<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Microsoft Defender Archives - MODIVA</title>
	<atom:link href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/category/microsoft-defender/feed/" rel="self" type="application/rss+xml" />
	<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/category/microsoft-defender/</link>
	<description>Become a Tech Leader with Guided Learning</description>
	<lastBuildDate>Sun, 09 Mar 2025 22:41:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>/wp-content/uploads/2025/02/cropped-fav-150x150.webp</url>
	<title>Microsoft Defender Archives - MODIVA</title>
	<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/category/microsoft-defender/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Microsoft 365 Defender delivers unified XDR experience to GCC, GCC High and DoD customers</title>
		<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/microsoft-365-defender-delivers-unified-xdr-experience-to-gcc-gcc-high-and-dod-customers/</link>
					<comments>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/microsoft-365-defender-delivers-unified-xdr-experience-to-gcc-gcc-high-and-dod-customers/#respond</comments>
		
		<dc:creator><![CDATA[Patrick]]></dc:creator>
		<pubDate>Fri, 08 Apr 2022 12:54:32 +0000</pubDate>
				<category><![CDATA[Microsoft Defender]]></category>
		<guid isPermaLink="false">http://modivasite.azurewebsites.net/?p=7090</guid>

					<description><![CDATA[<p>With persistent cyber threats and&#160;Executive Order 14028&#160;requirements announced in May 2021, there is significant pressure for government agencies to improve [&#8230;]</p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/microsoft-365-defender-delivers-unified-xdr-experience-to-gcc-gcc-high-and-dod-customers/">Microsoft 365 Defender delivers unified XDR experience to GCC, GCC High and DoD customers</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">With persistent cyber threats and&nbsp;<a href="https://www.microsoft.com/en-us/federal/CyberEO.aspx" target="_blank" rel="noreferrer noopener">Executive Order 14028</a>&nbsp;requirements announced in May 2021, there is significant pressure for government agencies to improve their security posture as well as proactively prevent and respond to attacks. Microsoft 365 Defender leverages the Microsoft 365 security portfolio to detect and help stop attacks anywhere in the kill chain. We are happy to announce that Microsoft 365 Defender is now available to GCC, GCC High and DoD customers. Microsoft 365 Defender can help government customers optimize their security by:</p>



<ul class="wp-block-list">
<li>Automatically preventing threats from accessing your organization and helping to stop attacks before they happen,&nbsp;</li>



<li>Reducing confusion, clutter and alert fatigue with a single dashboard to view prioritized incidents and one place to investigate and respond to incidents holistically,&nbsp;</li>



<li>Returning affected assets to a safe state in the broader context of an incident and automatically remediate seemingly isolated attacks.&nbsp;</li>
</ul>



<h2 class="wp-block-heading">What is Microsoft 365 Defender?&nbsp;</h2>



<p class="wp-block-paragraph">Microsoft 365 Defender provides XDR capabilities across Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity and Microsoft Defender for Cloud Apps in GCC, GCC High and DoD environments. Microsoft 365 Defender helps determine the full scope and impact of a threat by stitching together the threat signal received from each of these products. Microsoft 365 Defender can help identify initial threat entry, the scope of the issue, and how it’s currently impacting the organization. It also can take automatic action to prevent or stop the attack and self-heal affected mailboxes, endpoints, and user identities.&nbsp;</p>



<p class="wp-block-paragraph"><strong>Microsoft 365 Defender services protect:&nbsp;</strong></p>



<ul class="wp-block-list">
<li>Endpoints with Defender for Endpoint &#8211; Defender for Endpoint is a unified endpoint platform for preventative protection, post-breach detection, automated investigation, and response.&nbsp;</li>



<li>Email and collaboration with Defender for Office 365 &#8211; Defender for Office 365 safeguards your organization against malicious threats posed by email messages, links (URLs) and collaboration tools.&nbsp;</li>



<li>Identities with Defender for Identity and Azure Active Directory (Azure AD) Identity Protection &#8211; Defender for Identity uses your on-premises Active Directory Domain Services (AD DS) signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization. Azure AD Identity Protection automates the detection and remediation of identity-based risks in your cloud-based Azure AD.&nbsp;</li>



<li>Applications with Microsoft Defender for Cloud Apps &#8211; Microsoft Defender for Cloud Apps is a comprehensive cross-SaaS solution bringing deep visibility, strong data controls, and enhanced threat protection to your cloud apps.&nbsp;</li>
</ul>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/microsoft-365-defender-delivers-unified-xdr-experience-to-gcc-gcc-high-and-dod-customers/">Microsoft 365 Defender delivers unified XDR experience to GCC, GCC High and DoD customers</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/microsoft-365-defender-delivers-unified-xdr-experience-to-gcc-gcc-high-and-dod-customers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Defender for Endpoint and Defender for Cloud- which dashboard should you use?</title>
		<link>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/</link>
					<comments>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/#respond</comments>
		
		<dc:creator><![CDATA[Patrick]]></dc:creator>
		<pubDate>Fri, 08 Apr 2022 11:58:12 +0000</pubDate>
				<category><![CDATA[Microsoft Defender]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">http://modivasite.azurewebsites.net/?p=7081</guid>

					<description><![CDATA[<p>Microsoft Defender for Servers is a plan that is part of Microsoft Defender for Cloud. When you enable Microsoft Defender [&#8230;]</p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/">Defender for Endpoint and Defender for Cloud- which dashboard should you use?</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Microsoft Defender for Servers is a plan that is part of Microsoft Defender for Cloud. When you enable Microsoft Defender for Servers, you get a range of awesome functionality designed to protect your servers, including file integrity monitoring, adaptive application control, just in time access, among others.</p>



<p class="wp-block-paragraph">One additional capability that comes included with Defender for Servers is Microsoft Defender for Endpoint. See more details about the integrated solution here.</p>



<h2 class="wp-block-heading">Background</h2>



<p class="wp-block-paragraph">One advantage of this native integration is the centralization of alerts, in other words, when an alert is triggered by MDE, it will be surfaced in the Microsoft Defender for Cloud / Security Alerts dashboard</p>



<p class="wp-block-paragraph">If you select one alert, you can get more details about it and take action on the alert to start your investigation or remediation of it. You can also click on the link to be brought directly to the Microsoft 365 portal to investigate the alerts there.</p>



<p class="wp-block-paragraph">Which dashboard should you look at?</p>



<p class="wp-block-paragraph">As you can see, these alerts can be investigated from both dashboards of Microsoft Defender for Servers in the Azure Portal and from Microsoft Defender for Endpoint in Microsoft 365 Defender.</p>



<p class="wp-block-paragraph">So which dashboard should you use?</p>



<p class="wp-block-paragraph">The answer is your choice and lies entirely with how your Information Security Team is consuming the alerts and managing the devices.</p>



<p class="wp-block-paragraph">However, we can give you some guidance on best practises that we have seen to work with many customers.</p>



<p class="wp-block-paragraph">A SIEM is the recommended started point for investigation for all Defender for Cloud alerts (not just those coming from MDE).</p>



<p class="wp-block-paragraph">Note: You might see duplicate alerts in Microsoft Sentinel, coming from Microsoft defender for Cloud and Defender for Endpoint. This is a known behaviour if Defender for Endpoint sensor was onboarded via Defender for Cloud.</p>



<p class="wp-block-paragraph">In the absence of a SIEM and if you’re a general SOC team doing the investigation (not focused on just endpoints), we recommend that you start your investigation of alerts on Microsoft Defender for Cloud, and you can easily go to Microsoft 365 Defender to further your hunt via Defender for Endpoint.</p>



<p class="wp-block-paragraph">On the other hand, if you’re a team who focuses entirely on endpoints who are doing the investigation of the alerts, then you can use just the Microsoft 365 Portal.</p>



<p class="wp-block-paragraph">In summary, you can use whichever dashboard or method you choose to investigate the alerts, but you can decide based on the criteria listed above.</p>



<p class="wp-block-paragraph"><strong><em>Culled from Microsoft Blogs</em></strong></p>



<p class="wp-block-paragraph"><a href="https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/defender-for-endpoint-and-defender-for-cloud-which-dashboard/ba-p/3279558#"></a></p>
<p>The post <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/">Defender for Endpoint and Defender for Cloud- which dashboard should you use?</a> appeared first on <a href="https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net">MODIVA</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://modiva-d4a9aehgcbcfh5b3.westus2-01.azurewebsites.net/defender-for-endpoint-and-defender-for-cloud-which-dashboard-should-you-use/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
