Skip to content

Commit f96c4a0

Browse files
Merge pull request #4124 from MicrosoftDocs/main
[AutoPublish] main to live - 06/03 10:31 PDT | 06/03 23:01 IST
2 parents 1d44e5f + 83aa042 commit f96c4a0

35 files changed

+86
-62
lines changed

ATPDocs/remediation-actions.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -39,8 +39,24 @@ The following Defender for Identity actions can be performed directly on your on
3939

4040
- **Reset user password** – This will prompt the user to change their password on the next logon, ensuring that this account can't be used for further impersonation attempts.
4141

42+
- **Mark User Compromised** - The user’s risk level is set to High
43+
44+
- **Suspend User in Entra ID** - Block new sign-ins and access to cloud resources
45+
46+
- **Require User to Sign In Again** - Revoke a user’s active sessions
47+
4248
Depending on your Microsoft Entra ID roles, you might see additional Microsoft Entra ID actions, such as requiring users to sign in again and confirming a user as compromised. For more information, see [Remediate risks and unblock users](/entra/id-protection/howto-identity-protection-remediate-unblock).
4349

50+
## Roles and Permissions
51+
52+
| Action | XDR RBAC permissions |
53+
| ------------------------------------- | ------------------------------------------------------------ |
54+
|Mark User Compromised | - Global Administrator <br> - Security Administrator|
55+
|Suspend User in Entra ID | - Global Administrator |
56+
|Require User to Sign In Again | - Global Administrator <br> - Security Administrator <br> - Security Operator|
57+
| Disable/Enable User in Active Directory | Refer to [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr)|
58+
| Force Password Reset in Active Directory | Refer to [Required permissions Defender for Identity in Microsoft Defender XDR](/defender-for-identity/role-groups#required-permissions-defender-for-identity-in-microsoft-defender-xdr)|
59+
4460

4561
## Related videos
4662

defender-endpoint/api/collect-investigation-package.md

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -15,19 +15,19 @@ ms.topic: reference
1515
ms.subservice: reference
1616
ms.custom: api
1717
search.appverid: met150
18-
ms.date: 03/21/2025
18+
ms.date: 06/03/2025
1919
---
2020

2121
# Collect investigation package API
2222

2323
[!INCLUDE [Microsoft Defender XDR rebranding](../../includes/microsoft-defender.md)]
2424

2525
**Applies to:**
26+
2627
- [Microsoft Defender for Endpoint Plan 1](../microsoft-defender-endpoint.md)
2728
- [Microsoft Defender for Endpoint](../microsoft-defender-endpoint.md)
2829
- [Microsoft Defender XDR](/defender-xdr)
2930

30-
3131
> Want to experience Microsoft Defender for Endpoint? [Sign up for a free trial.](https://go.microsoft.com/fwlink/p/?linkid=2225630)
3232
3333
[!include[Microsoft Defender for Endpoint API URIs for US Government](../../includes/microsoft-defender-api-usgov.md)]
@@ -40,11 +40,7 @@ Collect investigation package from a device.
4040

4141
## Limitations
4242

43-
1. Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
44-
45-
> [!IMPORTANT]
46-
>
47-
> - These response actions are only available for devices on Windows 10, version 1703 or later, and on Windows 11.
43+
- Rate limitations for this API are 100 calls per minute and 1500 calls per hour.
4844

4945
## Permissions
5046

defender-endpoint/configure-machines-asr.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.collection:
1212
- tier2
1313
- mde-asr
1414
ms.custom: admindeeplinkDEFENDER
15-
ms.topic: conceptual
15+
ms.topic: article
1616
ms.subservice: asr
1717
search.appverid: met150
1818
ms.date: 03/27/2025

defender-endpoint/configure-mssp-support.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ audience: ITPro
1111
ms.collection:
1212
- m365-security
1313
- tier3
14-
ms.topic: conceptual
14+
ms.topic: article
1515
search.appverid: met150
1616
ms.date: 07/24/2024
1717
---

defender-endpoint/defender-antivirus-compatibility-without-mde.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ author: denisebmsft
55
ms.author: deniseb
66
ms.reviewer: yongrhee
77
ms.service: defender-endpoint
8-
ms.topic: conceptual
8+
ms.topic: article
99
ms.date: 04/09/2025
1010
ms.subservice: ngp
1111
search.appverid: met150

defender-endpoint/device-control-report.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.localizationpriority: medium
66
ms.date: 06/25/2024
77
ms.author: deniseb
88
author: denisebmsft
9-
ms.topic: conceptual
9+
ms.topic: article
1010
manager: deniseb
1111
ms.reviewer: joshbregman
1212
audience: ITPro

defender-endpoint/device-discovery-faq.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ audience: ITPro
1313
ms.collection:
1414
- m365-security
1515
- tier3
16-
ms.topic: conceptual
16+
ms.topic: faq
1717
search.appverid: met150
1818
ms.date: 03/04/2025
1919
---

defender-endpoint/edr-in-block-mode.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: deniseb
66
manager: deniseb
77
ms.reviewer: pahuijbr, kausd
88
audience: ITPro
9-
ms.topic: conceptual
9+
ms.topic: article
1010
ms.service: defender-endpoint
1111
ms.subservice: edr
1212
ms.localizationpriority: medium

defender-endpoint/ios-troubleshoot.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.collection:
1111
- m365-security
1212
- tier3
1313
- mde-ios
14-
ms.topic: conceptual
14+
ms.topic: faq
1515
ms.subservice: ios
1616
search.appverid: met150
1717
ms.date: 01/22/2025

defender-endpoint/machines-view-overview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ audience: ITPro
1111
ms.collection:
1212
- m365-security
1313
- tier2
14-
ms.topic: conceptual
14+
ms.topic: article
1515
search.appverid: met150
1616
ms.date: 01/23/2025
1717
---

0 commit comments

Comments
 (0)