Microsoft Unified SecOps Platform
Architecture and deployment

Deploy Microsoft Security Services for Unified Security Operations

In brief

The article’s title, metadata, and wording were updated to clarify deployment planning, Microsoft security services, Sentinel workspace and resource-group guidance, and RBAC recommendations.

What Defender admins need to know

Administrators have clearer guidance for planning and deploying unified security operations; no required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Deploy Microsoft security services for unified security operations

The Microsoft Defender portal provides unified security operations withbrings together Microsoft Defender XDR, Microsoft Sentinel, and other services. Together,services for unified security operations. Use Defender portal services provideto get a comprehensivefull view of your organization's security posture and helps you toposture. You can detect, investigate, and respond to threats across your organization.

Microsoft Security Exposure Management and Microsoft Threat Intelligence are available in any environment that meets the prerequisites, to users configured with required permissions.

Prerequisites

Deploy Microsoft Defender XDR services

Microsoft Defender XDR unifies incident response by integrating key capabilities across services, includingservices. These services include Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity. This unified experienceMicrosoft Defender XDR adds powerful features you can access in the Microsoft Defender portal.

  1. Microsoft Defender XDR automatically turns on when eligible customers with the required permissions visit Microsoft Defender portal. For more information, see Turn on Microsoft Defender XDR.

Configure Microsoft Entra ID Protection

Microsoft Defender XDR can ingest and include signals from Microsoft Entra ID Protection, whichProtection. This service evaluates risk data from billions of sign-in attempts and evaluatesscores the risk of each sign-in to your environment. Microsoft Entra ID Protectionuses this data is used by Microsoft Entra ID to allow or preventblock account access, dependingbased on how Conditional Access policies are configured.

Configure Microsoft Entra ID Protection to enhance your security posture and add Microsoft Entra signals to your unified security operations. For more information, see Configure your Microsoft Entra ID Protection policies.

Onboard to Microsoft Security Copilot

Onboard to Microsoft Security Copilot to enhance your security operations by leveragingwith advanced AI capabilities.AI. Security Copilot assists in threat detection, investigation,helps you detect, investigate, and response, providing actionablerespond to threats. It provides insights and recommendations to help you stay ahead of potential threats.risks. Use Security Copilot to automate routine tasks, reduce the time to detect and respond to incidents,response times, and improve the overall efficiency of your security team.

For more information, see Get started with Security Copilot.

Architect your workspace and onboard to Microsoft Sentinel

The first step in using Microsoft Sentinel is to create a Log Analytics workspace, if you don't have one already. A single Log Analytics workspace might be sufficientenough for many environments, but manyenvironments. However, some organizations create multiple workspaces to optimizereduce costs and better meet different business requirements.needs. The Defender portal supports a primary workspace and multiple secondary workspaces.

  1. Create a Security resource group for governance purposes, which allows you to isolate Microsoft Sentinel resources and role-based access to the collection.resource group.
  2. Create a Log Analytics workspace in the Security resource group and onboard Microsoft Sentinel into it.

For more information, see Onboard Microsoft Sentinel and Multiple Microsoft Sentinel workspaces in the Defender portal.

Configure roles and permissions

Provision your users based on your documented roles and permissions access plan. To comply withfollow Zero Trust principles, we recommend that you use role-based access control (RBAC) to providegive each user access only to the resources that are allowed and relevant for each user, instead of providingthey need. Don't provide access to the entire environment.

[!INCLUDE mininum-access-requirements]

Onboard to the Defender portal

When you onboardOnboard Microsoft Sentinel to the Defender portal, you unify capabilitiesportal to combine it with Microsoft Defender XDR likeXDR. This gives you unified incident management and advanced hunting for unified security operations.hunting. For more information, see Connect Microsoft Sentinel to Microsoft Defender.

Fine-tune system configurations

Enable health and auditing

Monitor the health and audit the integrity of supported Microsoft Sentinel resources by turningTurn on the auditing and health monitoring feature in the Microsoft Sentinel's Settings page. This feature monitors the health and integrity of supported Microsoft Sentinel resources. Get insights on health drifts, such as the latestrecent failure events or changes from success to failure states, and onstates. You can also track unauthorized actions,actions and use health monitoring andthe audit data to create notifications and other automated actions.

For more information, seeTurn on auditing and health monitoring for Microsoft Sentinel.

Configure Microsoft Sentinel content

Use the Microsoft Threat Intelligence analytics rule

Enable the out-of-the-box Microsoft Threat Intelligence analytics rule and verify that the ruleit matches your log data with Microsoft-generated threat intelligence. For more information, see Detect threats with threat indicator analytics. Microsoft has a vast repository of threat intelligence data, and this analyticdata. The Microsoft Threat Intelligence analytics rule uses a subset of itthat data to generate high high-fidelity alerts and incidents for SOC (security operations centers) teams to triage.

Avoid duplicate incidents

With fusion, anomaly, and threat intelligence analytic rules enabled, conduct a MITRE Att&ck crosswalk to help you decide which remaining analytic rules to enable and to finish implementing a mature XDR (extended detection and response) process. This empowers you to detect and respond throughout the lifecycle of an attack.

For more information, see Understand security coverage.