Skip to content

Commit e096e40

Browse files
author
Ken Lawson
committed
Updated unit per Global Admn audit
1 parent bd0a1db commit e096e40

9 files changed

+19
-19
lines changed

learn-pr/wwl-sci/perform-actions-device-microsoft-defender-for-endpoint/1-introduction.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
description: "Introduction"
77
ms.date: 11/28/2023
88
author: wwlpublish
9-
ms.author: bneeb
9+
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false
1212
labModal: false

learn-pr/wwl-sci/perform-actions-device-microsoft-defender-for-endpoint/2-understand-device-actions.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
description: "Explain device actions"
77
ms.date: 11/28/2023
88
author: wwlpublish
9-
ms.author: bneeb
9+
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false
1212
labModal: false

learn-pr/wwl-sci/perform-actions-device-microsoft-defender-for-endpoint/3-run-microsoft-defender-antivirus-scan-on-devices.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
description: "Run Microsoft Defender antivirus scan on devices"
77
ms.date: 11/28/2023
88
author: wwlpublish
9-
ms.author: bneeb
9+
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false
1212
labModal: false

learn-pr/wwl-sci/perform-actions-device-microsoft-defender-for-endpoint/4-collect-investigation-package-from-devices.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
description: "Collect investigation package from devices"
77
ms.date: 11/28/2023
88
author: wwlpublish
9-
ms.author: bneeb
9+
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false
1212
labModal: false

learn-pr/wwl-sci/perform-actions-device-microsoft-defender-for-endpoint/5-initiate-live-response-session.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -4,9 +4,9 @@ title: Initiate live response session
44
metadata:
55
title: Initiate live response session
66
description: "Initiate live response session"
7-
ms.date: 11/28/2023
7+
ms.date: 04/01/2025
88
author: wwlpublish
9-
ms.author: bneeb
9+
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false
1212
labModal: false

learn-pr/wwl-sci/perform-actions-device-microsoft-defender-for-endpoint/6-knowledge-check.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
description: "Knowledge check"
77
ms.date: 11/28/2023
88
author: wwlpublish
9-
ms.author: bneeb
9+
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false
1212
labModal: false

learn-pr/wwl-sci/perform-actions-device-microsoft-defender-for-endpoint/7-summary-resources.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
description: "Summary and resources"
77
ms.date: 11/28/2023
88
author: wwlpublish
9-
ms.author: bneeb
9+
ms.author: kelawson
1010
ms.topic: unit
1111
azureSandbox: false
1212
labModal: false

learn-pr/wwl-sci/perform-actions-device-microsoft-defender-for-endpoint/includes/5-initiate-live-response-session.md

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
Live response provides security operations teams instantaneous access to a device using a remote shell connection. Live response provides you the power to do in-depth investigation and take immediate response actions to promptly contain identified threats.
1+
Live response provides security operations teams instantaneous access to a device using a remote shell connection. Live response provides you with the power to do in-depth investigation and take immediate response actions to promptly contain identified threats.
22

33
Live response is designed to enhance investigations by enabling your security operations team to collect forensic data, run scripts, send suspicious entities for analysis, remediate threats, and proactively hunt for emerging threats.
44

@@ -22,21 +22,21 @@ Before you can start a session on a device, make sure you fulfill the following
2222

2323
**Verify that you're running a supported version of Windows 10 or later**
2424

25-
Enable live response from the settings page. You'll need to enable the live response capability in the Advanced features settings page.
25+
You need to enable the live response capability in the Advanced features settings page.
2626

27-
Only users with manage security or global admin roles can edit these settings.
27+
Only users with **Manage Portal Settings** permissions can enable these settings.
2828

2929
**Ensure that the device has an Automation Remediation level assigned to it**
3030

31-
You'll need to enable, at least, the minimum Remediation Level for a given Device Group. Otherwise you can't establish a Live Response session to a member of that group.
31+
You need to enable, at least, the minimum Remediation Level for a given Device Group. Otherwise you can't establish a Live Response session to a member of that group.
3232

3333
**Enable live response unsigned script execution (optional)**
3434

35-
Allowing the use of unsigned scripts may increase your exposure to threats. Running unsigned scripts isn't recommended as it can increase your exposure to threats. If you must use them however, you'll need to enable the setting in the Advanced features settings page.
35+
Allowing the use of unsigned scripts may increase your exposure to threats. Running unsigned scripts isn't recommended as it can increase your exposure to threats. If you must use them however, you need to enable the setting in the Advanced features settings page.
3636

3737
**Ensure that you have the appropriate permissions**
3838

39-
Only users who have been provisioned with the appropriate permissions can initiate a session. The option to upload a file to the library is only available to users with the appropriate Role-based access control (RBAC) permissions. The button is greyed out for users with only delegated permissions. Depending on the role that's been granted to you, you can run basic or advanced live response commands. Users' permissions are controlled by RBAC custom role.
39+
Only users who have been provisioned with the appropriate permissions can initiate a session. The option to upload a file to the library is only available to users with the appropriate Role-based access control (RBAC) permissions. The button is greyed out for users with only delegated permissions. Depending on the role that's been granted to you, you can run basic or advanced live response commands. Users' permissions are controlled by RBAC custom role.
4040

4141
## Live response dashboard overview
4242

@@ -93,7 +93,7 @@ The following commands are available for user roles that are granted the ability
9393
| Command| Description|
9494
| :--- | :--- |
9595
| analyze| Analyses the entity with various incrimination engines to reach a verdict.|
96-
| getfile| Gets a file from the device. This command has a prerequisite command. You can use the -auto command with getfile to automatically run the prerequisite command.|
96+
| getfile| Gets a file from the device. This command has a prerequisite command. You can use the -auto command with getfile to automatically run the prerequisite command.|
9797
| run| Runs a PowerShell script from the library on the device.|
9898
| library| Lists files that were uploaded to the live response library.|
9999
| putfile| Puts a file from the library to the device. Files are saved in a working folder and are deleted when the device restarts by default.|
@@ -135,7 +135,7 @@ Here are some examples:
135135

136136
### Put a file in the library
137137

138-
Live response has a library where you can put files in. The library stores files (such as scripts) that can be run in a live response session at the tenant level. Live response allows PowerShell scripts to run. However, you must first put the files into the library before you can run them. You can have a collection of PowerShell scripts that can run on devices that you initiate live response sessions with.
138+
Live response has a library where you can put files in. The library stores files (such as scripts) that can be run in a live response session at the tenant level. Live response allows PowerShell scripts to run. However, you must first put the files into the library before you can run them. You can have a collection of PowerShell scripts that can run on devices that you initiate live response sessions with.
139139

140140
To upload a file in the library:
141141

@@ -159,7 +159,7 @@ Anytime during a session, you can cancel a command by pressing CTRL + C.
159159

160160
### Automatically run prerequisite commands
161161

162-
Some commands have prerequisite commands to run. If you don't run the prerequisite command, you'll get an error. For example, running the download command without *fileinfo* will return an error. You can use the auto flag to automatically run prerequisite commands, for example:
162+
Some commands have prerequisite commands to run. If you don't run the prerequisite command, you get an error. For example, running the download command without *fileinfo* will return an error. You can use the auto flag to automatically run prerequisite commands, for example:
163163

164164
```console
165165
getfile c:\Users\user\Desktop\work.txt -auto
@@ -168,7 +168,7 @@ getfile c:\Users\user\Desktop\work.txt -auto
168168

169169
### Run a PowerShell script
170170

171-
Before you can run a PowerShell script, you must first upload it to the library. After uploading the script to the library, use the **run** command to run the script. If you plan to use an unsigned script in the session, you'll need to enable the setting in the Advanced features settings page.
171+
Before you can run a PowerShell script, you must first upload it to the library. After uploading the script to the library, use the **run** command to run the script. If you plan to use an unsigned script in the session, you need to enable the setting in the Advanced features settings page.
172172

173173
### Apply command parameters
174174

learn-pr/wwl-sci/perform-actions-device-microsoft-defender-for-endpoint/index.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ uid: learn.wwl.perform-actions-device-microsoft-defender-for-endpoint
33
metadata:
44
title: Perform actions on a device using Microsoft Defender for Endpoint
55
description: "Perform actions on a device using Microsoft Defender for Endpoint"
6-
ms.date: 3/13/2024
6+
ms.date: 04/01/2025
77
author: wwlpublish
88
ms.author: kelawson
99
ms.topic: module

0 commit comments

Comments
 (0)