Forum Discussion
Gig McClain
May 18, 2021Copper Contributor
Correlated Events
Just watched the M365 Defedner for Endpoint webinar a few minutes ago.
We don't use Sentinel.
We have M365 Identity, Endpoint, & MCAS all turned on.
Will we automatically see correlated incidents in M365 Security Center (security.microsoft.com) or is there some integration I have to turn on between all of these.
Or do you have a document I can check our settings for all this?
Thanks
- marysia_kMicrosoftHi Gig, M365 Defender for Endpoint will automatically correlate alerts from all of these sources into Incidents. There is no need for any manual work or Sentinel. Hope this helps!
- Gig McClainCopper ContributorThanks