mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-14 06:17:22 +00:00
Merge pull request #3128 from MicrosoftDocs/FromPrivateRepo
From private repo
This commit is contained in:
commit
07930a677d
@ -343,6 +343,7 @@
|
|||||||
##### Reporting
|
##### Reporting
|
||||||
###### [Create and build Power BI reports using Windows Defender ATP data](windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md)
|
###### [Create and build Power BI reports using Windows Defender ATP data](windows-defender-atp/powerbi-reports-windows-defender-advanced-threat-protection.md)
|
||||||
###### [Threat protection reports](windows-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md)
|
###### [Threat protection reports](windows-defender-atp/threat-protection-reports-windows-defender-advanced-threat-protection.md)
|
||||||
|
###### [Machine health and compliance reports](windows-defender-atp/machine-reports-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
##### Role-based access control
|
##### Role-based access control
|
||||||
###### [Manage portal access using RBAC](windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md)
|
###### [Manage portal access using RBAC](windows-defender-atp/rbac-windows-defender-advanced-threat-protection.md)
|
||||||
|
@ -333,6 +333,7 @@
|
|||||||
#### Reporting
|
#### Reporting
|
||||||
##### [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)
|
##### [Create and build Power BI reports using Windows Defender ATP data](powerbi-reports-windows-defender-advanced-threat-protection.md)
|
||||||
##### [Threat protection reports](threat-protection-reports-windows-defender-advanced-threat-protection.md)
|
##### [Threat protection reports](threat-protection-reports-windows-defender-advanced-threat-protection.md)
|
||||||
|
##### [Machine health and compliance reports](machine-reports-windows-defender-advanced-threat-protection.md)
|
||||||
|
|
||||||
#### Role-based access control
|
#### Role-based access control
|
||||||
##### [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md)
|
##### [Manage portal access using RBAC](rbac-windows-defender-advanced-threat-protection.md)
|
||||||
|
Binary file not shown.
After Width: | Height: | Size: 97 KiB |
@ -0,0 +1,82 @@
|
|||||||
|
---
|
||||||
|
title: Machine health and compliance report in Windows Defender ATP
|
||||||
|
description: Track machine health state detections, antivirus status, OS platform, and Windows 10 versions using the machine health and compliance report
|
||||||
|
keywords: health state, antivirus, os platform, windows 10 version, version, health, compliance, state
|
||||||
|
search.product: eADQiWindows 10XVcnh
|
||||||
|
search.appverid: met150
|
||||||
|
ms.prod: w10
|
||||||
|
ms.mktglfcycl: deploy
|
||||||
|
ms.sitesec: library
|
||||||
|
ms.pagetype: security
|
||||||
|
ms.author: macapara
|
||||||
|
author: mjcaparas
|
||||||
|
ms.localizationpriority: medium
|
||||||
|
manager: dansimp
|
||||||
|
audience: ITPro
|
||||||
|
ms.collection: M365-security-compliance
|
||||||
|
ms.topic: article
|
||||||
|
---
|
||||||
|
|
||||||
|
# Machine health and compliance report in Windows Defender ATP
|
||||||
|
|
||||||
|
**Applies to:**
|
||||||
|
- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://wincom.blob.core.windows.net/documents/Windows10_Commercial_Comparison.pdf)
|
||||||
|
|
||||||
|
[!include[Prerelease information](prerelease.md)]
|
||||||
|
|
||||||
|
The machines status report provides high-level information about the devices in your organization. The report includes trending information showing the sensor health state, antivirus status, OS platforms, and Windows 10 versions.
|
||||||
|
|
||||||
|
|
||||||
|
The dashboard is structured into two sections:
|
||||||
|

|
||||||
|
|
||||||
|
Section | Description
|
||||||
|
:---|:---
|
||||||
|
1 | Machine trends
|
||||||
|
2 | Machine summary (current day)
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
By default, the machine trends displays machine information from the 30-day period ending in the latest full day. To gain better perspective on trends occurring in your organization, you can fine-tune the reporting period by adjusting the time period shown. To adjust the time period, select a time range from the drop-down options:
|
||||||
|
|
||||||
|
- 30 days
|
||||||
|
- 3 months
|
||||||
|
- 6 months
|
||||||
|
- Custom
|
||||||
|
|
||||||
|
While the machines trends shows trending machine information, the machine summary shows machine information scoped to the current day.
|
||||||
|
|
||||||
|
The machine trends section allows you to drill down to the machines list with the corresponding filter applied to it. For example, clicking on the Inactive bar in the Sensor health state card will bring you the machines list with results showing only machines whose sensor status is inactive.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
## Machine attributes
|
||||||
|
The report is made up of cards that display the following machine attributes:
|
||||||
|
|
||||||
|
- **Health state**: shows information about the sensor state on devices, providing an aggregated view of devices that are active, experiencing impaired communications, inactive, or where no sensor data is seen.
|
||||||
|
|
||||||
|
- **Antivirus status for active Windows 10 machines**: shows the number of machines and status of Windows Defender Antivirus.
|
||||||
|
|
||||||
|
- **OS platforms**: shows the distribution of OS platforms that exists within your organization.
|
||||||
|
|
||||||
|
- **Windows 10 versions**: shows the distribution of Windows 10 machines and their versions in your organization.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
## Filter data
|
||||||
|
|
||||||
|
Use the provided filters to include or exclude machines with certain attributes.
|
||||||
|
|
||||||
|
You can select multiple filters to apply from the machine attributes.
|
||||||
|
|
||||||
|
>[!NOTE]
|
||||||
|
>These filters apply to **all** the cards in the report.
|
||||||
|
|
||||||
|
For example, to show data about Windows 10 machines with Active sensor health state:
|
||||||
|
|
||||||
|
1. Under **Filters > Sensor health state > Active**.
|
||||||
|
2. Then select **OS platforms > Windows 10**.
|
||||||
|
3. Select **Apply**.
|
||||||
|
|
||||||
|
|
@ -43,7 +43,7 @@ By default, the alert trends display alert information from the 30-day period en
|
|||||||
- 6 months
|
- 6 months
|
||||||
- Custom
|
- Custom
|
||||||
|
|
||||||
While the alerts trends shows trending information alerts, the alert summary shows alert information scoped to the current day.
|
While the alert trends shows trending alert information, the alert summary shows alert information scoped to the current day.
|
||||||
|
|
||||||
The alert summary allows you to drill down to a particular alert queue with the corresponding filter applied to it. For example, clicking on the EDR bar in the Detection sources card will bring you the alerts queue with results showing only alerts generated from EDR detections.
|
The alert summary allows you to drill down to a particular alert queue with the corresponding filter applied to it. For example, clicking on the EDR bar in the Detection sources card will bring you the alerts queue with results showing only alerts generated from EDR detections.
|
||||||
|
|
||||||
|
@ -23,6 +23,13 @@ ms.topic: conceptual
|
|||||||
|
|
||||||
Here are the new features in the latest release of Windows Defender ATP as well as security features in Windows 10 and Windows Server.
|
Here are the new features in the latest release of Windows Defender ATP as well as security features in Windows 10 and Windows Server.
|
||||||
|
|
||||||
|
## March 2019
|
||||||
|
### In preview
|
||||||
|
The following capability are included in the February 2019 preview release.
|
||||||
|
|
||||||
|
- [Machine health and compliance report](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/machine-reports-windows-defender-advanced-threat-protection) <BR> The machine health and compliance report provides high-level information about the devices in your organization.
|
||||||
|
|
||||||
|
|
||||||
## February 2019
|
## February 2019
|
||||||
The following capabilities are generally available (GA).
|
The following capabilities are generally available (GA).
|
||||||
- [Incidents](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/incidents-queue) <BR> Incident is a new entity in Windows Defender ATP that brings together all relevant alerts and related entities to narrate the broader attack story, giving analysts better perspective on the purview of complex threats.
|
- [Incidents](https://docs.microsoft.com/windows/security/threat-protection/windows-defender-atp/incidents-queue) <BR> Incident is a new entity in Windows Defender ATP that brings together all relevant alerts and related entities to narrate the broader attack story, giving analysts better perspective on the purview of complex threats.
|
||||||
|
Loading…
x
Reference in New Issue
Block a user