Sep 24 2021
- last edited on
Nov 02 2021
I'm relatively new into the industry and been tasked with championing some of our E5 platforms.
We have both MCAS and MS 365 Security which I'm going to call MDE... My questions are:
1. Which one should I be using to manage alerts?
a. Why can't I manage alert policies in MDE and I can in MCAS.
2. What are the differences between the two?
3. Should we even be using both of them?
Sep 30 2021 01:50 AM
MDE (Microsoft Defender for Endpoints), M365 Defender and MCAS (Microsoft Cloud App Security) are three different products: M365 Defender: the whole suite of security tools for M365 (which include MDE, MCAS, but also MDO, MDI and AADP2) https://docs.microsoft.com/en-us/microsoft-365/security/defender/overview-security-center?view=o365-...
- MDI (Microsoft Defender for Identity): Detection of compromise of your local AD
- AAD P2 : Information Governance + Information Protection (protection of cloud identity and improvement of conditional access)
- MDE (Microsoft Defender for Endpoints): Anti-malware / EDR for your endpoints
- MCAS (Microsoft Cloud App Security): "CASB" for the protection of t
- MDO (Microsoft Defender for Office 365): Protection of emails and collaborative tools
If you have ME5 licences, you should use all the tools as they bring a different value
The new unified security portal will let you to have all the security alerts in one place: https://docs.microsoft.com/en-us/microsoft-365/security/defender/overview-security-center?view=o365-...
Sep 30 2021 02:23 AM
Sep 30 2021 03:36 AM