Edit

Microsoft Defender for Endpoint Security Operations Guide

This article gives an overview of the requirements and tasks for successfully operating Microsoft Defender for Endpoint in your organization. These tasks help your security operations center (SOC) effectively detect and respond to Microsoft Defender for Endpoint detected security threats.

This article also describes daily, weekly, monthly, and ad-hoc tasks your security team can perform for your organization.

Note

These are recommended steps; check them against your own policies and environment to make sure they are fit for purpose.

Prerequisites

The Microsoft Defender Endpoint should be set up to support your regular security operations process. Although not covered in this document, the following articles provide configuration and setup information:

Daily activities

General

  • Review actions

    In the action center, review the actions that have been taken in your environment, both automated and manual. This information helps you validate that automated investigation and response (AIR) is performing as expected and identify any manual actions that need to be reviewed. For more information, see Visit the Action center to see remediation actions.

Security operations team

  • Monitor the Microsoft Defender XDR Incidents queue

    When Microsoft Defender for Endpoint identifies Indicators of compromise (IOCs) or Indicators of attack (IOAs) and generates an alert, the alert is included in an incident and displayed in the Incidents queue in the Microsoft Defender portal (https://security.microsoft.com).

    Review these incidents to respond to any Microsoft Defender for Endpoint alerts and resolve once the incident has been remediated. For more information, see Incident notifications by email and View and organize the Microsoft Defender for Endpoint Incidents queue.

  • Manage false positive and false negative detections

    Review the incident queue, identify false positive and false negative detections and submit them for review. This helps you effectively manage alerts in your environment and make your alerts more efficient. For more information, see Address false positives/negatives in Microsoft Defender for Endpoint.

  • Review threat analytics high-impact threats

    Review threat analytics to identify any campaigns that are impacting your environment. The "High-impact threats" table lists the threats that have had the highest impact to the organization. This section ranks threats by the number of devices that have active alerts. For more information, see Track and respond to emerging threats through threat analytics.

Security administration team

  • Review health reports

    Review health reports to identify any device health trends that need to be addressed. The device health reports cover Microsoft Defender for Endpoint AV signature, platform health, and EDR health. For more information, see Device health reports in Microsoft Defender for Endpoint.

  • Check Endpoint detection and response (EDR) sensor health

    EDR health is maintaining the connection to the EDR service to make sure that Defender for Endpoint is receiving the required signals to alert and identify vulnerabilities.

    Review unhealthy devices. For more information, see Device health, Sensor health & OS report.

  • Check Microsoft Defender Antivirus health

    Viewing the status of Microsoft Defender Antivirus updates is critical for the best performance of Defender for Endpoint in your environment and up-to-date detections. The device health page shows current status for platform, intelligence, and engine version. For more information, see the Device health, Microsoft Defender Antivirus health report.

Weekly activities

General

  • Message Center

    Microsoft Defender XDR uses the Microsoft 365 Message center to notify you of upcoming changes, such as new and changed features, planned maintenance, or other important announcements.

    Review the Message center messages to understand any upcoming changes that impact your environment.

    You can access this in the Microsoft 365 admin center under the Health tab. For more information, see How to check Microsoft 365 service health.

Security operations team

Security administration team

  • Review threat and vulnerability (TVM) status

    Review TVM to identify any new vulnerabilities and recommendations that require action. For more information, see Vulnerability management dashboard.

  • Review attack surface reduction reporting

    Review ASR reports to identify any files that affect your environment. For more information, see Attack surface reduction (ASR) rules report.

  • Review web protection events

    Review the web defense report to identify any IP addresses or URLs that are blocked. For more information, see Web protection.

Monthly activities

General

Review the following articles to understand recently released updates:

Security administration team

Periodically

These tasks are seen as maintenance for your security posture and are critical for your ongoing protection. But as they may take time and effort, it's recommended that you set a standard schedule that you can maintain to perform these tasks.

  • Review exclusions

    Review exclusions that have been set in your environment to confirm you haven't created a protection gap by excluding things that are no longer required to be excluded.

  • Review Defender policy configurations

    Periodically review your Defender configuration settings to confirm that they're set as required.

  • Review automation levels

    Review automation levels in automated investigation and remediation capabilities. For more information, see Automation levels in automated investigation and remediation.

  • Review custom detections

    Periodically review whether the custom detections that have been created are still valid and effective. For more information, see Review custom detection.

  • Review alerts suppression

    Periodically review any alert suppression rules that have been created to confirm they're still required and valid. For more information, see Review alerts suppression.

Troubleshooting

The following articles provide guidance to troubleshoot and fix errors that you may experience when setting up your Microsoft Defender for Endpoint service.