Blog Post

Microsoft Defender Vulnerability Management Blog
2 MIN READ

Announcing high value asset tagging in Microsoft Defender ATP

Tomer Teller's avatar
Tomer Teller
Icon for Microsoft rankMicrosoft
Jul 14, 2020

When attackers enter your network, they don’t treat all your assets equally. Some are more valuable than others. Assets such as domain controllers, internet facing machines, executive’s devices, and machines that host internal and external production services are attractive to bad actors – offering them access to sensitive corporate data, or ways to move further laterally across the organization.

 

These assets require higher levels of attention from the security team and should be prioritized when it comes to reducing overall risk for an organization.

 

Today, we are excited to introduce a new setting in Microsoft Defender ATP that allows customers to define a machine’s value to the organization. The first use case scenario for this is in threat and vulnerability management. This feature, now in public preview, will help customers differentiate between asset priorities, which results in a more accurate assessment of their overall risk. It’s the first time we’re providing a tool to our customers that enables them to help us in providing a more accurate assessment of their risk.

 

Security teams will benefit from having the additional machine value context, set by the admin, as they conduct investigations – helping to further bridge the gap between security and IT teams.

 

High value asset tag of device from incidents page

 

With the high value asset prioritizations, organizations can define a machine’s value with the following options:

  • Low Value
  • Normal Value (Default)
  • High Value

 

In threat and vulnerability management, the machine value is used to incorporate the risk appetite of an individual asset into the exposure score calculation. Meaning that machines marked as “high value” will receive more weight in the exposure score calculation.

 

Setting a machine value is simple:

  1. Navigate into any machine page
  2. Select Machine Value and define a value
  3. Review the value in the machine tag area

Options to set the device value.

 

Our newest partner, XM Cyber, a breach and attack simulation and security posture management solution provider, integrates with Microsoft Defender ATP and threat and vulnerability management to help customers see how an attacker moves laterally and compromises critical assets. The platform leverages the new machine tagging capability to help customers tag their most critical assets and adds rich contextual information to enable customers to fully assess the risk of an attack and understand the steps needed for remediation. We’re working with additional partners to incorporate machine tagging and can’t wait to share these collaborations with you in the near future.

 

Getting started

This feature is in public preview today and those customers that have preview features turned on can start trying it out immediately. If you haven’t yet opted in, we encourage you to turn on preview features in the Microsoft Defender Security Center. We welcome your feedback! If you have any comments or questions, let us know!

Updated Jul 14, 2020
Version 3.0
  • wroot's avatar
    wroot
    Silver Contributor

    I wonder if there are plans to implement some automatic tagging using AI. Certainly MD ATP can determine what is a DC and suggest to apply high value tag.

  • ToMMyBoaY's avatar
    ToMMyBoaY
    Copper Contributor

    Good stuff but we should at bare minimum be able to modify this value based on pre-existing tags.
    I.E. "Any system with tag "VIP" set value to "HIGH""

  • Kevin_Schilling's avatar
    Kevin_Schilling
    Copper Contributor

    mongie0  You could create a script that tags based on information from AAD/AD and others.  To apply a tag automatically you can use either InTune or Group Policy.

     

    • Registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection\DeviceTagging\
    • Registry key value (REG_SZ): Group
    • Registry key data: Name of the tag you want to set

     

    https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/machine-tags

  • mongie0's avatar
    mongie0
    Copper Contributor

    As others have mentioned, it would be good to be able to automate the tagging process. Some ideas...

     

    • Ability to mark a user as high value and automatically tag their primary device
    • Abililty to use an AAD/AD group of users / devices and automatically tag
    • Use user properties (e.g. Title) to tag primary device