This repository was archived by the owner on Sep 8, 2026. It is now read-only.
Commit 2f51dff
Resolve syncing conflicts from repo_sync_working_branch to public (#597)
* Fix issues noted in AI remediation work (9 of 10) (#9105)
* Fix issues noted in AI remediation work (9 of 10)
* Fix errors
* Restore original documentation formatting
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c22decca-6bd3-48ab-b340-3ac7ecc42866
* Restore remaining original formatting
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c22decca-6bd3-48ab-b340-3ac7ecc42866
* Restore underline markup
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: c22decca-6bd3-48ab-b340-3ac7ecc42866
* Update detect-and-remediate-outlook-rules-forms-attack.md
---------
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Copilot-Session: c22decca-6bd3-48ab-b340-3ac7ecc42866
* [mac] What's new for 101.26062.0012 (#9111)
* [mac] What's new for 101.26062.0009
* [mac] What's new for 101.26062.0011
* Add macOS AI discovery release note
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: a576e3ad-0fec-474f-9f6c-516dfdec8789
* [mac] whatsnew 101.26062.0012
---------
Co-authored-by: j0shbregman <joshbregman@microsoft.com>
Copilot-Session: a576e3ad-0fec-474f-9f6c-516dfdec8789
* Update README (#9113)
Per public PR https://github.com/MicrosoftDocs/defender-docs/pull/581
* First seen at field behavior
* tamper protection audit mode public preview documentation (#9116)
* tamper protection audit mode public preview documentation
* added images
* removed appendix content
* fixed images
* fixing
* fixing
* adding two more images
* fixing images
* final edit
* preview tag
* what's new entries
* final edits
* fix bash
* fix command it test a tampering scen
* fixing link in whats new
* fixing link in whats new
* tabs in releases page
* edited linux preference page
* fixed audit mode version
* release notes
* fixing syntax
* removed release notes pivot changes
* fix
* updated Defender for Endpoint release notes
* Revert "tamper protection audit mode public preview documentation (#9116)" (#9123)
This reverts commit a617229a447f8a905689b3296142569f383abdcc.
* Update Protection & posture insights report details (#9124)
Feature is GA - removed note about report being in Preview with limited availability.
@chrisda for review.
* Update attack-simulation-training-simulation-automations.md (#9125)
Updates per email request
* First Contact Safety Tip clarification (#9127)
* Update attack-simulation-training-simulation-automations.md
Updates per email request
* Update anti-phishing-policies-about.md
First Contact Safety Tip clarification per email request
* Defender catch-up scan updates- #20678 (#9128)
* Defender catch-up scan updates- #20678
Per <https://github.com/MicrosoftDocs/defender-docs/issues/537>
* Clarify Defender catch-up scan behavior
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add CVE details ARG schema release note
* Clarify CVE details ARG data consumption update
* Clarify CVE details ARG update already happened
* Remove retirement clarification sentence
* Update Logstash DCR article for output plugin v2.5.0
- Bump plugin to v2.5.0 and update RubyGems links
- Add Logstash 9.3.3 and 9.4.0; add security-update links for affected versions
- Rename config params: client_id, client_secret, dcr_id, stream_name
- Rewrite managed identity section around DefaultAzureCredential; remove invalid managed_identity/managed_identity_object_id
- Replace optional configuration table and add changelog entries through 2.5.0
- Update known issues to reference new waiting-time variables
* More catch-up scan updates (#9132)
* Defender catch-up scan updates- #20678
Per <https://github.com/MicrosoftDocs/defender-docs/issues/537>
* Clarify Defender catch-up scan behavior
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* More catchup scan updates
From: https://github.com/MicrosoftDocs/defender-docs/issues/537. Also did copy/technical/consistency edits on schedule-antivirus-scans-intune and use-intune-config-manager-microsoft-defender-antivirus
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Learn Editor: Update release-notes.md
* Learn Editor: Update release-notes.md
* Updated First seen at field description
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* Remove password protection preview labels
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 28174cd6-9878-4f1c-97f8-6dfc88d22241
* Updated CVE details tenant scope guidance
* Update email-authentication-dkim-configure.md (#9145)
* Update email-authentication-dkim-configure.md
correction
* Update email-authentication-dkim-configure.md
---------
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
* Document automatic auditing for non-DC identity servers (#9136)
* Document automatic auditing for non-DC servers
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 55a93760-c6f7-43b7-8938-dade4d7461a6
* Update whats-new.md
---------
Copilot-Session: 55a93760-c6f7-43b7-8938-dade4d7461a6
* reapplied tamper protection audit mode public preview documentation
* Update outbound-spam-restore-restricted-users.md (#9153)
Updates per email request.
* updated agentless machine scanning guidance (#9151)
* updated agentless machine scanning guidance
* updated agentless scanning section links
* Fix issues noted in AI remediation work (10 of 10) (#9154)
* Fix issues noted in AI remediation work (10 of 10)
* Restore Office 365 article formatting
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Update configure-junk-email-settings-on-exo-mailboxes.md
* Fix formatting of Set-MailboxJunkEmailConfiguration cmdlet
Updated formatting for cmdlet name in the Junk Email settings documentation.
* Improve cmdlet formatting in connection filter policy doc
Updated formatting for cmdlet name in PowerShell section.
* Refine email clustering analysis description
---------
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Update advanced-hunting-devicelogonevents-table (#9155)
* Update outbound-spam-restore-restricted-users.md
Updates per email request.
* Update advanced-hunting-devicelogonevents-table.md
Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/8701
* Update sentinel-siem-application-card.md (#9156)
Updates per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9000
* Nested API support (#9157)
Per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9001
* Retirement of contanerized SAP agent (#9158)
Per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9043
* .aspx link fixes (#9161)
* Retirement of contanerized SAP agent
Per Issue https://github.com/MicrosoftDocs/defender-docs-pr/issues/9043
* .aspx link fixes
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* update transition recs page (#9165)
* update transition recs page
* removed note from review page
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* Learn Editor: Update microsoft-defender-endpoint-releases.md
* Learn Editor: Update ai-model-security.md
* Add Remote tenant group (GDAP) option to URBAC custom role assignment
Documents the new Remote tenant group option in the Add assignment side pane, enabling GDAP-based cross-tenant URBAC assignment. Target go-live: 2026-08-31. Resubmission of public PR MicrosoftDocs/defender-docs#579 per @v-regandowner's guidance.
* removed tamper protection page
* removing release note
* Update accounts.md (#9169)
* Learn Editor: Update accounts.md
* Learn Editor: Update accounts.md
* Update deprecation notice for data risk graph
* Platform fixes from SME review (#8852)
* Platform fixes from SME review
* Fix warnings
* Update anti-spam-bulk-complaint-level-bcl-about.md (#9171)
* Update anti-spam-bulk-complaint-level-bcl-about.md
* Update anti-spam-bulk-complaint-level-bcl-about.md
* Link updates/fixes (#9175)
* Update anti-spam-bulk-complaint-level-bcl-about.md
* Update anti-spam-bulk-complaint-level-bcl-about.md
* Update release-notes-mde-archive.md
Formatting and link fixes
* Link updates
* Build report fixes
* Article alignment (#9176)
Intune procedures standardization and copy/technical edits.
* Update date and improve clarity in overview
Updated the date for the Codename MDASH overview and refined the wording in the 'Prepare' section for clarity.
* Add CallActivityEvents advanced hunting schema reference (#8949)
* Add CallActivityEvents hunting schema reference
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2879d2fb-b4ab-490b-96cb-e11e4735efe6
* Address CallActivityEvents review feedback
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Apply suggestion from @Stacyrch140
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Stacy Chambers <102548089+Stacyrch140@users.noreply.github.com>
Copilot-Session: 2879d2fb-b4ab-490b-96cb-e11e4735efe6
* Update ms.date and remove deletion note (#9178)
Bump ms.date to 07/01/2026 and remove the sentence claiming that existing Teams meetings, chats, channels, and calls are deleted after adding a block entry. This clarifies the Tenant Allow/Block List guidance in defender-office-365/tenant-allow-block-list-teams-domains-configure.md.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 91c4341f-a0c5-4d2a-9caf-7a91f19f5ba8
* Clarify Teams mailbox requirements for user reporting (#9179)
* Clarify Teams mailbox requirements
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0008fc20-c9b1-4711-96d3-3c2ea1cc6dd2
* Clarify reporting mailbox restrictions
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 0008fc20-c9b1-4711-96d3-3c2ea1cc6dd2
---------
Copilot-Session: 0008fc20-c9b1-4711-96d3-3c2ea1cc6dd2
* Update android-configure (#9188)
Consolidated redundant Intune procedures, copy edit and technical edit.
* Remove line break tag (#9190)
* Chrisda to Main (#9191)
* Update android-configure
Consolidated redundant Intune procedures, copy edit and technical edit.
* Update android-configure.md
* Intune policy standardization
* Update configure-cloud-block-timeout-period-microsoft-defender-antivirus.md
Intune policy standardization, Defender portal policy standardization, and added missing PowerShell procedure.
* Revert "Add Remote tenant group (GDAP) option to URBAC custom role assignment"
* Learn Editor: Update mdash-foundry-integration.md
* Update alerts-mdi-classic.md (#9197)
* Learn Editor: Update alerts-mdi-classic.md
* Learn Editor: Update alerts-mdi-classic.md
* Update alerts-xdr.md (#8902)
* Learn Editor: Update alerts-xdr.md
* Learn Editor: Update alerts-xdr.md
* Learn Editor: Update fixed-reported-inaccuracies.md (#9185)
* Document the DLP to Purview migration tool and non-Microsoft app support (#9203)
Add a section covering the DLP to Purview migration tool: prerequisites,
supported scope, the four wizard steps, post-migration review in Purview,
FAQ, known issues, and wizard screenshots.
Add a Non-Microsoft app support section listing the SaaS apps Purview DLP
supports (Box, Dropbox, Google Workspace, Salesforce) with prerequisites
and a pointer to the Purview documentation.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add known limitation for Teams launched from proxied Google Workspace sessions
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Learn Editor: Update advanced-hunting-datasecuritybehaviors-table.md
* Learn Editor: Update advanced-hunting-datasecuritybehaviors-table.md
* Learn Editor: Update defender-sensor-change-log.md
* Learn Editor: Update defender-sensor-change-log.md
* Learn Editor: Update ai-code-security-onboarding.md
* Learn Editor: Update mdash-foundry-integration.md
* Learn Editor: Update mdash-foundry-integration.md
* Learn Editor: Update mdash-foundry-integration.md
* Learn Editor: Update ai-code-security-onboarding.md
* Learn Editor: Update ai-code-security-onboarding.md
* Learn Editor: Update whats-new.md
* Learn Editor: Update whats-new.md
* Learn Editor: Update ai-code-security-onboarding.md
* Learn Editor: Update whats-new.md
* Learn Editor: Update mdash-foundry-integration.md
* Add Remote tenant group (GDAP) option to URBAC custom role assignment
Documents the Remote tenant group option in the Add assignment side pane, enabling GDAP-based cross-tenant URBAC assignment. Feature is live for customers today (2026-08-31) per Eng green light. Resubmission after revert PR #9195.
* Update remediate-vulnerability-findings-vm.md (#9205)
* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live
* Merge for Defender deployment tool GA announcement (#8099)
* Selective Response Actions: update from preview to GA
- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Deleted preview references, got rid of current ga behavior.
* Mentioned the zip / exe choice
* Added what's new entry
* Updated date
* Updated date
* Enhance Sentinel graph visualization documentation (#7904)
* Enhance Sentinel graph visualization documentation
Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.
* Fix formatting and enhance graph visualization section
* Update graph-visualization.md
* docauthoring:copy/edit updates
* updates
* fix
---------
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>
* Updated published docs with latest contributions (#8824)
* Update identity remediation actions for unified multi-connector support
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Make identity actions section generic and reference remediation actions page
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Use comma-separated values for supported identity sources column
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Update roles table with connector columns for identity providers and SaaS apps
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Add MDA roles for SaaS apps column and SOC Identity Responder role
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Remove Deactivate and Set account risk actions
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Add Entra ID roles for Force password change action
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Add SOC Identity Responder to Entra ID column for response actions
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Reference required permissions page for identity provider column
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Add SOC Identity Responder to Defender for Identity response actions permissions
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Clarify identity actions span connectors across on-prem, Entra ID, IAM, and SaaS
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Trim identity actions view details to account settings only
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Fix Supported actions table: remove stray SOC role and link column
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Remove SOC Identity Responder from Enable action (not supported)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
* Learn Editor: Update alerts-containers.md
* Learn Editor: Update alerts-containers.md
* Remove AI Agent write access classification
Removed the description for AI agents with privileged business system write access from the predefined classifications section.
* Learn Editor: Update ai-threat-protection.md
* Move account correlation rules under Settings (#8793)
* Move account correlation rules under settings
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313
* Adjust account correlation navigation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313
* Use full account correlation screenshot
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313
* Restore original account correlation screenshot
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313
* Resize account correlation screenshot
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313
---------
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313
---------
Co-authored-by: izauer-bit <76057672+izauer-bit@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: EyalGur74 <160857568+EyalGur74@users.noreply.github.com>
Co-authored-by: Sapir Schneider <296893019+SapirSchneiderService@users.noreply.github.com>
Co-authored-by: Liran Levy <309411196+liran-levy3@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>
Copilot-Session: e7ad5eb8-f209-4290-bb0e-05ce954fe256
Copilot-Session: 89d66bfa-446b-4532-bb81-7aaafa1e4313
* OOB publish for sync PR (#8976)
* Docs: soft rebrand Defender XDR → Defender (batch 612-6) (#8027)
* Docs: soft rebrand Defender XDR → Defender (batch 612-6)
Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 20 files. Protected references (metadata, includes, UI navigation, image alt text, detection source names, acronym definitions, XDR detection engine names) are preserved.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Roll back changes.
Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back Changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Fix conflict.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
* Confirm merge from repo_sync_working_branch to main to sync with https://github.com/MicrosoftDocs/defender-docs (branch public) (#7591)
* Add custom graph cost management link in graph charges section
* Update mdb-faq.yml
Updating public documentation because numerous support cases have been opened due to documentation being unclear. Government customers are not included in this section and should be clarified for customers when trying to understand what licensing is required.
* Initialize Docs repository: https://github.com/MicrosoftDocs/defender-docs-pr of branch live
* Merge for Defender deployment tool GA announcement (#8099)
* Selective Response Actions: update from preview to GA
- Remove (preview) tag from article title
- Remove (preview) from link in defender-deployment-tool-windows.md
- Add GA entry in June 2026 section of whats-new article
- Update ms.date in both articles
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Deleted preview references, got rid of current ga behavior.
* Mentioned the zip / exe choice
* Added what's new entry
* Updated date
* Updated date
* Enhance Sentinel graph visualization documentation (#7904)
* Enhance Sentinel graph visualization documentation
Clarified permissions for accessing Sentinel graphs and added details on query editor functionality. Expanded on graph visualization options and configuration settings for better user guidance.
* Fix formatting and enhance graph visualization section
* Update graph-visualization.md
* docauthoring:copy/edit updates
* updates
* fix
---------
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Danielle Dennis <dandennis@microsoft.com>
Co-authored-by: EdB-MSFT <105771311+EdB-MSFT@users.noreply.github.com>
Co-authored-by: prmerger-automator[bot] <40007230+prmerger-automator[bot]@users.noreply.github.com>
* Fix attack disruption docs: simplify TOC title and table entries (#525)
- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity
Co-authored-by: Ofer Schreiber <ofer@bigpanda.io>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Update advanced-hunting-emailattachmentinfo-table.md (#307)
Describing "FileType" as "File extension type" is misleading and can make people think of the file's extension (e.g. `.exe`) while the field is actually a file content type (e.g. `txt;text` or `email;mime` or `png`).
Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
* Update advanced-hunting-take-action.md with query reference (#406)
* Update advanced-hunting-take-action.md with query reference
Added Kusto query reference for enabling 'Submit to Microsoft' and 'Initiate automated investigation'. To make it more clear after it was raised in the community
* Potential fix for pull request finding
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
---------
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
* Update manage-event-based-updates-microsoft-defender-antivirus.md (#345)
Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
* Update with the correct GPO setting name (#365)
Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
* MDB: Update references to the onboarding (#377)
* fix: MDB, update onboarding, rename MAM to WIP
Azure Portal has slowly but progressively been moved to Entra admin center: Update the URL and the actual naming in the portal.
MAM isn't mentioned it seems to be replaced by Windows Information Protection in the same screen.
* fix: Further replace MAM occurrences by WIP
MAM wording has been removed from both the old Azure portal, as well as in Entra admin center.
* fix: MDB, add updated screenshot MDM and WIP user scopes
While the structure is mostly unchanged, add new screenshot that includes current namings and same design of selector / radio buttons.
* MDB: Include updated screenshot
Include updated screenshot and update description of the picture.
* MDB: Delete old screenshot of MEM/MAM user scope settings
New picture was added with new name, this one is now obsolete.
---------
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
* Change MDEConfig.txt to DefenderDTconfig.txt (#418)
"DefenderDT.exe -makeconfig" crates a file named DefenderDTconfig.txt instead of MDEConfig.txt
Co-authored-by: Tami Fosmark <v-tamif@microsoft.com>
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
* Update configure-network-connections-microsoft-defender-antivirus.md (#448)
Fixing broken link for https://learn.microsoft.com/en-us/windows/privacy/manage-windows-1709-endpoints#windows-update
No longer works because of ham-fisted MS redirects.
* Update advanced-hunting-microsoft-defender.md (#343)
Add to "known Issues":
When creating a new Microsoft Sentinel function in Log Analytics, there is a delay of up to 20 minutes until it appears in Advanced Hunting.
Co-authored-by: Shannon Leavitt <47186198+ShannonLeavitt@users.noreply.github.com>
* Fix grammar in Teams block entry instructions (#496)
* Fix grammar in Teams block entry instructions
Blocking a domain does not block the Teams meeting invitation itself. Blocking a domain will remove the user from the Teams meeting chat after the meeting ends. The current documentation (Teams Meetings) may be misleading as to suggest that it affects all meetings.
* Fix grammar in Teams block entry instructions
Corrected grammatical errors in the block entry explanation.
---------
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
* Clarify instructions for running Client Analyzer shipped version (#498)
* Clarify instructions for running Client Analyzer shipped version in live response
Adjust the format which is clearer for binary version and python version separately.
* Update run-analyzer-linux.md
* Fix formatting and wording in run-analyzer-linux.md
---------
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
* Update faqs-on-tamper-protection.yml (#532)
Remove bracket so link properly connects to target URL
* Update quarantine-shared-mailbox-messages.md (#528)
* Update quarantine-shared-mailbox-messages.md
Updated wording for clarity and expanded scope to include both shared and user mailboxes.
* Update quarantine management instructions and date
Updated the date for the document and refined the instructions for accessing quarantined messages in shared mailboxes.
* Update shared mailbox quarantine management instructions
Clarified that automapping is no longer required for managing quarantined messages in shared mailboxes. Updated conditions for accessing quarantined messages.
---------
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
* Resolve syncing conflicts from repo_sync_working_branch to public (#529)
* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-04) (#8059)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Fix fictional bookmarks AIRA created
Removed redundant options for enabling UEBA and streamlined the text.
* Remove bookmark to nonexistent content
Removed redundant sentence in the UEBA documentation.
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* Learn Editor: Update release-notes-recommendations-alerts.md
* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [2/2] (#8088)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 9
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Fix metadata for PIM in MDO configuration document
* Fix metadata for safe attachments configuration doc
* Update ms.custom metadata in documentation
* Fix formatting in submissions admin review document
* Fix formatting for ms.custom in documentation
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md
* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-sentinel-guywi-ms-06) (#8061)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Fix bad AIRA edit
Updated section header from 'Next steps' to 'Next step'.
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b5) (#8096)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 4
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Fix formatting of ms.custom metadata in document
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* fix(COPY-EDIT): editorial (#8060)
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* fix(COPY-EDIT): editorial (#8062)
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* fix(COPY-EDIT): batch (#8072)
Remediation for COPY-EDIT.
Files affected: 1
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* fix(COPY-EDIT): editorial (#8095)
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* Clarify that the Risky IP address category is dynamic (#8198)
* Clarify that the Risky IP category is dynamic and can expire
Add a note explaining that the Risky category is assigned automatically
based on threat intelligence and is removed if no further malicious
activity is detected. All other categories are assigned manually.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Apply suggestions from code review
Co-authored-by: AbbyMSFT <88824859+AbbyMSFT@users.noreply.github.com>
* Apply suggestion from @AbbyMSFT
* Apply suggestion from @AbbyMSFT
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Regan Downer <v-rdowner@microsoft.com>
* new onboarding (#7970)
* new onboarding
* updates
* updates
---------
Co-authored-by: Regan Downer <v-rdowner@microsoft.com>
* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-usp-test8a-mberdugo) (#8077)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 4
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Remove AIRA-duplicated ai-usage metadata
Removed 'ai-usage' line from the document header.
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* Update approval functionality (#8303)
* Update approval functionality (#8304)
* docs(sentinel): add parameterized notebook jobs
Adds overview and detailed guidance for parameterized notebook jobs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Learn Editor: Update sql-azure-vulnerability-assessment-overview.md
* WI591424: GA transition for serverless containers docs
* Restore historical preview note and keep separate GA release note
* Move June 25 GA note to top of table and section list
* Document Registry access requirement for full Serverless Containers features
* Update defender-for-cloud/release-notes.md
* Update defender-for-cloud/release-notes.md
* Mark Serverless Containers as supported in Defender portal
* Move serverless containers GA date to July 1
* Place July 1 release note under July table
* Set July 1 ms.date across remaining PR pages
* Version 26.1.1 (#8316)
* Version 26.1.1
* Fixes
* Mapping updates to transition from grouped to individual recommendations (#8151)
* Transition from grouped to individual recommendations
* Update transition article with end-state classification for deprecated assessments
- Add explanation of 3 end-states (dynamic substitute, static substitute, no substitute)
- Add End-state and New assessment ID columns to all reference tables
- Change 'NA (Static)' to 'Unknown' in Category column for static substitutes (EDR, SQL)
- Mark EDR and SQL rows as static substitutes with [TBD] new assessment IDs
- Fix HostMisconfiguration → HostMisconfigurations per category list
- Mark GitHub security posture management row as [TBD] pending DevOps partner input
- Add placeholder section for Microsoft Defender for Identity (pending partner review)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add July 31 deprecation date and clarify static substitute guidance
- Add July 31, 2026 as the grouped recommendation deprecation date
- Clarify that static substitute recommendations use 'Unknown' category
and users should filter by assessment ID, not category filter
Per meeting with Roy Hirsch (June 21, 2026)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Revert "Add July 31 deprecation date and clarify static substitute guidance"
This reverts commit c4f487921093d967d968310ed5e2773e07cf3291.
* Update grouped-to-individual recommendations article per Roy Hirsch review
- Remove IcM routing column from all tables (internal-only, not customer-facing)
- Fix ARG query field: securityCategories -> recommendationCategory
- Fix category name: 'Vulnerabilities' -> 'SoftwareUpdate' recommendation category
- Replace 'assessment key/ID' with 'recommendation ID' throughout
- Replace 'grouped assessment' with 'grouped recommendation' throughout
- Remove 'No substitute' end-state (deprecated items not included in this guide)
- Split each product table into Dynamic substitutes and Static substitutes sections
- Simplify table columns: Dynamic (Recommendation | Recommendation ID | Category),
Static (Recommendation | Recommendation ID | New recommendation ID)
- Remove IcM routing reference from intro tip and reference section
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Rename 'Recommendation category reference' to 'Recommendation transition reference'
Section now covers both dynamic (category-based) and static (recommendation ID-based)
transitions, so 'category reference' was no longer accurate.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add July 31 deprecation date to transition guides
- Add July 31, 2026 deprecation date in transition-grouped-individual-recommendations.md
(overview callout, adopting section, what you should do now callout)
- Add July 31, 2026 deprecation date in transition-disable-rules-exemptions.md
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Update transition guide with Roy's final feedback
- SQL databases/servers recs: mark as deprecated, replace static substitute table with note and link to full SQL recommendations reference
- Containers: add Azure (c609cf0f) and AWS (682b2595) running container images as dynamic substitutes mapped to SoftwareUpdate
- GitHub security posture mgmt (fd104c01): update [TBD] with link to full DevOps recommendations reference
- Linux secure boot rec (ad50b498): not added (status unknown per Roy)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Fix SQL recommendations link to point to VA rules mapping article
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Replace internal substitute terms with plain descriptions
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Apply manual edits and re-apply terminology changes
- Remove Secure Score row from comparison table
- Update vulnerability management example description
- Rename old query label and add note before new query
- Remove Secure Score during transition section
- Change EDR recs to deprecated recommendations
- Replace Dynamic/Static substitute terms with plain descriptions
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Fix terminology: replace 'Dynamic substitutes' with 'Replaced by individual recommendations' in Containers and DevOps sections; fix garbled text and table in Servers deprecated section
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Apply suggestion from @DebLanger
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* fix files moved in error (#8310)
* fix files moved in error
* fixes
* [AIRA] Bot Remediation - AbbyMSFT (defender-docs-pr, 20260615-dfi-root-b-r1) (#8073)
* fix(COPY-EDIT): batch
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Apply suggestion from @GitHubber17
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, b3) (#8094)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Fix ms.custom field formatting in documentation
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* fix(COPY-EDIT): batch (#8074)
Remediation for COPY-EDIT.
Files affected: 2
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* Restructure MDA TOC around customer journey (#7505)
* Restructure MDA TOC around customer journey
Reorganize from feature-based sections to a lifecycle flow:
Deploy > Connect and discover > Assess risk > Control and protect >
Detect threats > Investigate and respond > Stream to SIEM > Manage
Key changes:
- Dissolve app governance silo into relevant phases
- Merge 'View and manage applications' into discovery
- Merge 'Information protection' into 'Control access and protect data'
- Move AI agent protection into discovery section
- Rename SIEM section to clarify outbound direction
- Move operations guide into 'Manage and configure'
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Rename section to 'Investigate and respond to threats'
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add PR target instruction to copilot-instructions.md
Ensure PRs are always created against MicrosoftDocs/defender-docs-pr
rather than the fork.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Move app governance setup articles to appropriate sections
- 'Turn on app governance' moves into Configuration (it's a config task)
- 'Get started with app governance' moves into 'Discover and manage
OAuth apps' (it's a product walkthrough, not deployment)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Apply content audit: move articles to correct lifecycle phases
Based on full-content audit of 35 cross-cutting articles:
Moved to 'Control access and protect data':
- manage-app-permissions.md (renamed to 'Manage OAuth app permissions')
- app-governance-visibility-insights-sensitive-content.md
- governance-discovery.md
- mde-govern.md
- ai-agent-protection.md and real-time-agent-protection (AI agent protection)
Moved to 'Investigate and respond to threats':
- app-governance-anomaly-detection-alerts.md
- app-governance-investigate-predefined-policies.md
- tutorial-flow.md (response automation, not SIEM)
Kept ai-agent-inventory.md in discovery (primary entry point).
AI agent discovery stays in Connect and discover; protection moves
to Control access.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Rename discovery sections for clarity
- 'Discover cloud apps (shadow IT)' -> 'Discover cloud apps and shadow IT'
- 'Discover and manage OAuth apps' -> 'Discover and manage OAuth apps with app governance'
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Restructure MDA TOC: split discover/connect, rename access section
- Split 'Connect and discover apps' into separate 'Discover apps' and
'Connect apps' sections, with discovery first
- Rename 'Control access and protect data' to 'Manage access and app behavior'
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Consolidate app governance articles and clarify OAuth app scope in titles
- Flatten Connect apps TOC node (remove unnecessary intermediate level)
- Consolidate app governance articles:
- Merge policies overview + get-started + predefined into single overview
- Merge policies create + manage into single create-and-manage article
- Merge threat detection overview + get-started + monitor into single article
- Merge visibility insights overview + get-started into single article
- Update all app governance TOC nodes and article titles to include 'OAuth'
to distinguish from SaaS app content
- Add redirects for 6 deleted articles
- Fix all internal links to deleted articles
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Fix broken links in index.yml to deleted articles
Update references to consolidated app governance articles that were
deleted upstream.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Resolve PR review blocking issues: typos, casing, and alt-text fixes
- Fix 'polcies' typo in alt-text (app-policies-overview)
- Add graphic-type prefix to two image alt-texts (app-policies-overview)
- Lowercase 'app governance' in alt-text (detect-remediate-overview)
- Remove duplicate 'the' (secure-apps-access-non-graph-api)
- Lowercase three 'app governance' instances (anomaly-detection-alerts)
- Title case 'Zero Trust' (index.yml)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* fix(COPY-EDIT): batch (#8075)
Remediation for COPY-EDIT.
Files affected: 6
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* [AIRA] Bot Remediation - guywi-ms (defender-docs-pr, 20260615-usp-test8a-guywi) (#8076)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 7
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Update section title and content in mto-requirements.md
Renamed 'Next steps' section to 'Related content' and updated its content.
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* fix(COPY-EDIT): editorial (#8078)
Remediation for COPY-EDIT.
Files affected: 8
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-b) (#8081)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Improve formatting of simulation automation steps
Formatted the configuration steps into a bulleted list for better readability.
* Update attack-simulation-training-training-campaigns.md
* Apply suggestions from code review
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
* Update ms.custom metadata in connectors-remove-blocked.md
* Refactor ms.custom metadata in documentation
Updated ms.custom metadata to include a list format.
* Update ms.custom formatting in documentation
* Update ms.custom format in preset-security-policies.md
* Update quarantine-admin-manage-messages-files.md
* Fix formatting of ms.custom property in markdown
* Update ms.custom metadata format in markdown file
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Chris Davis <chris.davis@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
* WI590578-table-insights (#8265)
* WI590578-table-insights
* quality fixes
* additional work
* updated conceptual page
* page quality fixes
* Refine Table insights guidance and restore Data Lake terminology
* Update manage-table-tiers-retention.md
* fixes to instructions
* Update manage-table-tiers-retention.md
* quality fixes
* fix
* fix title
* small fixes
* small fixes
* fix based on Nikita's comment
actually I realized there is one more change when in Whats new section when you click on tables, you can see data sources in side drawer.
* fixing broken list
---------
Co-authored-by: Diana Richards <103777760+v-dirichards@users.noreply.github.com>
* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-d) (#8083)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 9
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Fix formatting for ms.custom in alert policies document
* Fix formatting for ms.custom in audit log document
* Fix formatting of ms.custom in documentation
* Fix formatting in connection filter policies document
* Fix formatting in connectors-detect-respond-to-compromise.md
* Remove section for new Microsoft 365 administrators
Removed unnecessary section for new Microsoft 365 administrators and related content. There were no links or anything of value. It was essentially an ad, and even that ad didn't link to anything.
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* Document AI agent awareness for Entra ID service principals
- Add Used by AI agents (Preview) column to NHI details table
- Add Used by AI agents (Preview) stat to NHI insight cards
- Add what's-new entry for AI agent visibility
Work item: 591169
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Chrisda to Main (#8323)
* Update attack-surface-reduction-rules-reference.md
Removed 'might not be available in Intune' call-out for 'Block executable files from running unless they meet a prevalence, age, or trusted list criterion'
* Update attack-surface-reduction-rules-overview.md
Consistency updates
* ASR rules report screenshot updates
More data
* Remove A3 from E3 gets MDO P1 refs
Per request
* Added Teams to report suspicious
* Update outbound-spam-high-risk-delivery-pool-about.md
Content VSO 591495
* [AIRA] Bot Remediation - dansimp (defender-docs-pr, d365-test8b-dansimp) (#8085)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 1
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Update email-analysis-investigations.md
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* [AIRA] Bot Remediation - deniseb (defender-docs-pr, d365-test8b-deniseb) (#8086)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 1
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Update authorship information in documentation
* Change section title to 'Related content'
Updated section title and added related content links.
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Denise Vangel-MSFT <deniseb@microsoft.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-f) [1/2] (#8087)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Apply suggestions from code review
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
* Fix formatting in air-report-false-positives-negatives.md
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-e) [2/2] (#8090)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 8
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Apply suggestions from code review
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
* Apply suggestion from @GitHubber17
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
* [AIRA] Bot Remediation - unowned (defender-docs-pr, em-test8d) (#8091)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 2
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Apply suggestions from code review
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
Co-authored-by: Beth Harvey <v-bharve@microsoft.com>
* fix(COPY-EDIT): editorial (#8089)
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* CFA article updates (#8149)
* Configure controlled folder access
* Added Windows Security app procedures
And removed them elsewhere
* CFA overview article rename
* CFA
* CFA Overview
* Delete customize-controlled-folders.md
* Removed CFA article from MDB
And also cleaned up ASR/ASR rule references and links, including any Intune procedure links.
* Link and link title updates for CFA
* Update address-unwanted-behaviors-mde.md
* New monitor CFA article
Remnants of the old evaluate CFA article + Windows event viewer steps/info from the CFA overview article.
* Copy and Technical edits
* CFA demonstrations
* CFA demos
* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md
* CFA/ASR demo updates
* Update defender-endpoint-demonstration-attack-surface-reduction-rules.md
* Final edits
* Offending file name renames
Per build report
* [AIRA] Bot Remediation - chrisda (defender-docs-pr, d365-test8b-c) (#8082)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Update address-compromised-users-quickly.md
* Fix formatting of ms.custom metadata in markdown
* Fix formatting of custom metadata in markdown file
* Correct 'ms.custom' formatting in documentation
Fixed formatting of the 'ms.custom' metadata entry.
* Update custom metadata in mdo-portal-permissions.md
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* fix(COPY-EDIT): editorial (#8053)
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* docs(sentinel): add parameterized notebook job guidance
Add steps for defining notebook parameters, refreshing job parameters, and overriding values when running a notebook job manually.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Docs: soft rebrand Defender XDR → Defender (batch 11) - NEW SERIES, IGNORE BATCH NUMBER (#7939)
* Docs: soft rebrand Defender XDR to Defender (batch 11)
Replace 'Defender XDR' and 'Microsoft Defender XDR' with 'Defender' and
'Microsoft Defender' in body text of 20 advanced hunting schema and
feature articles, per Microsoft Defender branding guidelines.
Preserved unchanged:
- appliesto metadata fields
- [!INCLUDE references
- ms.service and other metadata fields
- Link display text referencing external page titles
- URL paths and fragments
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Roll back changes.
* Roll back change.
Updated description to specify Microsoft Defender XDR.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
* Docs: soft rebrand Defender XDR → Defender (batch 612-2) (#8016)
* Docs: soft rebrand Defender XDR → Defender (batch 612-2)
Update 18 advanced hunting files to replace 'Defender XDR' and
'Microsoft Defender XDR' with 'Defender' and 'Microsoft Defender'
in body text per branding guidelines. Protected references
(metadata, includes, API names, historical records, plugin names)
are left unchanged.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Roll back change.
* Roll back change.
* Roll back change.
Updated the description to include 'XDR' in the title.
* Roll back change.
* Roll back changes.
Updated references to Microsoft Defender XDR in the document.
* Roll back changes.
Updated references from Microsoft Defender for Endpoint to Microsoft Defender XDR in the migration guide.
* Roll back changes.
* Roll back changes.
Updated title and references to reflect Microsoft Defender XDR.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
* Docs: soft rebrand Defender XDR → Defender (batch 612-9) (#8030)
* Docs: soft rebrand Defender XDR → Defender (batch 612-9)
Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR' with 'Defender' in body text, titles, descriptions, headings, and link display text across 10 files. 1 file had no eligible changes (all XDR refs were protected product names).
Protected references preserved: metadata fields, [!INCLUDE] lines, image alt text, historical changelog entries in whats-new.md, API endpoint names, external blog post titles, 'Defender Experts for XDR' product name, XDR capability descriptions (XDR solution, XDR tools, XDR/SIEM).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Roll back changes.
* Roll back changes.
* Roll back changes.
Updated the document to reflect the rebranding of Microsoft Defender to Microsoft Defender XDR, including changes to titles and descriptions throughout the content.
* Roll back changes.
* Roll back changes.
* Roll back changes.
* Fix typo in Microsoft Defender XDR description
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Paul Oliveria <pauloliveria@microsoft.com>
* Fix directory path and update checksum commands (#8334)
Command errors caused by folder structure or incorrect quotation/space within a zip file.
* Clarify prerequisites for attack disruption exclusions based on Unified RBAC state (#8276)
Split the Prerequisites section into Device and Identity exclusion
permissions, showing the required roles when Unified RBAC is enabled
versus disabled. Cross-link to Unified RBAC activation and custom
permissions docs.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Fix attack disruption docs: simplify TOC title and table entries (#8341)
- Shorten TOC entry from 'Attack disruption with Microsoft Sentinel' to 'Attack disruption'
- Remove redundant '(through Microsoft Sentinel integration)' from Okta and AWS IAM identity service names
- Move Microsoft Sentinel mention to Okta link text for clarity
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Update value-data-connectors.md with onboarding notes (#8254)
* Update value-data-connectors.md with onboarding notes
Added note about device onboarding requirements and limitations.
* Apply suggestion from @DebLanger
* Update date and permissions in get-machines.md (#8344)
Updated the date and permissions section in the API documentation.
* wi-589516: Remove '| Microsoft Docs' suffix from title metadata (#8255)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
* Update email post delivery events documentation
* Learn Editor: Update fixed-reported-inaccuracies.md (#8308)
* DisruptionAndResponseEvents table in the advanced hunting schema - GA (#8354)
* DisruptionAndResponseEvents table in the advanced hunting schema - GA
* Updating what's new
* Removing preview note
* Docs: soft rebrand Defender XDR → Defender (batch 2) (#8191)
* Docs: soft rebrand Defender XDR → Defender (batch 2)
Replace 'Microsoft Defender XDR' with 'Microsoft Defender' and 'Defender XDR'
with 'Defender' in eligible locations per branding guidelines.
Files updated:
- critical-asset-management.md (1 replacement)
- get-started-exposure-management.md (4 replacements)
- prerequisites.md (3 replacements)
- whats-new.md (0 - all references in historical What's New entries)
Preserved XDR references in:
- Bold UI navigation paths (prerequisites.md line 67)
- Historical What's New entries (whats-new.md lines 179, 310)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Roll back changes.
* Roll back changes.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Docs: soft rebrand Defender XDR → Defender (batch 13) (#7941)
* docs: soft rebrand Defender XDR → Defender (batch 13)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* roll back change.
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Document Security findings (Preview) Azure Policy limitation in Defender for Containers (#8350)
* Document Security findings (Preview) Azure Policy limitation in Defender for Containers
- Add limitation note to Security findings (Preview) component in AKS, EKS, and GKE tabs
stating it cannot be enabled through Azure Policy and must be toggled in plan Settings
- Rename 'Security findings' to 'Security findings (Preview)' for accuracy
- Remove 'This article explains' from opening line per style guide
Addresses US585115 / IcM 662676555 / CxE WI 19929
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Apply suggestion from @DebLanger
* Apply suggestion from @DebLanger
* Apply suggestion from @DebLanger
* Apply suggestion from @DebLanger
* Apply suggestions from code review
Co-authored-by: Deborah Langer <169067075+DebLanger@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add identity assessment key mappings to transition reference article (#8351)
* Add identity assessment key mappings to transition reference article
Replace placeholder in Microsoft Defender for Identity section with
assessment key mapping table for 5 guest/disabled account assessments.
Uses 'assessment' terminology per Roy's guidance.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Apply suggestion from @DebLanger
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* fix(COPY-EDIT): editorial (#8050)
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* fix(COPY-EDIT): editorial (#8048)
Remediation for COPY-EDIT.
Files affected: 7
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* [AIRA] Bot Remediation - mberdugo (defender-docs-pr, 20260615-sentinel-mberdugo-02) (#8047)
* fix(COPY-EDIT): editorial
Remediation for COPY-EDIT.
Files affected: 10
Applied by AI Readiness Remediation Tool v1.0.0
Assessment source: assessment.csv
* Update section title from 'Next steps' to 'Related content'
* Fix formatting of title in integration guide
---------
Co-authored-by: msec-docs-bot[bot] <258613010+msec-docs-bot[bot]@users.noreply.github.com>
Co-authored-by: Shawn Kupfer <60445862+ShawnKupfer@users.noreply.github.com>
* Cloud security reporting GA (#8267)
* Cloud security reporting GA: remove preview, add release note and card customization
- Remove (Preview) from title and H1 in cloud-security-reporting.md
- Remove preview features prerequisite
- Add card customization capability
- Add June 30 GA release note entry
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add customize cards section with screenshots to cloud reporting article
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Clarify that card customization is only for cards labeled Customizable
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Add migration guidance for Sentinel incident creation rules to Defender alert grouping (#7952)
* Add Sentinel-to-Defender alert grouping migration guidance
* Relocate Sentinel migration article to unified-secops docset
* Update migration images and include restored xdr article copy
* Remove duplicate defender-xdr migration article copy
* Update image alt text for incident correlation migration doc
* Fix validation issues for incident correlation migration docs
* Fix broken migration link and update image references
* israel review
* Fix PR validation issues for links, metadata, and image naming
* Fix broken unified secops migration links
* Remove image from incident creation migration article
* Remove unused onboardin…1 parent f2685dd commit 2f51dff
1,610 files changed
Lines changed: 43826 additions & 29829 deletions
File tree
- .github/workflows
- defender-business
- defender-endpoint
- api
- includes
- malware
- media
- linux-install-with-defender-deployment-tool
- defender-for-cloud-apps
- includes
- media/migrate-file-policies-to-purview
- defender-for-cloud
- defender-portal
- media
- anti-malware
- defender-for-sql-on-machines-vulnerability-assessment
- defender-for-sql-scan-results
- enable-defender-for-databases-azure
- serverless-protection
- simulate-alerts-sql-machines
- sql-azure-vulnerability-assessment-find
- defender-for-identity
- deploy
- media/deploy-defender-identity
- includes
- media
- investigate-domain
- ops-guide
- security-posture-assessments
- defender-for-iot-azure
- device-builders
- organizations
- api
- integrations
- legacy-central-management
- ot-deploy
- traffic-mirroring
- defender-for-iot
- defender-office-365
- media
- step-by-step-guides
- defender-vulnerability-management
- defender-xdr
- defender-experts
- media/defender-experts-hunting-ask-experts
- identity-security
- media
- media
- advanced-hunting-security-copilot
- advanced-hunting-take-action
- investigate-users
- scoping
- security-analyst-agent
- security-copilot-and-defender-threat-intelligence
- security-for-ai
- defender
- threat-intelligence
- media
- defender-ti-and-copilot
- easm
- exposure-management
- media/get-started-exposure-management
- includes
- media
- sentinel
- automation
- business-applications
- datalake
- dynamics-365
- includes
- isv
- media
- build-agent-azure-ai-foundry
- build-agent-security-copilot
- create-codeless-connector
- develop-custom-graph-platform-solutions
- develop-notebook-platform-solutions
- develop-siem-solutions-overview
- publish-agent-to-security-store
- publish-notebook-solutions
- sentinel-data-lake-onboarding
- sentinel-integration-guide
- sap
- soc-optimization
- unified-secops-platform
- media/mto-cross-cloud
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
252 | 252 | | |
253 | 253 | | |
254 | 254 | | |
255 | | - | |
| 255 | + | |
| 256 | + | |
256 | 257 | | |
257 | | - | |
| 258 | + | |
0 commit comments