Forum Discussion
MCAS or 365 Security
Hi SDB8519
MDE (Microsoft Defender for Endpoints), M365 Defender and MCAS (Microsoft Cloud App Security) are three different products: M365 Defender: the whole suite of security tools for M365 (which include MDE, MCAS, but also MDO, MDI and AADP2) https://docs.microsoft.com/en-us/microsoft-365/security/defender/overview-security-center?view=o365-worldwide
- MDI (Microsoft Defender for Identity): Detection of compromise of your local AD
- AAD P2 : Information Governance + Information Protection (protection of cloud identity and improvement of conditional access)
- MDE (Microsoft Defender for Endpoints): Anti-malware / EDR for your endpoints
- MCAS (Microsoft Cloud App Security): "CASB" for the protection of t
- MDO (Microsoft Defender for Office 365): Protection of emails and collaborative tools
If you have ME5 licences, you should use all the tools as they bring a different value
The new unified security portal will let you to have all the security alerts in one place: https://docs.microsoft.com/en-us/microsoft-365/security/defender/overview-security-center?view=o365-worldwide
I suppose I was most interested in what portal alerts were best actioned in?
In CAS I seem to be able to modify policies for alerts, even though they aren't fully working. Whereas in 365 security I can't suppress every alert which is frustrating. I like 365 security better but if CAS is better functionality wise not sure which to use.
Thanks!
- thijoubertoldSep 30, 2021Iron ContributorIn this case, the new M365 Defender Portal should answer to your needs.
You define the policies in the different admin centers and you manage them in the unified portal (with the incidents and alerts pages)
https://docs.microsoft.com/en-us/microsoft-365/security/defender/overview-security-center?view=o365-worldwide
Sami Lamppu wrote an interesting article on this topic: https://samilamppu.com/2020/11/24/microsoft-365-defender-vs-azure-sentinel-which-one-to-use/