|
| 1 | +You're a Security Operations Analyst working at a company that deployed both Microsoft Defender XDR and Microsoft Sentinel. You need to prepare for the Unified Security Operations Platform connecting Microsoft Sentinel to Defender XDR. |
| 2 | + |
| 3 | +In this exercise, you perform the following tasks: |
| 4 | + |
| 5 | +- Install the Microsoft Defender XDR Content Hub solution. |
| 6 | +- Deploy the Microsoft Sentinel connector to connect Microsoft Sentinel to Microsoft Defender XDR. |
| 7 | +- Connect Microsoft Sentinel to Microsoft Defender XDR. |
| 8 | +- Explore the Microsoft Sentinel capabilities in the Microsoft Defender XDR portal. |
| 9 | + |
| 10 | +> [!NOTE] |
| 11 | +>The environment for this exercise is a simulation generated from the product. As a limited simulation, links on a page may not be enabled and text-based inputs that fall outside of the specified script may not be supported. A pop-up message displays stating, "This feature isn't available within the simulation." When this occurs, select OK and continue the exercise steps. |
| 12 | +> |
| 13 | +> |
| 14 | +>:::image type="content" source="../media/simulation-pop-up-error.png" alt-text="Screenshot of pop-up screen indicating that this feature isn't available within the simulation."::: |
| 15 | +
|
| 16 | +### Task 1: Connect Defender XDR |
| 17 | + |
| 18 | +In this task, you deploy the Microsoft Defender XDR connector. |
| 19 | + |
| 20 | +1. In the Microsoft Edge browser, open the simulated environment by selecting this link: **[Azure portal]( https://app.highlights.guide/start/1c894b46-4b0a-40cb-b0f0-1e1c86c615f3?token=16d48b6c-eace-4a1f-8050-098d29d23a89)**. |
| 21 | + |
| 22 | +1. In the Search bar of the Azure portal, type *Sentinel*, then select **Microsoft Sentinel**. |
| 23 | + |
| 24 | +1. On the *Microsoft Sentinel* page, select the **Woodgrove-LogAnalyiticWorkspace** Workspace. |
| 25 | + |
| 26 | +1. In the Microsoft Sentinel navigation menu, scroll down to and expand the **Content management** section. Then select **Content Hub**. |
| 27 | + |
| 28 | +1. In the *Content hub*, search for the **Microsoft Defender XDR** solution and select it from the list. |
| 29 | + |
| 30 | +1. On the *Microsoft Defender XDR* solution details page, select **Install**. |
| 31 | + |
| 32 | +1. When the installation completes, search for the **Microsoft Defender XDR** solution and select it. |
| 33 | + |
| 34 | +1. On the *Microsoft Defender XDR* solution details page, select **Manage** |
| 35 | + |
| 36 | +1. Select the *Microsoft Defender XDR* Data connector check-box, and select **Open connector page**. |
| 37 | + |
| 38 | +1. In the *Configuration* section, under the *Instructions* tab, select the **Connect incidents & alerts** button. |
| 39 | + |
| 40 | +1. You should see a message that the connection was successful. |
| 41 | + |
| 42 | +### Task 2: Connect Microsoft Sentinel and Microsoft Defender XDR |
| 43 | + |
| 44 | +In this task, you continue with the simulation and connect a Microsoft Sentinel workspace to Microsoft Defender XDR. |
| 45 | + |
| 46 | +1. Navigate back to the Microsoft Sentinel *Content Hub* (using the "breadcrumb" menu link at the top of the page), and select **Overview (Preview)** from the navigation menu General section. |
| 47 | + |
| 48 | +1. Select the **Learn more** button on the *Get your SIEM and XDR in one place* message. |
| 49 | + |
| 50 | + :::image type="content" source="../media/siem-xdr-learn-more.png" alt-text="Screen capture of SIEM and XDR Learn more button message." lightbox="../media/siem-xdr-learn-more.png"::: |
| 51 | + |
| 52 | +1. Selecting the **Learn more** button opens a new tab in the browser for the *Microsoft Defender XDR* portal. |
| 53 | + |
| 54 | +1. On the **Defender Defender** portal **Home** screen, you should see a banner at the top with the message, *Get your SIEM and XDR in one place*. Select the **Connect a workspaces** button. |
| 55 | + |
| 56 | + :::image type="content" source="../media/siem-xdr-connect-workspace.png" alt-text="Screen capture of Defender XDR Connect a workspace button." lightbox="../media/siem-xdr-connect-workspace.png"::: |
| 57 | + |
| 58 | +1. On the *Choose a workspace* page, select the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace. |
| 59 | + |
| 60 | +1. Select the **Next** button. |
| 61 | + |
| 62 | +1. On the **Set a primary workspace** page, you should see the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace in the drop-down menu. Select the **Next** button. |
| 63 | + |
| 64 | +1. On the *Review and finish* page, verify that the *Workspace* selection is correct and review the bulleted items under the *What to expect when the workspace is connected* section. Select the **Connect** button. |
| 65 | + |
| 66 | +1. You should see a *You're about to connect a workspace* message. Select the **Connect** button. |
| 67 | + |
| 68 | +1. You should now be on the *Workspace successfully connected* page. |
| 69 | + |
| 70 | +1. Select the **Close** button. |
| 71 | + |
| 72 | + :::image type="content" source="../media/successfully-connected-close-button.png" alt-text="Screen capture of the Defender XDR workspace successfully connected page." lightbox="../media/successfully-connected-close-button.png"::: |
| 73 | + |
| 74 | +1. On the **Defender XDR** portal **Home** screen, you should see a banner at the top with the message, *Your unified SIEM and XDR is ready*. Select the **Start Hunting** button. |
| 75 | + |
| 76 | +1. In *Advanced hunting*, you should see a message to "Explore your content from Microsoft Sentinel". In the *Advanced hunting* navigation menu, you can find the *Microsoft Sentinel* tables, functions, and queries under the corresponding tabs. |
| 77 | + |
| 78 | +1. Scroll down under the **Schema** tab to the **Microsoft Sentinel** heading, and then double-click the **ThreatIntelligenceIndicator** table. |
| 79 | + |
| 80 | +1. In the *Query* pane, you should see a (KQL) query that returns threat intelligence indicators. Select the **Run query** button. |
| 81 | + |
| 82 | + :::image type="content" source="../media/advanced-hunting-sentinel-query.png" alt-text="Screen capture of Defender XDR Sentinel Advanced hunting tables." lightbox="../media/advanced-hunting-sentinel-query.png"::: |
| 83 | + |
| 84 | +1. Expand the left main menu pane if collapsed and expand the new **Microsoft Sentinel** menu items. You should see *Search*, *Threat management*, *Content management*, and *Configuration* selections. |
| 85 | + |
| 86 | + > [!NOTE] |
| 87 | + > Be aware that there are capability differences between the Azure Microsoft Sentinel portal and Sentinel in the Microsoft Defender XDR portal **[Portal capability differences](/azure/sentinel/microsoft-sentinel-defender-portal#capability-differences-between-portals)**. |
| 88 | +
|
| 89 | +1. From the Microsoft Defender XDR **Microsoft Sentinel** menu items, then select **Configuration** and then **Data connectors**. |
| 90 | + |
| 91 | +1. In the *Data connectors* page, you should see the **Azure Activity** and other data connectors listed with a status of **Connected**. |
| 92 | + |
| 93 | +> [!NOTE] |
| 94 | +> Feel free to explore and compare the other Microsoft Sentinel capabilities, but as this is a simulation, your ability to explore Microsoft Sentinel in the Microsoft Defender portal is limited. In a real environment, you would be able to explore the full Microsoft Sentinel capabilities in the Microsoft Defender portal. |
0 commit comments