diff --git a/solutions/security/cloud/integrations/microsoft-defender-xdr.md b/solutions/security/cloud/integrations/microsoft-defender-xdr.md new file mode 100644 index 0000000000..e9ed6ef0c1 --- /dev/null +++ b/solutions/security/cloud/integrations/microsoft-defender-xdr.md @@ -0,0 +1,23 @@ +--- +applies_to: + stack: all + serverless: + security: all +products: + - id: security + - id: cloud-serverless +--- + +# Microsoft Defender XDR + +This page explains how to make data from the Microsoft Defender XDR integration appear in the following places within {{elastic-sec}}: + +- **Findings page**: Data appears on the [Vulnerabilities](/solutions/security/cloud/findings-page-3.md) tab. +- **Alert and Entity details flyouts**: Data appears in the Insights section of the [Alert](/solutions/security/detect-and-alert/view-detection-alert-details.md#insights-section) and [Entity](/solutions/security/advanced-entity-analytics/view-entity-details.md#insights) details flyouts. + + +In order for Microsoft Defender XDR data to appear in these workflows: + +* Follow the steps to [set up the Microsoft Defender XDR integration](https://www.elastic.co/docs/reference/integrations/m365_defender). +* Make sure the integration version is at least 4.0.0. +* Ensure you have `read` privileges for the following index: `security_solution-*.vulnerability_latest`. \ No newline at end of file diff --git a/solutions/toc.yml b/solutions/toc.yml index ef97a90f9c..df8afd1ee0 100644 --- a/solutions/toc.yml +++ b/solutions/toc.yml @@ -685,6 +685,8 @@ toc: - file: security/cloud/integration-rapid7.md - file: security/cloud/integrations/aws-config-integration.md - file: security/cloud/integrations/microsoft-defender-for-cloud.md + + - file: security/cloud/integrations/microsoft-defender-xdr.md - file: security/cloud/integrations/google-security-command-center.md - file: security/investigate.md children: