Microsoft Defender XDR
Architecture and deployment

Step 1. Plan for Microsoft Defender XDR operations readiness

In brief

The page date and authoring metadata were updated, and descriptions of SOC device monitoring and readiness-assessment guidance were reworded for clarity.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Step 1. Plan for Microsoft Defender XDR operations readiness

Centralize monitoring and logging of your organization's security sources

Usually, the SOC team's core function is to make sure all security devices such asare working correctly and being monitored. These devices include firewalls, intrusion prevention systems, data loss prevention systems, vulnerability management systems, and identity systems are functioning correctly and being monitored.systems. The SOC teams work with the broader network operations teams, such as identity, DevOps, cloud, application, data science, and other business teams to ensure the analysis ofteams. Together, they make sure that security information analysis is centralized and secured. Additionally, theThe SOC team is responsible for maintainingalso maintains logs of the data in useableusable and readable formats, which couldformats. This work can include parsing and normalizing disparatedifferent data formats.

Establish Red, Blue, and Purple team operational readiness

Next step

As the next step in this series,For guidance on assessing SOC integration readiness, see Perform a SOC integration readiness assessment using the Zero Trust Framework. [!INCLUDE Microsoft Defender XDR rebranding]