Skip to content

Commit 3f46a12

Browse files
authored
Merge pull request #49791 from KenMAG/main
Revised unit per updated UI and updated ms.author field
2 parents 10455c7 + cb491a4 commit 3f46a12

8 files changed

+180
-176
lines changed
Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.introduction
3-
title: Introduction
4-
metadata:
5-
title: Introduction
6-
description: "Introduction"
7-
ms.date: 11/28/2023
8-
author: wwlpublish
9-
ms.author: bneeb
10-
ms.topic: unit
11-
azureSandbox: false
12-
labModal: false
13-
durationInMinutes: 3
14-
content: |
15-
[!include[](includes/1-introduction.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.introduction
3+
title: Introduction
4+
metadata:
5+
title: Introduction
6+
description: "Introduction"
7+
ms.date: 11/28/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 3
14+
content: |
15+
[!include[](includes/1-introduction.md)]
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.configure-advanced-features
3-
title: Configure advanced features
4-
metadata:
5-
title: Configure advanced features
6-
description: "Configure advanced features"
7-
ms.date: 11/28/2023
8-
author: wwlpublish
9-
ms.author: bneeb
10-
ms.topic: unit
11-
azureSandbox: false
12-
labModal: false
13-
durationInMinutes: 4
14-
content: |
15-
[!include[](includes/2-configure-advanced-features.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.configure-advanced-features
3+
title: Configure advanced features
4+
metadata:
5+
title: Configure advanced features
6+
description: "Configure advanced features"
7+
ms.date: 11/28/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 4
14+
content: |
15+
[!include[](includes/2-configure-advanced-features.md)]
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.upload-folder-settings
3-
title: Manage automation upload and folder settings
4-
metadata:
5-
title: Manage automation upload and folder settings
6-
description: "Manage automation upload and folder settings"
7-
ms.date: 11/28/2023
8-
author: wwlpublish
9-
ms.author: bneeb
10-
ms.topic: unit
11-
azureSandbox: false
12-
labModal: false
13-
durationInMinutes: 5
14-
content: |
15-
[!include[](includes/3-manage-automation-upload-folder-settings.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.upload-folder-settings
3+
title: Manage automation upload and folder settings
4+
metadata:
5+
title: Manage automation upload and folder settings
6+
description: "Manage automation upload and folder settings"
7+
ms.date: 11/28/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 5
14+
content: |
15+
[!include[](includes/3-manage-automation-upload-folder-settings.md)]
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.configure-automated-investigation-remediation-capabilities
3-
title: Configure automated investigation and remediation capabilities
4-
metadata:
5-
title: Configure automated investigation and remediation capabilities
6-
description: "Configure automated investigation and remediation capabilities"
7-
ms.date: 11/28/2023
8-
author: wwlpublish
9-
ms.author: bneeb
10-
ms.topic: unit
11-
azureSandbox: false
12-
labModal: false
13-
durationInMinutes: 5
14-
content: |
15-
[!include[](includes/4-configure-automated-investigation-remediation-capabilities.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.configure-automated-investigation-remediation-capabilities
3+
title: Configure automated investigation and remediation capabilities
4+
metadata:
5+
title: Configure automated investigation and remediation capabilities
6+
description: "Configure automated investigation and remediation capabilities"
7+
ms.date: 03/31/2025
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 5
14+
content: |
15+
[!include[](includes/4-configure-automated-investigation-remediation-capabilities.md)]
Lines changed: 51 additions & 51 deletions
Original file line numberDiff line numberDiff line change
@@ -1,51 +1,51 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.knowledge-check
3-
title: Knowledge check
4-
metadata:
5-
title: Knowledge check
6-
description: "Knowledge check"
7-
ms.date: 11/28/2023
8-
author: wwlpublish
9-
ms.author: bneeb
10-
ms.topic: unit
11-
azureSandbox: false
12-
labModal: false
13-
durationInMinutes: 3
14-
content: |
15-
[!include[](includes/6-knowledge-check.md)]
16-
quiz:
17-
title: "Check your knowledge"
18-
questions:
19-
- content: "Which is a valid remediation level?"
20-
choices:
21-
- content: "Semi - require approval for any remediation"
22-
isCorrect: true
23-
explanation: "Correct. This is a valid remediation level."
24-
- content: "Semi - user accounts only"
25-
isCorrect: false
26-
explanation: "Incorrect. This isn't a valid remediation level."
27-
- content: "Semi - files only"
28-
isCorrect: false
29-
explanation: "Incorrect. This isn't a valid remediation level."
30-
- content: "A security operations analyst needs to exclude a custom executable file c:\\myapp\\myapp.exe, which exclusion type should they use?"
31-
choices:
32-
- content: "File"
33-
isCorrect: true
34-
explanation: "Correct. File will exclude this specific file from automation"
35-
- content: "Extension"
36-
isCorrect: false
37-
explanation: "Incorrect. Extension would exclude all files with the extension."
38-
- content: "Folder"
39-
isCorrect: false
40-
explanation: "Incorrect. Folder would exclude all files in a folder."
41-
- content: "In advanced features, which setting should be turned on to block files even if a third-party antivirus is used?"
42-
choices:
43-
- content: "Enable EDR in block mode"
44-
isCorrect: true
45-
explanation: "Correct. EDR in block mode is used with third party antivirus"
46-
- content: "Allow or block file"
47-
isCorrect: false
48-
explanation: "Incorrect. The feature requires Defender antivirus"
49-
- content: "Automated Investigation"
50-
isCorrect: false
51-
explanation: "Incorrect. Automated investigations aren't specific to blocking files."
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.knowledge-check
3+
title: Knowledge check
4+
metadata:
5+
title: Knowledge check
6+
description: "Knowledge check"
7+
ms.date: 11/28/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 3
14+
content: |
15+
[!include[](includes/6-knowledge-check.md)]
16+
quiz:
17+
title: "Check your knowledge"
18+
questions:
19+
- content: "Which is a valid remediation level?"
20+
choices:
21+
- content: "Semi - require approval for any remediation"
22+
isCorrect: true
23+
explanation: "Correct. This is a valid remediation level."
24+
- content: "Semi - user accounts only"
25+
isCorrect: false
26+
explanation: "Incorrect. This isn't a valid remediation level."
27+
- content: "Semi - files only"
28+
isCorrect: false
29+
explanation: "Incorrect. This isn't a valid remediation level."
30+
- content: "A security operations analyst needs to exclude a custom executable file c:\\myapp\\myapp.exe, which exclusion type should they use?"
31+
choices:
32+
- content: "File"
33+
isCorrect: true
34+
explanation: "Correct. File excludes this specific file from automation"
35+
- content: "Extension"
36+
isCorrect: false
37+
explanation: "Incorrect. Extension would exclude all files with the extension."
38+
- content: "Folder"
39+
isCorrect: false
40+
explanation: "Incorrect. Folder would exclude all files in a folder."
41+
- content: "In advanced features, which setting should be turned on to block files even if a third-party antivirus is used?"
42+
choices:
43+
- content: "Enable EDR in block mode"
44+
isCorrect: true
45+
explanation: "Correct. EDR in block mode is used with third party antivirus"
46+
- content: "Allow or block file"
47+
isCorrect: false
48+
explanation: "Incorrect. The feature requires Defender antivirus"
49+
- content: "Automated Investigation"
50+
isCorrect: false
51+
explanation: "Incorrect. Automated investigations aren't specific to blocking files."
Lines changed: 15 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
1-
### YamlMime:ModuleUnit
2-
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.summary-resources
3-
title: Summary and resources
4-
metadata:
5-
title: Summary and resources
6-
description: "Summary and resources"
7-
ms.date: 11/28/2023
8-
author: wwlpublish
9-
ms.author: bneeb
10-
ms.topic: unit
11-
azureSandbox: false
12-
labModal: false
13-
durationInMinutes: 3
14-
content: |
15-
[!include[](includes/7-summary-resources.md)]
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.summary-resources
3+
title: Summary and resources
4+
metadata:
5+
title: Summary and resources
6+
description: "Summary and resources"
7+
ms.date: 11/28/2023
8+
author: wwlpublish
9+
ms.author: kelawson
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 3
14+
content: |
15+
[!include[](includes/7-summary-resources.md)]

learn-pr/wwl-sci/configure-manage-automation-microsoft-defender-for-endpoint/includes/4-configure-automated-investigation-remediation-capabilities.md

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,18 @@ To configure automated investigation and remediation, turn on the features, and
22

33
## **Turn on automated investigation and remediation**
44

5-
As a global administrator or security administrator:
5+
As a Global Administrator or Security Administrator:
66

77
1. In the navigation pane, select **Settings > Endpoints**.
88

99
1. In the General section, select **Advanced features**.
1010

11-
1. Turn on both Automated Investigation and Automatically resolve alerts.
11+
1. Turn on **Automatically resolve alerts**.
12+
13+
> [!NOTE]
14+
> The **Automated Investigation** option is gone from the advanced features setting in Defender for Endpoint. Automated investigation is now enabled by default.
15+
16+
1. Select the **Save preferences** button.
1217

1318
## Set up device groups
1419

@@ -24,7 +29,7 @@ As a global administrator or security administrator:
2429

2530
- In the Devices section, use one or more conditions to identify and include devices.
2631

27-
- On the User access tab, select the Azure Active Directory groups that should have access to the device group you're creating.
32+
- On the User access tab, select the Entra ID groups that should have access to the device group you're creating.
2833

2934
1. Select **Done** when you're finished setting up your device group.
3035

@@ -74,5 +79,4 @@ Using the no automation option isn't recommended because it reduces the security
7479

7580
## Quickly configure remediation levels on device groups
7681

77-
Another way to set or update remediation levels on Device groups is in the Settings, General, Auto remediation page. The page provides a list of Device groups and the current remediation level for each. Select the row will allow you to adjust the remediation setting.
78-
82+
Another way to set or update remediation levels on Device groups is in the Settings, General, Auto remediation page. The page provides a list of Device groups and the current remediation level for each. Selecting the row allows you to adjust the remediation setting.
Lines changed: 45 additions & 45 deletions
Original file line numberDiff line numberDiff line change
@@ -1,45 +1,45 @@
1-
### YamlMime:Module
2-
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint
3-
metadata:
4-
title: Configure and manage automation using Microsoft Defender for Endpoint
5-
description: "Configure and manage automation using Microsoft Defender for Endpoint"
6-
ms.date: 1/2/2025
7-
author: wwlpublish
8-
ms.author: kelawson
9-
ms.topic: module
10-
ms.service: azure
11-
title: Configure and manage automation using Microsoft Defender for Endpoint
12-
summary: Learn how to configure automation in Microsoft Defender for Endpoint by managing environmental settings.
13-
abstract: |
14-
Upon completion of this module, the learner will be able to:
15-
- Configure advanced features of Microsoft Defender for Endpoint
16-
- Manage automation settings in Microsoft Defender for Endpoint
17-
prerequisites: |
18-
Intermediate understanding of Windows 10.
19-
iconUrl: /training/achievements/configure-manage-automation-microsoft-defender-endpoint.svg
20-
levels:
21-
- intermediate
22-
roles:
23-
- security-operations-analyst
24-
products:
25-
- m365
26-
- m365-security-center
27-
- windows-11
28-
- windows-security
29-
- defender-endpoint
30-
- intune
31-
- entra-id
32-
subjects:
33-
- information-protection-governance
34-
- threat-protection
35-
- automation
36-
units:
37-
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.introduction
38-
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.configure-advanced-features
39-
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.upload-folder-settings
40-
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.configure-automated-investigation-remediation-capabilities
41-
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.block-at-risk-devices
42-
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.knowledge-check
43-
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.summary-resources
44-
badge:
45-
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.badge
1+
### YamlMime:Module
2+
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint
3+
metadata:
4+
title: Configure and manage automation using Microsoft Defender for Endpoint
5+
description: "Configure and manage automation using Microsoft Defender for Endpoint"
6+
ms.date: 03/31/2025
7+
author: wwlpublish
8+
ms.author: kelawson
9+
ms.topic: module
10+
ms.service: azure
11+
title: Configure and manage automation using Microsoft Defender for Endpoint
12+
summary: Learn how to configure automation in Microsoft Defender for Endpoint by managing environmental settings.
13+
abstract: |
14+
Upon completion of this module, the learner will be able to:
15+
- Configure advanced features of Microsoft Defender for Endpoint
16+
- Manage automation settings in Microsoft Defender for Endpoint
17+
prerequisites: |
18+
Intermediate understanding of Windows 10.
19+
iconUrl: /training/achievements/configure-manage-automation-microsoft-defender-endpoint.svg
20+
levels:
21+
- intermediate
22+
roles:
23+
- security-operations-analyst
24+
products:
25+
- m365
26+
- m365-security-center
27+
- windows-11
28+
- windows-security
29+
- defender-endpoint
30+
- intune
31+
- entra-id
32+
subjects:
33+
- information-protection-governance
34+
- threat-protection
35+
- automation
36+
units:
37+
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.introduction
38+
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.configure-advanced-features
39+
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.upload-folder-settings
40+
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.configure-automated-investigation-remediation-capabilities
41+
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.block-at-risk-devices
42+
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.knowledge-check
43+
- learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.summary-resources
44+
badge:
45+
uid: learn.wwl.configure-manage-automation-microsoft-defender-for-endpoint.badge

0 commit comments

Comments
 (0)