Forum Discussion

Gig McClain's avatar
Gig McClain
Copper Contributor
May 18, 2021

Correlated Events

Just watched the M365 Defedner for Endpoint webinar a few minutes ago. 

We don't use Sentinel.

We have M365 Identity, Endpoint, & MCAS all turned on.

Will we automatically see correlated incidents in M365 Security Center (security.microsoft.com) or is there some integration I have to turn on between all of these.

Or do you have a document I can check our settings for all this?

 

Thanks

  • Hi Gig, M365 Defender for Endpoint will automatically correlate alerts from all of these sources into Incidents. There is no need for any manual work or Sentinel. Hope this helps!

Resources