Skip to content

Commit 6120d77

Browse files
committed
fix
1 parent 231df0f commit 6120d77

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

learn-pr/wwl-sci/security-copilot-exercises/includes/8-explore-embedded-defender-xdr.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@ In this exercise, you investigate an incident in Microsoft Defender XDR. As part
33
> [!NOTE]
44
> The environment for this exercise is a simulation generated from the product. As a limited simulation, links on a page may not be enabled and text-based inputs that fall outside of the specified script may not be supported. A pop-up message displays stating, "This feature is not available within the simulation." When this occurs, select OK and continue the exercise steps.
55
>
6+
>
67
>:::image type="content" source="../media/simulation-pop-up-error.png" alt-text="Screenshot of pop-up screen indicating that this feature isn't available within the simulation.":::
78
89

@@ -13,7 +14,7 @@ For this exercise, you're logged in as Avery Howard and have the Copilot owner r
1314
This exercise should take approximately **30** minutes to complete.
1415

1516
> [!NOTE]
16-
> When a lab instruction calls for opening a link to the simulated environment, we recommended that you open the link in a new browser window so that you can simultaneously view the instructions and the exercise environment. To do so, select the right mouse key and select the option.
17+
> When a lab instruction calls for opening a link to the simulated environment, it's recommended that you open the link in a new browser window so that you can simultaneously view the instructions and the exercise environment. To do so, select the right mouse key and select the option.
1718
1819
#### Task: Explore Incident summary and guided responses
1920

@@ -43,7 +44,7 @@ This exercise should take approximately **30** minutes to complete.
4344

4445
1. There's much information on the page, so to get a better view of this alert, select **Open alert page**. It's on the third panel on the alert page, next to the incident graph and below the alert title.
4546

46-
1. On the top of the page, is card for the device parkcity-win10v. Select the ellipses and note the options. Select **Summarize**. Copilot generates a **Device summary**. It's worth nothing that there are many ways you can access device summary and this way is just one convenient method. The summary shows the device is a VM, identifies the owner of the device, it shows its compliance status against Intune policies, and more.
47+
1. On the top of the page, is card for the device **parkcity-win10v**. Select the ellipses and note the options. Select **Summarize**. Copilot generates a **Device summary**. It's worth nothing that there are many ways you can access device summary and this way is just one convenient method. The summary shows the device is a VM, identifies the owner of the device, it shows its compliance status against Intune policies, and more.
4748

4849
1. Next to the device card is a card for the owner of the device. Select **parkcity\jonaw**. The third panel on the page updates from showing details of the alert to providing information about the user. In this case, *Jonathan Wolcott*, an account executive, whose Insider risk severity is classified as *High*. These details aren't surprising given what you learned from the Copilot incident and alert summaries. Select **Summarize** to obtain an identity summary generated by Copilot.
4950

0 commit comments

Comments
 (0)