Skip to content

Commit 51cc81e

Browse files
Merge pull request #51129 from KenMAG/main
Added new simulation exercise unit to module 3rd PR try
2 parents d497354 + c0712df commit 51cc81e

17 files changed

+132
-14
lines changed

learn-pr/wwl-sci/.openpublishing.redirection.wwl-sci.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -377,6 +377,16 @@
377377
"redirect_url": "https://learn.microsoft.com/training/modules/configure-siem-security-operations-using-microsoft-sentinel/7-summary/",
378378
"redirect_document_id": false
379379
},
380+
{
381+
"source_path_from_root": "/learn-pr/wwl-sci/integrate-microsoft-defender-xdr-with-microsoft-sentinel/6-knowledge-check.yml",
382+
"redirect_url": "https://learn.microsoft.com/en-us/training/modules/integrate-microsoft-defender-xdr-with-microsoft-sentinel/knowledge-check/",
383+
"redirect_document_id": false
384+
},
385+
{
386+
"source_path_from_root": "/learn-pr/wwl-sci/integrate-microsoft-defender-xdr-with-microsoft-sentinel/7-summary.yml",
387+
"redirect_url": "https://learn.microsoft.com/training/modules/integrate-microsoft-defender-xdr-with-microsoft-sentinel/summary/",
388+
"redirect_document_id": false
389+
},
380390
{
381391
"source_path": "learn-pr/wwl-azure/purview-implement-manage-retention/auto-apply-retention-label.md",
382392
"redirect_url": "/training/modules/purview-manage-records/auto-apply-retention-label",
Loading
-130 Bytes
Loading

learn-pr/wwl-sci/integrate-microsoft-defender-xdr-with-microsoft-sentinel/4-onboarding-sentinel-to-defender-xdr.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,8 +4,8 @@ title: Onboarding Microsoft Sentinel to Microsoft Defender XDR
44
metadata:
55
title: Onboarding Microsoft Sentinel to Microsoft Defender XDR
66
description: "Onboarding Microsoft Sentinel to Microsoft Defender XDR."
7-
ms.date: 10/2/2024
8-
author: wwlpublish
7+
ms.date: 6/25/2025
8+
author: KenMAG
99
ms.author: kelawson
1010
ms.topic: unit
1111
durationInMinutes: 15

learn-pr/wwl-sci/integrate-microsoft-defender-xdr-with-microsoft-sentinel/includes/4-onboarding-sentinel-to-defender-xdr.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ But, before you begin, make sure you have completed the following steps and have
44

55
## Prerequisites
66

7-
The Microsoft Defender portal supports a single Microsoft Entra tenant and the connection to one workspace at a time. In the context of this article, a workspace is a Log Analytics workspace with Microsoft Sentinel enabled.
7+
The Microsoft Defender portal supports a single Microsoft Entra tenant and the connection to a primary workspace and multiple secondary workspaces. In the context of this article, a workspace is a Log Analytics workspace with Microsoft Sentinel enabled.
88

99
To onboard and use Microsoft Sentinel in the Microsoft Defender portal, you must have the following resources and access:
1010

Lines changed: 94 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,94 @@
1+
You're a Security Operations Analyst working at a company that deployed both Microsoft Defender XDR and Microsoft Sentinel. You need to prepare for the Unified Security Operations Platform connecting Microsoft Sentinel to Defender XDR.
2+
3+
In this exercise, you perform the following tasks:
4+
5+
- Install the Microsoft Defender XDR Content Hub solution.
6+
- Deploy the Microsoft Sentinel connector to connect Microsoft Sentinel to Microsoft Defender XDR.
7+
- Connect Microsoft Sentinel to Microsoft Defender XDR.
8+
- Explore the Microsoft Sentinel capabilities in the Microsoft Defender XDR portal.
9+
10+
> [!NOTE]
11+
>The environment for this exercise is a simulation generated from the product. As a limited simulation, links on a page may not be enabled and text-based inputs that fall outside of the specified script may not be supported. A pop-up message displays stating, "This feature isn't available within the simulation." When this occurs, select OK and continue the exercise steps.
12+
>
13+
>
14+
>:::image type="content" source="../media/simulation-pop-up-error.png" alt-text="Screenshot of pop-up screen indicating that this feature isn't available within the simulation.":::
15+
16+
### Task 1: Connect Defender XDR
17+
18+
In this task, you deploy the Microsoft Defender XDR connector.
19+
20+
1. In the Microsoft Edge browser, open the simulated environment by selecting this link: **[Azure portal]( https://app.highlights.guide/start/1c894b46-4b0a-40cb-b0f0-1e1c86c615f3?token=16d48b6c-eace-4a1f-8050-098d29d23a89)**.
21+
22+
1. In the Search bar of the Azure portal, type *Sentinel*, then select **Microsoft Sentinel**.
23+
24+
1. On the *Microsoft Sentinel* page, select the **Woodgrove-LogAnalyiticWorkspace** Workspace.
25+
26+
1. In the Microsoft Sentinel navigation menu, scroll down to and expand the **Content management** section. Then select **Content Hub**.
27+
28+
1. In the *Content hub*, search for the **Microsoft Defender XDR** solution and select it from the list.
29+
30+
1. On the *Microsoft Defender XDR* solution details page, select **Install**.
31+
32+
1. When the installation completes, search for the **Microsoft Defender XDR** solution and select it.
33+
34+
1. On the *Microsoft Defender XDR* solution details page, select **Manage**
35+
36+
1. Select the *Microsoft Defender XDR* Data connector check-box, and select **Open connector page**.
37+
38+
1. In the *Configuration* section, under the *Instructions* tab, select the **Connect incidents & alerts** button.
39+
40+
1. You should see a message that the connection was successful.
41+
42+
### Task 2: Connect Microsoft Sentinel and Microsoft Defender XDR
43+
44+
In this task, you continue with the simulation and connect a Microsoft Sentinel workspace to Microsoft Defender XDR.
45+
46+
1. Navigate back to the Microsoft Sentinel *Content Hub* (using the "breadcrumb" menu link at the top of the page), and select **Overview (Preview)** from the navigation menu General section.
47+
48+
1. Select the **Learn more** button on the *Get your SIEM and XDR in one place* message.
49+
50+
:::image type="content" source="../media/siem-xdr-learn-more.png" alt-text="Screen capture of SIEM and XDR Learn more button message." lightbox="../media/siem-xdr-learn-more.png":::
51+
52+
1. Selecting the **Learn more** button opens a new tab in the browser for the *Microsoft Defender XDR* portal.
53+
54+
1. On the **Defender Defender** portal **Home** screen, you should see a banner at the top with the message, *Get your SIEM and XDR in one place*. Select the **Connect a workspaces** button.
55+
56+
:::image type="content" source="../media/siem-xdr-connect-workspace.png" alt-text="Screen capture of Defender XDR Connect a workspace button." lightbox="../media/siem-xdr-connect-workspace.png":::
57+
58+
1. On the *Choose a workspace* page, select the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace.
59+
60+
1. Select the **Next** button.
61+
62+
1. On the **Set a primary workspace** page, you should see the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace in the drop-down menu. Select the **Next** button.
63+
64+
1. On the *Review and finish* page, verify that the *Workspace* selection is correct and review the bulleted items under the *What to expect when the workspace is connected* section. Select the **Connect** button.
65+
66+
1. You should see a *You're about to connect a workspace* message. Select the **Connect** button.
67+
68+
1. You should now be on the *Workspace successfully connected* page.
69+
70+
1. Select the **Close** button.
71+
72+
:::image type="content" source="../media/successfully-connected-close-button.png" alt-text="Screen capture of the Defender XDR workspace successfully connected page." lightbox="../media/successfully-connected-close-button.png":::
73+
74+
1. On the **Defender XDR** portal **Home** screen, you should see a banner at the top with the message, *Your unified SIEM and XDR is ready*. Select the **Start Hunting** button.
75+
76+
1. In *Advanced hunting*, you should see a message to "Explore your content from Microsoft Sentinel". In the *Advanced hunting* navigation menu, you can find the *Microsoft Sentinel* tables, functions, and queries under the corresponding tabs.
77+
78+
1. Scroll down under the **Schema** tab to the **Microsoft Sentinel** heading, and then double-click the **ThreatIntelligenceIndicator** table.
79+
80+
1. In the *Query* pane, you should see a (KQL) query that returns threat intelligence indicators. Select the **Run query** button.
81+
82+
:::image type="content" source="../media/advanced-hunting-sentinel-query.png" alt-text="Screen capture of Defender XDR Sentinel Advanced hunting tables." lightbox="../media/advanced-hunting-sentinel-query.png":::
83+
84+
1. Expand the left main menu pane if collapsed and expand the new **Microsoft Sentinel** menu items. You should see *Search*, *Threat management*, *Content management*, and *Configuration* selections.
85+
86+
> [!NOTE]
87+
> There are capability differences between the Azure Microsoft Sentinel portal and Sentinel in the Microsoft Defender XDR portal **[Portal capability differences](/azure/sentinel/microsoft-sentinel-defender-portal#capability-differences-between-portals)**.
88+
89+
1. From the Microsoft Defender XDR **Microsoft Sentinel** menu items, then select **Configuration** and then **Data connectors**.
90+
91+
1. In the *Data connectors* page, you should see the **Azure Activity** and other data connectors listed with a status of **Connected**.
92+
93+
> [!NOTE]
94+
> Feel free to explore and compare the other Microsoft Sentinel capabilities, but as this is a simulation, your ability to explore Microsoft Sentinel in the Microsoft Defender portal is limited. In a real environment, you would be able to explore the full Microsoft Sentinel capabilities in the Microsoft Defender portal.

learn-pr/wwl-sci/integrate-microsoft-defender-xdr-with-microsoft-sentinel/index.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ uid: learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel
33
metadata:
44
title: Integrate Microsoft Defender XDR with Microsoft Sentinel
55
description: "In this module, you learn how to integrate Microsoft Defender XDR with Microsoft Sentinel."
6-
ms.date: 04/23/2025
6+
ms.date: 06/25/2025
77
author: KenMAG
88
ms.author: kelawson
99
ms.topic: module
@@ -39,7 +39,8 @@ units:
3939
- learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.3-capability-differences-between-portals
4040
- learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.4-onboarding-sentinel-to-defender-xdr
4141
- learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.5-exploring-sentinel-features-in-defender-xdr
42-
- learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.6-knowledge-check
43-
- learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.7-summary
42+
- learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.simulation-exercise-deploy-sentinel-to-defender
43+
- learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.knowledge-check
44+
- learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.summary
4445
badge:
4546
uid: learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.badge

learn-pr/wwl-sci/integrate-microsoft-defender-xdr-with-microsoft-sentinel/6-knowledge-check.yml renamed to learn-pr/wwl-sci/integrate-microsoft-defender-xdr-with-microsoft-sentinel/knowledge-check.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,17 @@
11
### YamlMime:ModuleUnit
2-
uid: learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.6-knowledge-check
2+
uid: learn.wwl.integrate-microsoft-defender-xdr-with-microsoft-sentinel.knowledge-check
33
title: Module assessment
44
metadata:
55
title: Module assessment
66
description: "Knowledge check."
7-
ms.date: 10/2/2024
8-
author: wwlpublish
7+
ms.date: 06/26/2025
8+
author: KenMAG
99
ms.author: kelawson
1010
ms.topic: unit
1111
module_assessment: true
1212
durationInMinutes: 10
1313
content: |
14-
[!include[](includes/6-knowledge-check.md)]
14+
[!include[](includes/knowledge-check.md)]
1515
quiz:
1616
title: Check your knowledge
1717
questions:

0 commit comments

Comments
 (0)