Microsoft 365 Security Center Mdi
In brief
The page now refers to Microsoft Defender instead of Microsoft Defender XDR and updates the alert-tuning description to say it improves threat detection coverage throughout your system.
What Defender admins need to know
Use the updated terminology when referencing this documentation. No administrator action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Applies to:
- What is Microsoft
Defender XDR?Defender? - Microsoft Defender for Identity
Microsoft Defender for Identity is part of the Microsoft Defender portal, the home for monitoring and managing security across your Microsoft identities, data, devices, apps, and infrastructure. The Microsoft Defender portal allows security admins to perform their security tasks in one location, which simplifies workflows and integrating functionality from other Microsoft Defender XDR services.
Microsoft Defender for Identity contributes identity focused information into the incidents and alerts that the Microsoft Defender portal presents. This information is key to providing context and correlating alerts from the other products within Microsoft Defender XDR.Defender.
| Area | Description |
|---|---|
| Alert and incident correlation | Defender for Identity alerts is now included in the Microsoft Defender portal's alert queue, making them available to the automated incident correlation feature. View all of your alerts in one place, and determine the scope of the breach even quicker than before. For more information, see Investigate Defender for Identity alerts in the Microsoft Defender portal. |
| Alert exclusions | The Microsoft Defender portal's alert interface is more user friendly, and includes a search function and global exclusions, meaning you can exclude any entity from all alerts generated by Defender for Identity. For more information, see Configure Defender for Identity detection exclusions in Microsoft Defender. |
| Alert tuning | Alert tuning, previously known as alert suppression, allows you to adjust and optimize your alerts. Alert tuning reduces false positives, allowing your SOC teams to focus on high-priority alerts, and improves threat detection coverage In Microsoft |
| Remediation actions | Defender for Identity remediation actions, such as disabling accounts or requiring password resets, are available from the Microsoft Defender portal user details page. For more information, see Remediation actions in Microsoft Defender for Identity. |
Quick reference for legacy portal users
@@ -20,12 +20,12 @@ ms.custom: admindeeplinkDEFENDER, defender-for-identity **Applies to:** -- What is Microsoft Defender XDR?+- What is Microsoft Defender? - [Microsoft Defender for Identity](/defender-for-identity/) -Microsoft Defender for Identity is part of the Microsoft Defender portal, the home for monitoring and managing security across your Microsoft identities, data, devices, apps, and infrastructure. The Microsoft Defender portal allows security admins to perform their security tasks in one location, which simplifies workflows and integrating functionality from other Microsoft Defender XDR services.+Microsoft Defender for Identity is part of the Microsoft Defender portal, the home for monitoring and managing security across your Microsoft identities, data, devices, apps, and infrastructure. The Microsoft Defender portal allows security admins to perform their security tasks in one location, which simplifies workflows and integrating functionality from other Microsoft Defender services. -Microsoft Defender for Identity contributes identity focused information into the incidents and alerts that the Microsoft Defender portal presents. This information is key to providing context and correlating alerts from the other products within Microsoft Defender XDR.+Microsoft Defender for Identity contributes identity focused information into the incidents and alerts that the Microsoft Defender portal presents. This information is key to providing context and correlating alerts from the other products within Microsoft Defender. <a name='converged-experiences-in-microsoft-365-defender'></a> @@ -67,8 +67,8 @@ The following sections describe enhanced Defender for Identity features found in |Area |Description | |---------|---------| | **Alert and incident correlation** |Defender for Identity alerts is now included in the Microsoft Defender portal's alert queue, making them available to the automated incident correlation feature. <br><br>View all of your alerts in one place, and determine the scope of the breach even quicker than before. <br><br>For more information, see [Investigate Defender for Identity alerts in the Microsoft Defender portal](/defender-for-identity/manage-security-alerts). |-| **Alert exclusions** |The Microsoft Defender portal's alert interface is more user friendly, and includes a search function and global exclusions, meaning you can exclude any entity from all alerts generated by Defender for Identity. <br><br>For more information, see [Configure Defender for Identity detection exclusions in Microsoft Defender XDR](/defender-for-identity/exclusions).|-| **Alert tuning** |Alert tuning, previously known as *alert suppression*, allows you to adjust and optimize your alerts. Alert tuning reduces false positives, allowing your SOC teams to focus on high-priority alerts, and improves threat detection coverage across your system.<br><br> In Microsoft Defender XDR, create rule conditions based on evidence types, and then apply your rule on any rule type that matches your conditions. For more information, see [Tune an alert](/defender-xdr/investigate-alerts#tune-an-alert).|+| **Alert exclusions** |The Microsoft Defender portal's alert interface is more user friendly, and includes a search function and global exclusions, meaning you can exclude any entity from all alerts generated by Defender for Identity. <br><br>For more information, see [Configure Defender for Identity detection exclusions in Microsoft Defender](/defender-for-identity/exclusions).|+| **Alert tuning** |Alert tuning, previously known as *alert suppression*, allows you to adjust and optimize your alerts. Alert tuning reduces false positives, allowing your SOC teams to focus on high-priority alerts, and improves threat detection coverage throughout your system.<br><br> In Microsoft Defender, create rule conditions based on evidence types, and then apply your rule on any rule type that matches your conditions. For more information, see [Tune an alert](/defender-xdr/investigate-alerts#tune-an-alert).| | **Remediation actions** |Defender for Identity remediation actions, such as disabling accounts or requiring password resets, are available from the Microsoft Defender portal user details page. <br><br>For more information, see [Remediation actions in Microsoft Defender for Identity](/defender-for-identity/remediation-actions). ## Quick reference for legacy portal users 