From 30c52bb0e3dee7231dc8c74de58a9c1ad5cc034f Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 8 May 2019 13:59:46 -0700 Subject: [PATCH 01/22] compare content --- .../compare-commercial-gov.md | 87 +++++++++++++++++++ 1 file changed, 87 insertions(+) create mode 100644 windows/security/threat-protection/windows-defender-atp/compare-commercial-gov.md diff --git a/windows/security/threat-protection/windows-defender-atp/compare-commercial-gov.md b/windows/security/threat-protection/windows-defender-atp/compare-commercial-gov.md new file mode 100644 index 0000000000..bfa328616b --- /dev/null +++ b/windows/security/threat-protection/windows-defender-atp/compare-commercial-gov.md @@ -0,0 +1,87 @@ +--- +title: Compare commercial and government Microsoft Defender ATP +description: +keywords: +search.product: eADQiWindows 10XVcnh +search.appverid: met150 +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +ms.author: macapara +author: mjcaparas +ms.localizationpriority: medium +manager: dansimp +audience: ITPro +ms.collection: M365-security-compliance +ms.topic: conceptual +--- + + +# Compare commercial and government Microsoft Defender ATP + +**Applies to:** +- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) + +Microsoft Defender ATP for government uses the same underlying techonologies as commercial Microsoft Defender ATP. The government SKU/version is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for the government version. + + + + + +## Threat & Vulnerability Management +Not supported + +## Attack surface reduction +Not supported + +## Next generation protection + + +## Endpoint detection and response +Not supported + + +## Automated investigation and remediation +Supported + +>[!NOTE] +>Response to Office 365 alerts are not supported. + +## Secure score + + +## Microsoft Threat Experts + + + +## Management and APIs +Not supported + +## Product integrations + +Integrations with the following products are not supported: +- Azure Security Center +- Azure Advanced Threat Protection +- Azure Information Protection +- Office 365 Advanced Threat Protection +- Microsoft Cloud App Security +- Skype +- Intune + + +## Endpoint versions +The following OS versions are supported: + +- Windows 10, version 1709 or later + + +The following OS versions are not supported: +- Windows Server +- Windows 7, 8, 8.1 +- Linux +- macOS +- iOS +- Android + + From 9fd778eb409c2844a4fd740f38ee5b1c04a82e64 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 8 May 2019 15:10:59 -0700 Subject: [PATCH 02/22] space --- .../windows-defender-atp/compare-commercial-gov.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-atp/compare-commercial-gov.md b/windows/security/threat-protection/windows-defender-atp/compare-commercial-gov.md index bfa328616b..cbc2e19627 100644 --- a/windows/security/threat-protection/windows-defender-atp/compare-commercial-gov.md +++ b/windows/security/threat-protection/windows-defender-atp/compare-commercial-gov.md @@ -27,8 +27,6 @@ Microsoft Defender ATP for government uses the same underlying techonologies as - - ## Threat & Vulnerability Management Not supported From 48f4f907df03494411c734e38be6320c7d1c412d Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Tue, 21 May 2019 14:30:46 -0700 Subject: [PATCH 03/22] edit supported and not --- windows/security/threat-protection/TOC.md | 4 ++ .../microsoft-defender-atp/TOC.md | 3 ++ .../compare-commercial-gov.md | 47 +++++++------------ 3 files changed, 24 insertions(+), 30 deletions(-) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index eb9c04d03f..6f2de5d8b7 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -114,6 +114,10 @@ #### [Data storage and privacy](microsoft-defender-atp/data-storage-privacy.md) #### [Assign user access to the portal](microsoft-defender-atp/assign-portal-access.md) + +#### [Compare commercial and government Microsoft Defender ATP](microsoft-defender-atp/compare-commercial-gov.md) + + #### [Evaluate Microsoft Defender ATP](microsoft-defender-atp/evaluate-atp.md) #####Evaluate attack surface reduction ###### [Hardware-based isolation](windows-defender-application-guard/test-scenarios-wd-app-guard.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md index cb802c617a..9d2e3ae764 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/TOC.md +++ b/windows/security/threat-protection/microsoft-defender-atp/TOC.md @@ -118,6 +118,9 @@ ### [Data storage and privacy](data-storage-privacy.md) ### [Assign user access to the portal](assign-portal-access.md) +### [Compare commercial and government Microsoft Defender ATP](compare-commercial-gov.md) + + ### [Evaluate Microsoft Defender ATP](evaluate-atp.md) ####Evaluate attack surface reduction ##### [Hardware-based isolation](../windows-defender-application-guard/test-scenarios-wd-app-guard.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md index cbc2e19627..5afd63e71e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md @@ -21,40 +21,39 @@ ms.topic: conceptual # Compare commercial and government Microsoft Defender ATP **Applies to:** -- [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) +- [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Microsoft Defender ATP for government uses the same underlying techonologies as commercial Microsoft Defender ATP. The government SKU/version is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for the government version. +Microsoft Defender ATP for government uses the same underlying technologies as commercial Microsoft Defender ATP. The government SKU/version is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for the government version. +## Endpoint versions +The following OS versions are supported: + +- Windows 10, version 1709 or later + + +The following OS versions are not supported: +- Windows Server +- Windows 7, 8, 8.1 + ## Threat & Vulnerability Management Not supported -## Attack surface reduction -Not supported - -## Next generation protection - - -## Endpoint detection and response -Not supported - ## Automated investigation and remediation -Supported +Response to Office 365 alerts are not supported ->[!NOTE] ->Response to Office 365 alerts are not supported. - -## Secure score +## Live response +ADDED, BUT NOT SURE IF SUPPORTED. ## Microsoft Threat Experts - +Not supported ## Management and APIs -Not supported +NOT SURE WHAT IS SUPPORTED AND NOT. ## Product integrations @@ -68,18 +67,6 @@ Integrations with the following products are not supported: - Intune -## Endpoint versions -The following OS versions are supported: - -- Windows 10, version 1709 or later -The following OS versions are not supported: -- Windows Server -- Windows 7, 8, 8.1 -- Linux -- macOS -- iOS -- Android - From 968ddd4c5be83a4640f12e229cd824de91f16f98 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Tue, 21 May 2019 14:32:50 -0700 Subject: [PATCH 04/22] apis --- .../microsoft-defender-atp/compare-commercial-gov.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md index 5afd63e71e..8a28474cfa 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md @@ -46,14 +46,14 @@ Response to Office 365 alerts are not supported ## Live response -ADDED, BUT NOT SURE IF SUPPORTED. +NOTE: ADDED, BUT NEED TO CHECK IF SUPPORTED. ## Microsoft Threat Experts Not supported ## Management and APIs -NOT SURE WHAT IS SUPPORTED AND NOT. +NOTE: NOT SURE WHAT IS SUPPORTED AND NOT. Keeping here for now. ## Product integrations From bf7190ac4507fb26c39cbc94860efa249c3f2b7c Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 29 May 2019 16:49:51 -0700 Subject: [PATCH 05/22] added win 10 KB versions --- .../microsoft-defender-atp/compare-commercial-gov.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md index 8a28474cfa..204a5049c3 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md @@ -29,8 +29,12 @@ Microsoft Defender ATP for government uses the same underlying technologies as c ## Endpoint versions The following OS versions are supported: -- Windows 10, version 1709 or later +- Windows 10, version 1809 (OS Build 17763.404 with [KB4490481](https://support.microsoft.com/en-us/help/4490481)) +- Windows 10, version 1803 (OS Build 17134.799 with [KB4499183](https://support.microsoft.com/help/4499183)) +- Windows 10, version 1709 (OS Build 16299.1182 with [KB4499147](https://support.microsoft.com/help/4499147)) +>[!NOTE] +>If the patches are not implemented, telemetry is sent to the default public geolocation. If public IPs are blocked then the data will not be sent back to Microsoft Defender ATP. Detection and hunting experience will not be available. If public IPs are allowed, then data will reach non-compliant data centers and will then be forwarded to appropriate data centers. The following OS versions are not supported: - Windows Server From 049c903dec96463e0ba95d5ffa96efcf0366e39c Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Thu, 30 May 2019 15:40:53 -0700 Subject: [PATCH 06/22] update note fendpoint versions section --- .../microsoft-defender-atp/compare-commercial-gov.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md index 204a5049c3..dd5f412778 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md @@ -34,7 +34,7 @@ The following OS versions are supported: - Windows 10, version 1709 (OS Build 16299.1182 with [KB4499147](https://support.microsoft.com/help/4499147)) >[!NOTE] ->If the patches are not implemented, telemetry is sent to the default public geolocation. If public IPs are blocked then the data will not be sent back to Microsoft Defender ATP. Detection and hunting experience will not be available. If public IPs are allowed, then data will reach non-compliant data centers and will then be forwarded to appropriate data centers. +>If patches are not implemented after the machine onboarding, some Microsoft Defender ATP telemetry might be sent to the Microsoft Defender ATP Commercial Cloud. The following OS versions are not supported: - Windows Server From 7a80b7dee7be3ca9d2968d0dbb3b85bfb78ed2c8 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Mon, 1 Jul 2019 14:25:18 -0700 Subject: [PATCH 07/22] update to os, not available etc --- .../compare-commercial-gov.md | 50 ++++++++++++------- 1 file changed, 33 insertions(+), 17 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md index dd5f412778..882f7b7518 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md @@ -17,7 +17,6 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- - # Compare commercial and government Microsoft Defender ATP **Applies to:** @@ -27,41 +26,49 @@ Microsoft Defender ATP for government uses the same underlying technologies as c ## Endpoint versions -The following OS versions are supported: +The following OS versions are available: +- Windows 10, version 1903 - Windows 10, version 1809 (OS Build 17763.404 with [KB4490481](https://support.microsoft.com/en-us/help/4490481)) - Windows 10, version 1803 (OS Build 17134.799 with [KB4499183](https://support.microsoft.com/help/4499183)) - Windows 10, version 1709 (OS Build 16299.1182 with [KB4499147](https://support.microsoft.com/help/4499147)) +- Windows Server, 2019 >[!NOTE] >If patches are not implemented after the machine onboarding, some Microsoft Defender ATP telemetry might be sent to the Microsoft Defender ATP Commercial Cloud. -The following OS versions are not supported: -- Windows Server -- Windows 7, 8, 8.1 +The following OS versions are not available: +- Windows Server 2008 R2 SP1 +- Windows Server 2012 R2 +- Windows Server 2016 +- Windows Server, version 1803 +- Windows 7 SP1 Enterprise +- Windows 7 SP1 Pro +- Windows 8 Pro +- Windows 8.1 Enterprise ## Threat & Vulnerability Management -Not supported +Not available. ## Automated investigation and remediation -Response to Office 365 alerts are not supported +The following capabilities are not available: +- Response to Office 365 alerts +- Live response -## Live response -NOTE: ADDED, BUT NEED TO CHECK IF SUPPORTED. - -## Microsoft Threat Experts -Not supported - ## Management and APIs -NOTE: NOT SURE WHAT IS SUPPORTED AND NOT. Keeping here for now. +The following capabilities are not available: -## Product integrations +- Threat protection report +- Machine health and compliance report +- Integration with third-party products -Integrations with the following products are not supported: + +## Microsoft Threat Protection +Integrations with the following products are not available: - Azure Security Center - Azure Advanced Threat Protection - Azure Information Protection @@ -70,7 +77,16 @@ Integrations with the following products are not supported: - Skype - Intune - +## Microsoft Threat Experts +Not available. + +## Required connectivity settings +You'll need to ensure that traffic from the following are allowed: + +Service location | DNS record +:---|:--- +Common URLs for all locations (Global location) | ```crl.microsoft.com```
```ctldl.windowsupdate.com```
```notify.windows.com``` +Microsoft Defender ATP GCC high specific | ```us4-v20.events.data.microsoft.com```
```winatp-gw-usgt.microsoft.com```
```winatp-gw-usgv.microsoft.com```
```*.blob.core.usgovcloudapi.net``` From 7954838203dc946b1b1f727074293bab82a1b4a4 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Mon, 1 Jul 2019 15:25:19 -0700 Subject: [PATCH 08/22] change to supported for OS versions --- .../microsoft-defender-atp/compare-commercial-gov.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md index 882f7b7518..c37fd9e251 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md @@ -26,7 +26,7 @@ Microsoft Defender ATP for government uses the same underlying technologies as c ## Endpoint versions -The following OS versions are available: +The following OS versions are supported: - Windows 10, version 1903 - Windows 10, version 1809 (OS Build 17763.404 with [KB4490481](https://support.microsoft.com/en-us/help/4490481)) @@ -37,7 +37,7 @@ The following OS versions are available: >[!NOTE] >If patches are not implemented after the machine onboarding, some Microsoft Defender ATP telemetry might be sent to the Microsoft Defender ATP Commercial Cloud. -The following OS versions are not available: +The following OS versions are not supported: - Windows Server 2008 R2 SP1 - Windows Server 2012 R2 - Windows Server 2016 From e2639c972cfeb8f8880eabae7a201103413021af Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 3 Jul 2019 08:02:34 -0700 Subject: [PATCH 09/22] update file name and other details --- ...re-commercial-gov.md => commercial-gov.md} | 21 ++++++++++--------- 1 file changed, 11 insertions(+), 10 deletions(-) rename windows/security/threat-protection/microsoft-defender-atp/{compare-commercial-gov.md => commercial-gov.md} (64%) diff --git a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md similarity index 64% rename from windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md rename to windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index c37fd9e251..341a8c2d5f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/compare-commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -1,7 +1,7 @@ --- -title: Compare commercial and government Microsoft Defender ATP -description: -keywords: +title: Microsoft Defender ATP in Azure Government +description: Learn about the requirements and the available Microsoft Defender ATP capabilities in Azure Government +keywords: government, requirements, capabilities, azure, defender, defender atp, mdatp search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -22,7 +22,7 @@ ms.topic: conceptual **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Microsoft Defender ATP for government uses the same underlying technologies as commercial Microsoft Defender ATP. The government SKU/version is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for the government version. +Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) in Azure Government uses the same underlying technologies as commercial Microsoft Defender ATP. This offering is currently available to US GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for Azure Government version. ## Endpoint versions @@ -32,7 +32,7 @@ The following OS versions are supported: - Windows 10, version 1809 (OS Build 17763.404 with [KB4490481](https://support.microsoft.com/en-us/help/4490481)) - Windows 10, version 1803 (OS Build 17134.799 with [KB4499183](https://support.microsoft.com/help/4499183)) - Windows 10, version 1709 (OS Build 16299.1182 with [KB4499147](https://support.microsoft.com/help/4499147)) -- Windows Server, 2019 +- Windows Server, 2019 (with [KB4490481](https://support.microsoft.com/en-us/help/4490481)) >[!NOTE] >If patches are not implemented after the machine onboarding, some Microsoft Defender ATP telemetry might be sent to the Microsoft Defender ATP Commercial Cloud. @@ -47,13 +47,14 @@ The following OS versions are not supported: - Windows 8 Pro - Windows 8.1 Enterprise +The initial release of Microsoft Defender ATP will not have immediate parity with the commercial offering. While our goal is to deliver all commercial features and functionality to our Azure Government environment, there are some capabilities not yet available that we’d like to highlight. These are the known gaps as of August 2019: ## Threat & Vulnerability Management -Not available. +Not currently available. ## Automated investigation and remediation -The following capabilities are not available: +The following capabilities are not currently available: - Response to Office 365 alerts - Live response @@ -67,8 +68,8 @@ The following capabilities are not available: - Integration with third-party products -## Microsoft Threat Protection -Integrations with the following products are not available: +## Integrations +Integrations with the following Microsoft products are not currently available: - Azure Security Center - Azure Advanced Threat Protection - Azure Information Protection @@ -78,7 +79,7 @@ Integrations with the following products are not available: - Intune ## Microsoft Threat Experts -Not available. +Not currently available. ## Required connectivity settings You'll need to ensure that traffic from the following are allowed: From 3c77dabb9d641648c7d3db5351bda25a6a49da4d Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 3 Jul 2019 08:05:49 -0700 Subject: [PATCH 10/22] update TOC --- windows/security/threat-protection/TOC.md | 2 +- .../security/threat-protection/microsoft-defender-atp/TOC.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index b75d914b47..87abacb1bf 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -117,7 +117,7 @@ #### [Assign user access to the portal](microsoft-defender-atp/assign-portal-access.md) -#### [Compare commercial and government Microsoft Defender ATP](microsoft-defender-atp/compare-commercial-gov.md) +#### [Microsoft Defender ATP in Azure Government ](microsoft-defender-atp/commercial-gov.md) #### [Evaluate Microsoft Defender ATP](microsoft-defender-atp/evaluate-atp.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/TOC.md b/windows/security/threat-protection/microsoft-defender-atp/TOC.md index 78996ebff7..4224dfcfad 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/TOC.md +++ b/windows/security/threat-protection/microsoft-defender-atp/TOC.md @@ -119,7 +119,7 @@ ### [Data storage and privacy](data-storage-privacy.md) ### [Assign user access to the portal](assign-portal-access.md) -### [Compare commercial and government Microsoft Defender ATP](compare-commercial-gov.md) +### [Microsoft Defender ATP in Azure Government ](commercial-gov.md) ### [Evaluate Microsoft Defender ATP](evaluate-atp.md) From 84a26ffe1330a11faf81c088a0491dd23e1f79d7 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Thu, 11 Jul 2019 14:57:55 -0700 Subject: [PATCH 11/22] updates --- .../microsoft-defender-atp/commercial-gov.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index 341a8c2d5f..ceeb77e4c4 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -17,12 +17,12 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Compare commercial and government Microsoft Defender ATP +# Microsoft Defender ATP in Azure Government **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) in Azure Government uses the same underlying technologies as commercial Microsoft Defender ATP. This offering is currently available to US GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for Azure Government version. +Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) in Azure Government uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for Azure Government version. ## Endpoint versions @@ -75,8 +75,8 @@ Integrations with the following Microsoft products are not currently available: - Azure Information Protection - Office 365 Advanced Threat Protection - Microsoft Cloud App Security -- Skype -- Intune +- Skype for Business +- Microsoft Intune ## Microsoft Threat Experts Not currently available. From 2f7c536370e09f676dfd1c8699ea0177cc462747 Mon Sep 17 00:00:00 2001 From: jcaparas Date: Fri, 12 Jul 2019 09:41:38 -0700 Subject: [PATCH 12/22] Update commercial-gov.md --- .../threat-protection/microsoft-defender-atp/commercial-gov.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index ceeb77e4c4..4fe0a45583 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -47,7 +47,7 @@ The following OS versions are not supported: - Windows 8 Pro - Windows 8.1 Enterprise -The initial release of Microsoft Defender ATP will not have immediate parity with the commercial offering. While our goal is to deliver all commercial features and functionality to our Azure Government environment, there are some capabilities not yet available that we’d like to highlight. These are the known gaps as of August 2019: +The initial release of Microsoft Defender ATP will not have immediate parity with the commercial offering. While our goal is to deliver all commercial features and functionality to our Azure Government environment, there are some capabilities not yet available that we'd like to highlight. These are the known gaps as of August 2019: ## Threat & Vulnerability Management Not currently available. From 61a42c13937feeb1711f8fd1585b602f306f9afe Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Thu, 18 Jul 2019 15:07:31 -0700 Subject: [PATCH 13/22] add gov topic --- windows/security/threat-protection/TOC.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index 4e7cc95c8e..cd29847664 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -124,8 +124,12 @@ ### [Validate licensing and complete setup](microsoft-defender-atp/licensing.md) ### [Preview features](microsoft-defender-atp/preview.md) ### [Data storage and privacy](microsoft-defender-atp/data-storage-privacy.md) +### [Microsoft Defender ATP in Azure Government ](microsoft-defender-atp/commercial-gov.md) ### [Assign user access to the portal](microsoft-defender-atp/assign-portal-access.md) + + + ### [Evaluate Microsoft Defender ATP]() #### [Attack surface reduction and next-generation capability evaluation]() ##### [Attack surface reduction and nex-generation evaluation overview](microsoft-defender-atp/evaluate-atp.md) From d885551ae3d0616266bd054d1e380cf1433bb126 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Thu, 18 Jul 2019 15:10:50 -0700 Subject: [PATCH 14/22] note update --- .../threat-protection/microsoft-defender-atp/commercial-gov.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index 4fe0a45583..d598e63b2b 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -35,7 +35,7 @@ The following OS versions are supported: - Windows Server, 2019 (with [KB4490481](https://support.microsoft.com/en-us/help/4490481)) >[!NOTE] ->If patches are not implemented after the machine onboarding, some Microsoft Defender ATP telemetry might be sent to the Microsoft Defender ATP Commercial Cloud. +>A patch must be deployed before machine onboarding in order to configure Microsoft Defender ATP to the correct environment. The following OS versions are not supported: - Windows Server 2008 R2 SP1 From 6cb3eec7883d92cb6a099b3059535f8fc31b4df8 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Mon, 22 Jul 2019 13:55:29 -0700 Subject: [PATCH 15/22] update topic title and sections --- windows/security/threat-protection/TOC.md | 3 +-- .../microsoft-defender-atp/commercial-gov.md | 4 ++-- 2 files changed, 3 insertions(+), 4 deletions(-) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index 935138e41b..cd28df105d 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -116,7 +116,7 @@ ### [Microsoft Threat Experts](microsoft-defender-atp/microsoft-threat-experts.md) ### [Portal overview](microsoft-defender-atp/portal-overview.md) - +### [Microsoft Defender ATP for US Government customers](microsoft-defender-atp/commercial-gov.md) ## [Get started]() ### [What's new in Microsoft Defender ATP](microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md) @@ -124,7 +124,6 @@ ### [Validate licensing and complete setup](microsoft-defender-atp/licensing.md) ### [Preview features](microsoft-defender-atp/preview.md) ### [Data storage and privacy](microsoft-defender-atp/data-storage-privacy.md) -### [Microsoft Defender ATP in Azure Government ](microsoft-defender-atp/commercial-gov.md) ### [Assign user access to the portal](microsoft-defender-atp/assign-portal-access.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index d598e63b2b..f364c1ba2e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -17,12 +17,12 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Microsoft Defender ATP in Azure Government +# Microsoft Defender ATP for US Government customers **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) in Azure Government uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for Azure Government version. +Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) in Azure Government uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for Office 365 GCC High customers. ## Endpoint versions From 0d8f5f11e863723740c73f00295abb56f91fede8 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Mon, 22 Jul 2019 13:59:20 -0700 Subject: [PATCH 16/22] add device sharing for intune details --- .../microsoft-defender-atp/commercial-gov.md | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index f364c1ba2e..5b520ffe75 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -22,7 +22,9 @@ ms.topic: conceptual **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) in Azure Government uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for Office 365 GCC High customers. +Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for US Government customers uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. + +This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for Office 365 GCC High customers. ## Endpoint versions @@ -76,7 +78,7 @@ Integrations with the following Microsoft products are not currently available: - Office 365 Advanced Threat Protection - Microsoft Cloud App Security - Skype for Business -- Microsoft Intune +- Microsoft Intune (sharing of device information and enhanced policy enforcement) ## Microsoft Threat Experts Not currently available. From 3de806d87bbe2b130c2707c69e95119191a65c80 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Mon, 22 Jul 2019 14:13:14 -0700 Subject: [PATCH 17/22] add macos in not supported --- .../threat-protection/microsoft-defender-atp/commercial-gov.md | 1 + 1 file changed, 1 insertion(+) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index 5b520ffe75..26de307f2e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -48,6 +48,7 @@ The following OS versions are not supported: - Windows 7 SP1 Pro - Windows 8 Pro - Windows 8.1 Enterprise +- macOS The initial release of Microsoft Defender ATP will not have immediate parity with the commercial offering. While our goal is to deliver all commercial features and functionality to our Azure Government environment, there are some capabilities not yet available that we'd like to highlight. These are the known gaps as of August 2019: From 71f805192d5f072ad4e43243c064ddb4b7463cbe Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Tue, 23 Jul 2019 17:24:27 -0700 Subject: [PATCH 18/22] updates from pms --- .../microsoft-defender-atp/commercial-gov.md | 17 ++++++++--------- .../overview-secure-score.md | 2 +- 2 files changed, 9 insertions(+), 10 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index 26de307f2e..b31826876f 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -1,7 +1,7 @@ --- -title: Microsoft Defender ATP in Azure Government -description: Learn about the requirements and the available Microsoft Defender ATP capabilities in Azure Government -keywords: government, requirements, capabilities, azure, defender, defender atp, mdatp +title: Microsoft Defender ATP for US Government CCC High customers +description: Learn about the requirements and the available Microsoft Defender ATP capabilities for US Government CCC High customers +keywords: government, gcc, high, requirements, capabilities, defender, defender atp, mdatp search.product: eADQiWindows 10XVcnh search.appverid: met150 ms.prod: w10 @@ -17,14 +17,14 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Microsoft Defender ATP for US Government customers +# Microsoft Defender ATP for US Government CCC High customers **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for US Government customers uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. +Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for US Government GCC High customers, built in the US Azure Government environment, uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. -This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for Office 365 GCC High customers. +This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for this offering. ## Endpoint versions @@ -50,8 +50,7 @@ The following OS versions are not supported: - Windows 8.1 Enterprise - macOS -The initial release of Microsoft Defender ATP will not have immediate parity with the commercial offering. While our goal is to deliver all commercial features and functionality to our Azure Government environment, there are some capabilities not yet available that we'd like to highlight. These are the known gaps as of August 2019: - +The initial release of Microsoft Defender ATP will not have immediate parity with the commercial offering. While our goal is to deliver all commercial features and functionality to our Office 365 GCC High customers, there are some capabilities not yet available that we'd like to highlight. These are the known gaps for US GCC High customers as of August 2019: ## Threat & Vulnerability Management Not currently available. @@ -64,7 +63,7 @@ The following capabilities are not currently available: ## Management and APIs -The following capabilities are not available: +The following capabilities are not currently available: - Threat protection report - Machine health and compliance report diff --git a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md index cb57adc063..2dd209c645 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md +++ b/windows/security/threat-protection/microsoft-defender-atp/overview-secure-score.md @@ -43,7 +43,7 @@ The Microsoft secure score tile is reflective of the sum of all the Windows Defe Each Windows Defender security control contributes 100 points to the score. The total number is reflective of the score potential and calculated by multiplying the number of supported security controls (Microsoft Defender security controls pillars) by the maximum points that each pillar contributes (maximum of 100 points for each pillar). -The Office 365 Secure Score looks at your settings and activities and compares them to a baseline established by Microsoft. For more information, see [Introducing the Office 365 Secure Score](https://support.office.com/en-us/article/introducing-the-office-365-secure-score-c9e7160f-2c34-4bd0-a548-5ddcc862eaef#howtoaccess). +The Office 365 Secure Score looks at your settings and activities and compares them to a baseline established by Microsoft. For more information, see [Introducing the Office 365 Secure Score](https://support.office.com/article/introducing-the-office-365-secure-score-c9e7160f-2c34-4bd0-a548-5ddcc862eaef#howtoaccess). In the example image, the total points for the Windows security controls and Office 365 add up to 602 points. From ec9b70e68ab3c4710e3b650d3f9dd4251e5dec80 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 24 Jul 2019 10:15:40 -0700 Subject: [PATCH 19/22] initial release line --- .../threat-protection/microsoft-defender-atp/commercial-gov.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index b31826876f..9da9f189ee 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -50,7 +50,8 @@ The following OS versions are not supported: - Windows 8.1 Enterprise - macOS -The initial release of Microsoft Defender ATP will not have immediate parity with the commercial offering. While our goal is to deliver all commercial features and functionality to our Office 365 GCC High customers, there are some capabilities not yet available that we'd like to highlight. These are the known gaps for US GCC High customers as of August 2019: +The initial release of Microsoft Defender ATP will not have immediate parity with the commercial offering. While our goal is to deliver all commercial features and functionality to our US Government (GCC High) customers, there are some capabilities not yet available that we'd like to highlight. These are the known gaps as of August 2019: + ## Threat & Vulnerability Management Not currently available. From 78f85d1e5e4ed1116d1eace3eb915f721def8990 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 24 Jul 2019 10:18:22 -0700 Subject: [PATCH 20/22] update title --- .../microsoft-defender-atp/commercial-gov.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index 9da9f189ee..bc995f094e 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -1,5 +1,5 @@ --- -title: Microsoft Defender ATP for US Government CCC High customers +title: Microsoft Defender ATP for US Government GCC High customers description: Learn about the requirements and the available Microsoft Defender ATP capabilities for US Government CCC High customers keywords: government, gcc, high, requirements, capabilities, defender, defender atp, mdatp search.product: eADQiWindows 10XVcnh @@ -17,14 +17,14 @@ ms.collection: M365-security-compliance ms.topic: conceptual --- -# Microsoft Defender ATP for US Government CCC High customers +# Microsoft Defender ATP for US Government GCC High customers **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for US Government GCC High customers, built in the US Azure Government environment, uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. -This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for this offering. +This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for this offering. ## Endpoint versions From a52a8fefc27dbcbcc6f3280b5a1862f685d83c6f Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 24 Jul 2019 10:19:35 -0700 Subject: [PATCH 21/22] typo --- .../threat-protection/microsoft-defender-atp/commercial-gov.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index bc995f094e..9e64eb5d76 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -90,7 +90,7 @@ You'll need to ensure that traffic from the following are allowed: Service location | DNS record :---|:--- Common URLs for all locations (Global location) | ```crl.microsoft.com```
```ctldl.windowsupdate.com```
```notify.windows.com``` -Microsoft Defender ATP GCC high specific | ```us4-v20.events.data.microsoft.com```
```winatp-gw-usgt.microsoft.com```
```winatp-gw-usgv.microsoft.com```
```*.blob.core.usgovcloudapi.net``` +Microsoft Defender ATP GCC High specific | ```us4-v20.events.data.microsoft.com```
```winatp-gw-usgt.microsoft.com```
```winatp-gw-usgv.microsoft.com```
```*.blob.core.usgovcloudapi.net``` From 798c2d12ba16473e80e5af281ab6585524b3f4c5 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Fri, 26 Jul 2019 15:51:10 -0700 Subject: [PATCH 22/22] gcc --- windows/security/threat-protection/TOC.md | 2 +- .../threat-protection/microsoft-defender-atp/commercial-gov.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/TOC.md b/windows/security/threat-protection/TOC.md index 4709a971cb..017ba4df6d 100644 --- a/windows/security/threat-protection/TOC.md +++ b/windows/security/threat-protection/TOC.md @@ -129,7 +129,7 @@ ### [Microsoft Threat Experts](microsoft-defender-atp/microsoft-threat-experts.md) ### [Portal overview](microsoft-defender-atp/portal-overview.md) -### [Microsoft Defender ATP for US Government customers](microsoft-defender-atp/commercial-gov.md) +### [Microsoft Defender ATP for US Government Community Cloud High customers](microsoft-defender-atp/commercial-gov.md) ## [Get started]() ### [What's new in Microsoft Defender ATP](microsoft-defender-atp/whats-new-in-microsoft-defender-atp.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md index 9e64eb5d76..dfff630e9d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md +++ b/windows/security/threat-protection/microsoft-defender-atp/commercial-gov.md @@ -22,7 +22,7 @@ ms.topic: conceptual **Applies to:** - [Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) -Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for US Government GCC High customers, built in the US Azure Government environment, uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. +Microsoft Defender Advanced Threat Protection (Microsoft Defender ATP) for US Government Community Cloud High (GCC High) customers, built in the US Azure Government environment, uses the same underlying technologies as Microsoft Defender ATP in Azure Commercial. This offering is currently available to US Office 365 GCC High customers and is based on the same prevention, detection, investigation, and remediation as the commercial version. However, there are some key differences in the availability of capabilities for this offering.