This commit is contained in:
lomayor 2019-09-06 11:18:05 -07:00
parent e3d69bff5a
commit 0ee1195ea5
3 changed files with 18 additions and 18 deletions

View File

@ -1,7 +1,7 @@
--- ---
title: Monitoring web browsing security in Microsoft Defender ATP title: Monitoring web browsing security in Microsoft Defender ATP
description: Use web threat protection in Microsoft Defender ATP to monitor web browsing security description: Use web protection in Microsoft Defender ATP to monitor web browsing security
keywords: web threat protection, web browsing, monitoring, reports, cards, domain list, security, phishing, malware, exploit, websites, network protection, Edge, Internet Explorer, Chrome, Firefox, web browser keywords: web protection, web browsing, monitoring, reports, cards, domain list, security, phishing, malware, exploit, websites, network protection, Edge, Internet Explorer, Chrome, Firefox, web browser
search.product: eADQiWindows 10XVcnh search.product: eADQiWindows 10XVcnh
search.appverid: met150 search.appverid: met150
ms.prod: w10 ms.prod: w10
@ -24,13 +24,13 @@ ms.date: 08/30/2019
[!include[Prerelease information](prerelease.md)] [!include[Prerelease information](prerelease.md)]
Web threat protection lets you monitor your organizations web browsing security through reports under **Reports > Web protection** in the Microsoft Defender Security Center. The report contains the following cards that provide detection statistics from web threat protection: Web protection lets you monitor your organizations web browsing security through reports under **Reports > Web protection** in the Microsoft Defender Security Center. The report contains the following cards that provide web threat detection statistics:
- **Web threat protection detections over time** — this trending card displays the number of web threats detected by type during the selected time period (Last 30 days, Last 3 months, Last 6 months) - **Web threat protection detections over time** — this trending card displays the number of web threats detected by type during the selected time period (Last 30 days, Last 3 months, Last 6 months)
![Image of the card showing web threats protection detections over time](images/wtp-blocks-over-time.png) ![Image of the card showing web threats protection detections over time](images/wtp-blocks-over-time.png)
- **Web threat protection summary** — this card displays the total web threat protection detections in the past 30 days, showing distribution across the different types of web threats. Clicking a slice opens the list of the domains that were found with malicious or unwanted websites. - **Web threat protection summary** — this card displays the total web threat detections in the past 30 days, showing distribution across the different types of web threats. Selecting a slice opens the list of the domains that were found with malicious or unwanted websites.
![Image of the card showing web threats protection summary](images/wtp-summary.png) ![Image of the card showing web threats protection summary](images/wtp-summary.png)
@ -38,7 +38,7 @@ Web threat protection lets you monitor your organizations web browsing securi
>It can take up to 12 hours before a block is reflected in the cards or the domain list. >It can take up to 12 hours before a block is reflected in the cards or the domain list.
## Types of web threats ## Types of web threats
Web threat protection categorizes malicious and unwanted websites as: Web protection categorizes malicious and unwanted websites as:
- **Phishing** — websites that contain spoofed web forms and other phishing mechanisms designed to trick users into divulging credentials and other sensitive information - **Phishing** — websites that contain spoofed web forms and other phishing mechanisms designed to trick users into divulging credentials and other sensitive information
- **Malicious** — websites that host malware and exploit code - **Malicious** — websites that host malware and exploit code
- **Custom indicator** — websites whose URLs or domains you've added to your [custom indicator list](manage-indicators.md) for blocking - **Custom indicator** — websites whose URLs or domains you've added to your [custom indicator list](manage-indicators.md) for blocking
@ -55,5 +55,5 @@ Clicking on a specific web threat category in the **Web threat protection summar
Selecting a domain opens a panel that shows the list of URLs in that domain that have been accessed. The panel also lists machines that have attempted to access URLs in the domain. Selecting a domain opens a panel that shows the list of URLs in that domain that have been accessed. The panel also lists machines that have attempted to access URLs in the domain.
## Related topics ## Related topics
- [Web threat protection overview](web-threat-protection-overview.md) - [Web protection overview](web-threat-protection-overview.md)
- [Respond to web threats](web-threat-protection-response.md) - [Respond to web threats](web-threat-protection-response.md)

View File

@ -1,7 +1,7 @@
--- ---
title: Overview of web threat protection in Microsoft Defender ATP title: Overview of web protection in Microsoft Defender ATP
description: Learn about web threat protection in Microsoft Defender ATP and how it can protect your organization description: Learn about web protection in Microsoft Defender ATP and how it can protect your organization
keywords: web threat protection, web browsing, security, phishing, malware, exploit, websites, network protection, Edge, Internet Explorer, Chrome, Firefox, web browser keywords: web protection, web browsing, security, phishing, malware, exploit, websites, network protection, Edge, Internet Explorer, Chrome, Firefox, web browser
search.product: eADQiWindows 10XVcnh search.product: eADQiWindows 10XVcnh
search.appverid: met150 search.appverid: met150
ms.prod: w10 ms.prod: w10
@ -24,10 +24,10 @@ ms.date: 08/30/2019
[!include[Prerelease information](prerelease.md)] [!include[Prerelease information](prerelease.md)]
Web threat protection in Microsoft Defender ATP secures your machines against web threats without relying on a web proxy, providing security for devices that are either away or on premises. By integrating with Microsoft Edge as well as popular third-party browsers like Chrome and Firefox, web threat protection stops access to phishing sites, malware vectors, exploit sites, untrusted or low-reputation sites, as well as sites that you have blocked in your [custom indicator list](manage-indicators.md). Web protection in Microsoft Defender ATP leverages [network protection](network-protection.md) to secure your machines against web threats without relying on a web proxy, providing security for devices that are either away or on premises. By integrating with Microsoft Edge as well as popular third-party browsers like Chrome and Firefox, web protection stops access to phishing sites, malware vectors, exploit sites, untrusted or low-reputation sites, as well as sites that you have blocked in your [custom indicator list](manage-indicators.md).
With web threat protection in Microsoft Defender ATP, you get: With web protection, you also get:
- Comprehensive visibility of web threats - Comprehensive visibility into web threats affecting your organization
- Investigation capabilities over web-related threat activity through alerts and comprehensive profiles of URLs and the machines that access these URLs - Investigation capabilities over web-related threat activity through alerts and comprehensive profiles of URLs and the machines that access these URLs
- A full set of security features that track general access trends to malicious and unwanted websites - A full set of security features that track general access trends to malicious and unwanted websites
@ -35,7 +35,7 @@ With web threat protection in Microsoft Defender ATP, you get:
>It can take up to an hour for machines to receive new customer indicators. >It can take up to an hour for machines to receive new customer indicators.
## Prerequisites ## Prerequisites
Web threat protection uses network protection to provide web browsing security on Microsoft Edge and third-party web browsers. Web protection uses network protection to provide web browsing security on Microsoft Edge and third-party web browsers.
To turn on network protection on your machines: To turn on network protection on your machines:
- Edit the Microsoft Defender ATP security baseline under **Web & Network Protection** to enable network protection before deploying or redeploying it. [Learn about reviewing and assigning the Microsoft Defender ATP security baseline](configure-machines-security-baseline.md#review-and-assign-the-microsoft-defender-atp-security-baseline) - Edit the Microsoft Defender ATP security baseline under **Web & Network Protection** to enable network protection before deploying or redeploying it. [Learn about reviewing and assigning the Microsoft Defender ATP security baseline](configure-machines-security-baseline.md#review-and-assign-the-microsoft-defender-atp-security-baseline)

View File

@ -1,7 +1,7 @@
--- ---
title: Respond to web threats in Microsoft Defender ATP title: Respond to web threats in Microsoft Defender ATP
description: Respond to alerts related to malicious and unwanted websites. Understand how web threat protection informs end users through their web browsers and Windows notifications description: Respond to alerts related to malicious and unwanted websites. Understand how web threat protection informs end users through their web browsers and Windows notifications
keywords: web threat protection, web browsing, alerts, response, security, phishing, malware, exploit, websites, network protection, Edge, Internet Explorer, Chrome, Firefox, web browser, notifications, end users, Windows notifications, blocking page, keywords: web protection, web browsing, alerts, response, security, phishing, malware, exploit, websites, network protection, Edge, Internet Explorer, Chrome, Firefox, web browser, notifications, end users, Windows notifications, blocking page,
search.product: eADQiWindows 10XVcnh search.product: eADQiWindows 10XVcnh
search.appverid: met150 search.appverid: met150
ms.prod: w10 ms.prod: w10
@ -24,7 +24,7 @@ ms.date: 08/30/2019
[!include[Prerelease information](prerelease.md)] [!include[Prerelease information](prerelease.md)]
Web threat protection in Microsoft Defender APT lets you efficiently investigate and respond to alerts related to malicious websites and websites in your custom indicator list. Web protection in Microsoft Defender APT lets you efficiently investigate and respond to alerts related to malicious websites and websites in your custom indicator list.
## View web threat alerts ## View web threat alerts
Microsoft Defender ATP generates the following [alerts](manage-alerts.md) for malicious or suspicious web activity: Microsoft Defender ATP generates the following [alerts](manage-alerts.md) for malicious or suspicious web activity:
@ -40,7 +40,7 @@ Each alert provides the following information:
![Image of an alert related to web threat protection](images/wtp-alert.png) ![Image of an alert related to web threat protection](images/wtp-alert.png)
>[!Note] >[!Note]
>To reduce the volume of alerts, Microsoft Defender ATP consolidates web threat protection detections for the same domain on the same machine each day to a single alert. Only one alert is generated and counted into the [web protection report](web-threat-protection-monitoring.md). >To reduce the volume of alerts, Microsoft Defender ATP consolidates web threat detections for the same domain on the same machine each day to a single alert. Only one alert is generated and counted into the [web protection report](web-threat-protection-monitoring.md).
## Inspect website details ## Inspect website details
You can dive deeper by selecting the URL or domain of the website in the alert. This opens a page about that particular URL or domain with various information, including: You can dive deeper by selecting the URL or domain of the website in the alert. This opens a page about that particular URL or domain with various information, including:
@ -59,7 +59,7 @@ You can also check the machine that attempted to access a blocked URL. Selecting
## Web browser and Windows notifications for end users ## Web browser and Windows notifications for end users
With web threat protection in Microsoft Defender ATP, your end users will be blocked from visiting malicious or unwanted websites using Microsoft Edge or other browsers. Because blocking is performed by [network protection](../windows-defender-exploit-guard/network-protection-exploit-guard.md), they will see a generic error from the web browser. They will also see a notification from Windows. With web protection in Microsoft Defender ATP, your end users will be prevented from visiting malicious or unwanted websites using Microsoft Edge or other browsers. Because blocking is performed by [network protection](../windows-defender-exploit-guard/network-protection-exploit-guard.md), they will see a generic error from the web browser. They will also see a notification from Windows.
![Image of Microsoft Edge showing a 403 error and the Windows notification](images/wtp-browser-blocking-page.png) ![Image of Microsoft Edge showing a 403 error and the Windows notification](images/wtp-browser-blocking-page.png)
*Web threat blocked by Microsoft Edge* *Web threat blocked by Microsoft Edge*
@ -68,5 +68,5 @@ With web threat protection in Microsoft Defender ATP, your end users will be blo
*Web threat blocked by the Chrome web browser* *Web threat blocked by the Chrome web browser*
## Related topics ## Related topics
- [Web threat protection overview](web-threat-protection-overview.md) - [Web protection overview](web-threat-protection-overview.md)
- [Monitor web security](web-threat-protection-monitoring.md) - [Monitor web security](web-threat-protection-monitoring.md)