Microsoft Defender XDR
General

Highlight security impact and achievements with the unified security summary

In brief

The documentation date and metadata were updated, and descriptions and links for detection, protection, investigation, response, and Copilot metrics were clarified.

What Defender admins need to know

Administrators get clearer terminology and navigation when using the documentation. No action is indicated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Highlight security impact and achievements with the unified security summary

[!INCLUDE Microsoft Defender XDR rebranding]

Security operations center (SOC) teams can easily showcase their security achievements and the impact of Microsoft Defender using the unified security summary. Having the summary readily available in the Microsoft Defender portal streamlines the process for SOC teams to generate security reports, saving time usually spent on collecting data from various sources and creating reports tailored to their audiences. SOC teams can readily communicate performance and achievements to their stakeholders with the unified security summary.

The unified security summary highlights the following information:

  • Posture: Your organization’s posture includes data from Microsoft Secure Score, threat protection information related to ransomware and phishing prevention, exposure score based on Microsoft Defender Vulnerability Management, and the number of onboarded devices to Microsoft Defender for Endpoint :::image type="content" source="media/security-summary-report/summary-posture-small.png" alt-text="Screenshot of the Posture section in the security summary report" lightbox="media/security-summary-report/summary-posture.png":::
  • Detection: This section contains the number of incidents and alerts overview, including how many alerts were consolidated into incidents, the number of alerts grouped into incidents, and information on active detection rules and the corresponding response actions produced by those rules :::image type="content" source="media/security-summary-report/summary-detection-small.png" alt-text="Screenshot of the Detection section in the security summary report" lightbox="media/security-summary-report/summary-detection.png":::
  • Protection: Cards under this section include data from Microsoft’s automatic investigation and response features like the total number of automatic attack disruptions, a list of the disruption incidents, the number of malicious activities blocked by Microsoft Defender Antivirus, and the number of malicious emails and URLs blocked :::image type="content" source="media/security-summary-report/summary-protection-small.png" alt-text="Screenshot of the Protection section in the security summary report" lightbox="media/security-summary-report/summary-protection.png":::
  • Investigation and response: This section contains the number of active and resolved alerts and incidents, top 10 critical incidents with each incident’s status and affected number of assets, the number of automated investigation and response in Microsoft Defender actions taken on impacted assets, and the number of email messages where malicious files were automatically identified and extracted through Microsoft Defender for Office 365 Zero-hour auto purge (ZAP) :::image type="content" source="media/security-summary-report/summary-investigation-small.png" alt-text="Screenshot of the Investigation and Response section in the security summary report" lightbox="media/security-summary-report/summary-investigation.png":::
  • Copilot-powered investigation and response: This section contains the number of file analysis in Copilot in Defender and script analysis in Copilot in Defender operations where Microsoft Copilot in Defender was used. :::image type="content" source="media/security-summary-report/summary-copilot-small.png" alt-text="Screenshot of the Copilot section in the security summary report" lightbox="media/security-summary-report/summary-copilot.png":::

SOC teams can use the unified security summary to highlight the impact of their day-to-day operations. They can also emphasize how Microsoft’s automated actions impact the efficient protection of their organization with features like automatic attack disruption stoppingdisruption, which stops attacks before it becomesthey become widespread.

Prerequisites

:::image type="content" source="media/security-summary-report/duration-picker.png" alt-text="Screenshot highlighting the report data duration options in the security summary report"::: 4. Once the summary is generated, you can check the details of each card under each section.

  1. You can export the summary as a PDF or CSV file. To export, select the dropdown menu on the upper right corner of the page and choose the format. :::image type="content" source="media/security-summary-report/export-picker.png" alt-text="Screenshot highlighting the export options in the security summary report":::
  2. If you choose to export the summary as a PDF, an option to customize by adding a logo of your choice is available. Select Upload logo to add a logo to the PDF. Otherwise, you can select Generate PDF to proceed exporting the summary to a PDF file.