Event details
During Microsoft Secure you learned about the latest innovations around Microsoft's SIEM and XDR solution. Join this Ask Microsoft Anything (AMA) session to get your questions about Microsoft Sentinel and Microsoft 365 Defender answered by our product experts!
|
This session is part of the Microsoft Secure Tech Accelerator. RSVP for event reminders, add it to your calendar, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
80 Comments
- bobbobcomCopper Contributor
there are a lot of pieces to Defender. Assuming you have an E5 license what else would you need to budget for if you needed everything? Defender for Server is per host - pricing in Defender for Cloud.
Defender for TI portal is extra? vuln management is disabled by default in the defender portal but included with E5 or is it an extra $2 per host? IoT is per asset
- Microsoft Defender Family (in M365) [https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-365-defender?view=o365-worldwide] is a different and separate product from Microsoft Defender for Cloud (in Azure) [https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-cloud-introduction]. M365 E5 subscription has nothing to do with Azure features (in the simplest way).
- bobbobcomCopper ContributorUnderstood, but as a security architect I need to understand all of the costs relative to security. it's a long list and all microsoft related security services can't be found in one place. A simple checklist of all security features and a link to a cost sheet is needed. The Azure cost calculator is nice but incomplete. The m365 comparison sheet is nice but incomplete. Same for Defender for server pricing in the defender for cloud portal.
- John_ShinCopper ContributorWith active subscriptions for M365 E3, Mobility + Security E5, and Compliance E5, what is the required subscription for Defender? What is the difference between Microsoft 365 Defender vs. Microsoft Defender.
- Sreedhar_Ande
Microsoft
Microsoft Defender is a security solution that is focused on protecting endpoints, such as desktops, laptops, and servers. It includes features such as antivirus, firewall, and endpoint detection and response (EDR) capabilities. Microsoft Defender is available for Windows 10, Windows Server, and macOS.
Microsoft 365 Defender, on the other hand, is a more comprehensive security solution that is designed to protect the entire Microsoft 365 environment, including endpoints, email, identities, and applications. It includes features such as endpoint protection, email protection, identity protection, and cloud application security. Microsoft 365 Defender is a cloud-based solution that is integrated with other Microsoft 365 services, such as Azure Active Directory and Microsoft Cloud App Security.
- As an SME organization, when is the right time to introduce a SIEM to my environment? Is Microsoft Sentinel for SME or Enterprise?
- Heather_Poulsen
Community Manager
Thanks for participating in the Tech Accelerator! For reference, the panel covered this topic at around 17:20. - Any time when it is sufficient for you. I have a small tenant with just two physical users and a few virtual, and we have implementer SIEM (as Microsoft Sentinel) in full from the beginning.
- Dean_GrossSilver ContributorWhat products are included in the XDR platform?
- Ed Fisher
Microsoft
Microsoft 365 Defender, and Microsoft Defender for Cloud. Start at https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Yp71?culture=en-us&country=us for more detail. - Steve Newby
Microsoft
The XDR platform is M365 Defender which depending upon the SKU you purchase includes Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office, Microsoft Defender for Cloud Apps. The value of our XDR solution is the tight integration of these products for both detection and response.- Dean_GrossSilver ContributorThis is confusing to me, I was under the impression that XDR would also include Defender for Cloud and Sentinel, and possibly some other services.
- bobbobcomCopper ContributorMy client has an E5 license and he's an azure global admin. he's having difficulty enabling the "Office 365 Threat Intelligence connection" feature in the defender portal > settings > endpoint. it says he doesn't have permission (but he's global admin)
- Azure Global Admin != M365 Global Admin != Defender Admin - even if you have GA roles, that role is not super powerful - cannot execute many things and actions in Microsoft Purview Portal and Microsoft Defender Portal. You have to apply proper permission for products and subproducts inside M365.
- Ed Fisher
Microsoft
Tobias is quite right, but just to add a little more specificity to this, to enable the Office 365 Threat Intelligence connection, you need to have Security Administrator permissions.
- John AubreyOccasional ReaderWe are just starting down the Sentinel/XDR/SIEM/SOAR route. We didn't have anything in place before this outside Defender AV. We have some alerts and hunting queries setup, but is there a next step? Where do you see customers going from here? What are the hurdles that are commonly seen from customers?
- Heather_Poulsen
Community Manager
Thanks for participating in the Tech Accelerator! For reference, the panel covered this topic at around 13:50. - Dean_GrossSilver ContributorJohn, I frequently see our clients focusing on using their new tools like Sentinel when they have not yet ensured that security baselines are in place. People go for the new shiny things instead of doing the basics. I strongly recommend focusing on implementing the secure score recommendations because this will decrease the noise in Sentinel Also, spend some time getting familiar with the numerous Workbooks in Sentinel, they will provide a wealth of information about the environment. make sure to use Watchlists, they can provide many benefits.
- Joshua_HohbeinCopper ContributorGood Morning! Are there any plans to expand the capabilities of Microsoft Defender for Servers that's included as the $3 add on SKU to business premium? Additional features or capabilities coming in a road map? For SMB's it's a better sell than utilizing the Azure Arc/Defender for Cloud services. Thank you!
- Ed Fisher
Microsoft
Microsoft Defender for Servers is now a part of Microsoft Defender for Cloud, extending the capabilities of this well beyond "just" server endpoints. Take a look at https://www.microsoft.com/en-us/security/business/cloud-security/microsoft-defender-cloud for some of the latest information.
- Richard_HortonBrass ContributorIf our organization is using a specific product atm and want to find out the equivalent Microsoft Defender and companion products who do we talk to in order to review a Microsoft solution and the products that would help replace an existing product?
- Heather_Poulsen
Community Manager
Thanks for participating in the Tech Accelerator! For reference, the panel covered this topic at around 11:15. - Ed Fisher
Microsoft
Hi Richard, your account team and CSAM would be great people to help you with this, but if you do not have those relationships or know who they are, and want to provide some specifics here, I will see if I can point you in the right direction.- Richard_HortonBrass ContributorWe work with CDW but they have not really identified if we have a Microsoft Account team or a CSAM. We have just over 500 employee's. Can you direct me to who I should talk to about identifying or account team?
- lasse_selsingCopper ContributorHi, is there any special considerations to make when building data collection rules? im ingesting firewall data into native tables via Logstash, but are there any guidelines or best practices to follow when working with large amounts of data? 400+ gb/daily of firewall data. when using the TransformKql, can i use has just as well as contain? or are there any restrictions or limitations that i should be aware of when building those transformkql statements?
- Heather_Poulsen
Community Manager
Thanks for participating in the Tech Accelerator! For reference, the panel covered this topic at around 23:45. - Sreedhar_Ande
Microsoft
https://learn.microsoft.com/en-us/azure/azure-monitor/essentials/data-collection-rule-best-practices Filter data at the source: Whenever possible, try to filter your data at the source before it is ingested into your system. For example, you could filter out data that is not relevant to your use case, such as internal traffic or known benign traffic. This can help reduce the amount of data that needs to be processed and improve query performance.
- Trevor_Rusher
Community Manager
Welcome to the SIEM and XDR AMA and the Microsoft Secure Tech Accelerator. Let's get started! Please post your questions here in the Comments. We will be answering questions in the live stream—and others will be answering here in the Comments.- Richard_HortonBrass ContributorIf our organization is using a specific product atm and want to find out the equivalent Microsoft Defender and companion products who do we talk to in order to review a Microsoft solution and the products that would help replace an existing product?
- Ed Fisher
Microsoft
Your best place to start would be with your account team, or your Customer Success Account Manager (TAM.) If you do not know who they are or do not have them, we can try to give you at least a start in this chat, though there are limits to how much information/how deep we can go in this live session.