
lines changed
53.9 KB
Loading
107 KB
Loading
20.2 KB
Loading

defender-xdr/security-upload-guide.md

Lines changed: 22 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ ms.topic: install-set-up-deploy
1414
search.appverid:
1515
- MOE150
1616
- MET150
17-
ms.date: 11/18/2024
17+
ms.date: 11/18/2025
1818
appliesto:
1919
- Microsoft Defender XDR
2020
- Microsoft Sentinel with Defender XDR in the Microsoft Defender portal
@@ -59,4 +59,24 @@ Then follow these steps:
5959

6060
:::image type="content" source="./media/security-upload-guide/approve-guidebook.png" alt-text="Screenshot of the approve and activate button for uploaded guidebooks.":::
6161

62-
Copilot uses the most relevant guidance it has for each incident. A banner shows which guidebook is being used for the current recommendation.
62+
1. Make sure the guidebook appears as active in the **Guidebooks** tab. To deactivate it later, select the guidebook and choose **Deactivate**.
63+
64+
:::image type="content" source="./media/security-upload-guide/active-guidebooks.png" alt-text="Screenshot of the active guidebooks tab.":::
65+
66+
Copilot will prioritize your organization's custom guidebooks over the default ones provided by Microsoft. If multiple guidebooks are relevant, Copilot will use the one that best matches the incident context.
67+
68+
:::image type="content" source="./media/security-upload-guide/custom-responses.png" alt-text="Screenshot of suggested responses based on the custom guidebooks.":::
69+
70+
You have the opportunity to provide feedback on the effectiveness of the guided responses generated from your organization's guidebooks. This feedback helps improve future recommendations.
71+
72+
:::image type="content" source="./media/security-upload-guide/feedback.png" alt-text="Screenshot of the feedback window for guided responses.":::
73+
74+
## Best practices for creating effective guidebooks
75+
76+
For examples of Microsoft's own incident response playbooks, see [Incident response playbooks](/security/operations/incident-response-playbooks).
77+
78+
When creating your organization's guidebooks, consider the following best practices:
79+
80+
- **Clarity and Conciseness**: Ensure that the guidelines are clear and concise to facilitate quick understanding and action.
81+
- **Text only**: The guidebook can only read text. Avoid using images, graphs, or complex formatting that may hinder text extraction.
82+
- **Regular Updates**: Periodically review and update the guidebooks to reflect any changes in your organization's policies or procedures.

0 commit comments

Comments
 (0)