Skip to content

Commit fb95a57

Browse files
authored
Update identity-security-initiative.md
1 parent d607e4c commit fb95a57

File tree

1 file changed

+29
-26
lines changed

1 file changed

+29
-26
lines changed

ATPDocs/identity-security-initiative.md

Lines changed: 29 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -16,40 +16,17 @@ Identity security is the practice of protecting the digital identities of indivi
1616
- Your organization must have a Microsoft Defender for Identity license.
1717
- [Review prerequisites and permissions needed](/security-exposure-management/prerequisites) for working with Security Exposure Management.
1818

19-
## View Identity security recommendations
20-
21-
The Security recommendations tab displays a list of prioritized remediation actions related to your identity security posture. Each recommendation is evaluated for compliance and mapped to its corresponding risk impact, workload, and domain. This view helps you triage and take action based on urgency and business relevance.
22-
23-
:::image type="content" source="media/identity-security-initiative/screenshot-showing-the-security-recommendations-page.png" alt-text="Showing showing the security recommendations page":::
24-
19+
## View Identity Security Initiatives
2520
1. Navigate to [Microsoft Defender portal](https://security.microsoft.com/)
2621
1. From the Exposure management section on the navigation bar, select Exposure insights **>** Initiatives to open the Identity Security page.
27-
1. Sort the recommendations by any of the headings or filter them based on your task needs. Sorting includes all of the headers:
28-
29-
30-
| **Column** | **Description** |
31-
|------------------------|---------------------------------------------------------------------------------|
32-
| **Name** | The name of the recommended action (for example, *Configure VPN integration*, *Enable MFA*). |
33-
| **State** | Indicates whether the recommendation is *Compliant* or *Not Compliant*. |
34-
| **Impact** | The security impact level (Low, Medium, or High) of implementing the recommendation. |
35-
| **Workload** | The Microsoft service area the recommendation applies to (for example, Defender for Identity, Microsoft Entra ID). |
36-
| **Domain** | The security domain (for example, identity, apps) associated with the recommendation. |
37-
| **Last calculated** | The most recent time the recommendation's status was evaluated. |
38-
| **Last state change** | When the recommendation’s compliance state last changed. |
39-
| **Related initiatives**| Number of security initiatives impacted by this recommendation. |
40-
| **Related metrics** | Number of security metrics that this recommendation contributes to. |
41-
42-
Security Exposure Management categorizes recommendations by compliance status, as follows:
43-
44-
- **Compliant**: Indicates that the recommendation was implemented successfully.
45-
- **Not complaint**: Indicates that the recommendation wasn't fixed.
4622

4723
## Review security metrics
4824

4925
Metrics in security initiatives help you to measure exposure risk for different areas within the initiative. Each metric gathers together one or more recommendations for similar assets.
5026
Metrics can be associated with one or more initiatives.
5127

5228
On the Metrics tab of an initiative, or in the Metrics section of Exposure Insights, you can see the metric state, its effect, and relative importance in an initiative, and recommendations to improve the metric.
29+
We recommend that you prioritize metrics with the highest impact on Initiative Score level. This composite measure considers both the weight value of each recommendation and the percentage of non-compliant recommendations.
5330

5431
:::image type="content" source="media/identity-security-initiative/screenshot-of-the-security-metrics-page.png" alt-text="Screenshot showing the security metrics page":::
5532

@@ -59,13 +36,39 @@ On the Metrics tab of an initiative, or in the Metrics section of Exposure Insig
5936
|**Metric name** | The name of the metric. |
6037
|**Progress** |Shows the improvement of the exposure level for the metric from 0 (high exposure) to 100 (no exposure). |
6138
|**State** | Shows if the metric needs attention or if the target was met. |
62-
|**Affected assets** | The number of affected assets within the metric. |
6339
|**Total assets** | Total number of assets under the metric scope. |
6440
|**Recommendations** | Security recommendations associated with the metric. |
6541
|**Weight** | The relative weight (importance) of the metric within the initiative, and its effect on the initiative score. Shown as High, Medium, and Low. It can also be defined as Risk accepted. |
6642
|**14-day trend** | Shows the metric value changes over the last 14 days. |
6743
|**Last updated** | Shows a timestamp of when the metric was last updated.
6844

45+
> [!NOTE]
46+
> The Affected assets experience is not fully supported during the Preview phase.
47+
48+
## View Identity security recommendations
49+
50+
The Security recommendations tab displays a list of prioritized remediation actions related to your identity security posture. Each recommendation is evaluated for compliance and mapped to its corresponding risk impact, workload, and domain. This view helps you triage and take action based on urgency and business relevance.
51+
52+
:::image type="content" source="media/identity-security-initiative/screenshot-showing-the-security-recommendations-page.png" alt-text="Showing showing the security recommendations page":::
53+
54+
Sort the recommendations by any of the headings or filter them based on your task needs.
55+
56+
| **Column** | **Description** |
57+
|------------------------|---------------------------------------------------------------------------------|
58+
| **Name** | The name of the recommended action (for example, *Configure VPN integration*, *Enable MFA*). |
59+
| **State** | Indicates whether the recommendation is *Compliant* or *Not Compliant*. |
60+
| **Impact** | The security impact level (Low, Medium, or High) of implementing the recommendation. |
61+
| **Workload** | The Microsoft service area the recommendation applies to (for example, Defender for Identity, Microsoft Entra ID). |
62+
| **Domain** | The security domain (for example, identity, apps) associated with the recommendation. |
63+
| **Last calculated** | The most recent time the recommendation's status was evaluated. |
64+
| **Last state change** | When the recommendation’s compliance state last changed. |
65+
| **Related initiatives**| Number of security initiatives impacted by this recommendation. |
66+
| **Related metrics** | Number of security metrics that this recommendation contributes to. |
67+
68+
Security Exposure Management categorizes recommendations by compliance status, as follows:
69+
70+
- **Compliant**: Indicates that the recommendation was implemented successfully.
71+
- **Not complaint**: Indicates that the recommendation wasn't fixed.
6972

7073
## Set target scores
7174

0 commit comments

Comments
 (0)