Microsoft Unified SecOps Platform
General

customer intent: As a security operations center leader, I want to learn about the services and features available in the Microsoft Defender portal f…

In brief

The overview page was revised to describe automatic attack disruption as containing attacks, limiting lateral movement, and reducing impact. The page date and authoring metadata were also updated.

What Defender admins need to know

No administrator action is indicated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Standard cybersecurity metrics focus on the time to detect (TTD) and time to respond (TTR). Time to detect (TTD) measures how long it takes security teams to discover an incident. Time to respond (TTR) measures the amount of time it takes to respond after a threat is detected. The shorter the TTD and TTR, the more effective your detection, and response strategy is.

The Microsoft Defender portal correlates millions of signals from Defender products, Microsoft Sentinel, Microsoft security research, and threat intelligence to identify attacks in progress. It initiates automatic attack disruption to automatically contain attacks, limiting lateral movement early and reducing attack impact. Automatic attack disruption contains attacks to limit lateral movement and reduce their impact. This response helps to reduce costs associated withproductivity loss of productivity, provide control toand gives the SecOpssecurity operations team controltime to investigate and remediate compromised assets.

Automatic attack disruption responds to threats by containing devices and containing or disabling users to mitigate attacks.