diff --git a/windows/keep-secure/TOC.md b/windows/keep-secure/TOC.md index ab2757958f..56f8c27db1 100644 --- a/windows/keep-secure/TOC.md +++ b/windows/keep-secure/TOC.md @@ -402,6 +402,29 @@ #### [How User Account Control works](how-user-account-control-works.md) #### [User Account Control security policy settings](user-account-control-security-policy-settings.md) #### [User Account Control Group Policy and registry key settings](user-account-control-group-policy-and-registry-key-settings.md) +### [Windows Defender Advanced Threat Protection](windows-defender-advanced-threat-protection.md) +#### [Minimum requirements](minimum-requirements-windows-defender-advanced-threat-protection.md) +#### [Data storage and privacy](data-storage-privacy-windows-defender-advanced-threat-protection.md) +#### [Onboard endpoints and set up access](onboard-configure-windows-defender-advanced-threat-protection.md) + +##### [Configure endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +##### [Configure proxy and Internet settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) +##### [Additional configuration settings](additional-configuration-windows-defender-advanced-threat-protection.md) +##### [Monitor onboarding](monitor-onboarding-windows-defender-advanced-threat-protection.md) +##### [Troubleshoot onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) +#### [Portal overview](portal-overview-windows-defender-advanced-threat-protection.md) +#### [Use the Windows Defender ATP portal](use-windows-defender-advanced-threat-protection.md) +##### [View the Dashboard](dashboard-windows-defender-advanced-threat-protection.md) +##### [View and organize the Alerts queue](alerts-queue-windows-defender-advanced-threat-protection.md) +##### [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +##### [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md) +##### [Investigate files](investigate-files-windows-defender-advanced-threat-protection.md) +##### [Investigate an IP address](investigate-ip-windows-defender-advanced-threat-protection.md) +##### [Investigate a domain](investigate-domain-windows-defender-advanced-threat-protection.md) +##### [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +#### [Windows Defender ATP settings](settings-windows-defender-advanced-threat-protection.md) +#### [Troubleshoot Windows Defender ATP](troubleshoot-windows-defender-advanced-threat-protection.md) +#### [Review events and errors on endpoints with Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md) ### [Windows Defender in Windows 10](windows-defender-in-windows-10.md) #### [Update and manage Windows Defender in Windows 10](get-started-with-windows-defender-for-windows-10.md) #### [Configure Windows Defender in Windows 10](configure-windows-defender-in-windows-10.md) @@ -412,4 +435,3 @@ ### [Microsoft Passport guide](microsoft-passport-guide.md) ### [Windows 10 Mobile security guide](windows-10-mobile-security-guide.md) ### [Windows 10 security overview](windows-10-security-guide.md) - diff --git a/windows/keep-secure/additional-configuration-windows-defender-advanced-threat-protection.md b/windows/keep-secure/additional-configuration-windows-defender-advanced-threat-protection.md new file mode 100644 index 0000000000..604d4ba268 --- /dev/null +++ b/windows/keep-secure/additional-configuration-windows-defender-advanced-threat-protection.md @@ -0,0 +1,46 @@ +--- +title: Additional Windows Defender ATP configuration settings +description: Use the Group Policy Console to configure settings that enable sample sharing from your endpoints. These settings are used in the deep analysis feature. +keywords: configuration settings, Windows Defender ATP configuration settings, Windows Defender Advanced Threat Protection configuration settings, group policy Management Editor, computer configuration, policies, administrative templates, +search.product: eADQiWindows 10XVcnh +ms.prod: W10 +ms.mktglfcycl: deploy +ms.sitesec: library +author: mjcaparas +--- + +# Additional Windows Defender ATP configuration settings + +**Applies to** + +- Windows 10 Insider Preview Build 14332 or later +- Windows Defender Advanced Threat Protection (Windows Defender ATP) + +[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.] + +You can use Group Policy (GP) to configure settings, such as settings for the sample sharing used in the deep analysis feature. + +## Configure sample collection settings with Group Policy +1. On your GP management machine, copy the following files from the + configuration package: + + a. Copy _AtpConfiguration.admx_ into _C:\\Windows\\PolicyDefinitions_ + + b. Copy _AtpConfiguration.adml_ into _C:\\Windows\\PolicyDefinitions\\en-US_ + +2. Open the [Group Policy Management Console](https://technet.microsoft.com/en-us/library/cc731212.aspx), right-click the GPO you want to configure and click **Edit**. + +3. In the **Group Policy Management Editor**, go to **Computer configuration**. + +4. Click **Policies**, then **Administrative templates**. + +5. Click **Windows components** and then **Windows Advanced Threat Protection**. + +6. Choose to enable or disable sample sharing from your endpoints. + +## Related topics + +- [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +- [Configure endpoint proxy and Internet connectivity settings](configure-proxy-internet-windows-defender-advanced-threat-protection.md) +- [Monitor the Windows Defender ATP onboarding](monitor-onboarding-windows-defender-advanced-threat-protection.md) +- [Troubleshoot Windows Defender Advanced Threat Protection onboarding issues](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md) diff --git a/windows/keep-secure/alerts-queue-windows-defender-advanced-threat-protection.md b/windows/keep-secure/alerts-queue-windows-defender-advanced-threat-protection.md new file mode 100644 index 0000000000..ee4ce0a4a9 --- /dev/null +++ b/windows/keep-secure/alerts-queue-windows-defender-advanced-threat-protection.md @@ -0,0 +1,70 @@ +--- +title: View and organize the Windows Defender ATP Alerts queue +description: Learn about how the Windows Defender ATP alerts queue work, and how to sort and filter lists of alerts. +keywords: alerts, queues, alerts queue, sort, order, filter, manage alerts, new, in progress, resolved, newest, time in queue, severity, time period +search.product: eADQiWindows 10XVcnh +ms.prod: W10 +ms.mktglfcycl: deploy +ms.sitesec: library +author: mjcaparas +--- + +# View and organize the Windows Defender Advanced Threat Protection Alerts queue + +**Applies to:** + +- Windows 10 Insider Preview Build 14332 or later +- Windows Defender Advanced Threat Protection (Windows Defender ATP) + +[Some information relates to pre-released product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.] + +As a security operations team member, you can manage Windows Defender ATP alerts as part of your routine activities. Alerts will appear in queues according to their current status. + +To see a list of alerts, click any of the queues under the **Alerts queue** option in the navigation pane. + +> **Note** By default, the queues are sorted from newest to oldest. + +The following table and screenshot demonstrate the main areas of the **Alerts queue**. + + + +Highlighted area|Area name|Description +:---|:---|:--- +(1)|**Alerts queue**| Select to show **New**, **In Progress**, or **Resolved alerts** +(2)|Alerts|Each alert shows:
Event ID | +Message | +Description | +Action | +
---|---|---|---|
1 | +Windows Advanced Threat Protection service started (Version ```variable```). | +Occurs during system start up, shut down, and during onbboarding. | +Normal operating notification; no action required. | +
2 | +Windows Advanced Threat Protection service shutdown. | +Occurs when the endpoint is shut down or offboarded. | +Normal operating notification; no action required. | +
3 | +Windows Advanced Threat Protection service failed to start. Failure code: ```variable``` | +Service did not start. | +Review other messages to determine possible cause and troubleshooting steps. | +
4 | +Windows Advanced Threat Protection service contacted the server at ```variable```. | +variable = URL of the Windows Defender ATP processing servers. +This URL will match that seen in the Firewall or network activity. |
+Normal operating notification; no action required. | +
5 | +Windows Advanced Threat Protection service failed to connect to the server at ```variable```. | +variable = URL of the Windows Defender ATP processing servers. +The service could not contact the external processing servers at that URL. |
+Check the connection to the URL. See [Configure proxy and Internet connectivity](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#configure-proxy-and-Internet-connectivity). | +
6 | +Windows Advanced Threat Protection service is not onboarded and no onboarding parameters were found. | +The endpoint did not onboard correctly and will not be reporting to the portal. | +Onboarding must be run before starting the service. +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md). |
+
7 | +Windows Advanced Threat Protection service failed to read the onboarding parameters. Failure code: ```variable``` | +The endpoint did not onboard correctly and will not be reporting to the portal. | +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
8 | +Windows Advanced Threat Protection service failed to clean its configuration. Failure code: ```variable``` | +The endpoint did not onboard correctly and will not be reporting to the portal. | +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
9 | +Windows Advanced Threat Protection service failed to change its start type. Failure code: ```variable``` | +The endpoint did not onboard correctly and will not be reporting to the portal. | +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
10 | +Windows Advanced Threat Protection service failed to persist the onboarding information. Failure code: ```variable``` | +The endpoint did not onboard correctly and will not be reporting to the portal. | +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
11 | +Windows Advanced Threat Protection service completed. | +The endpoint onboarded correctly. | +Normal operating notification; no action required. +It may take several hours for the endpoint to appear in the portal. |
+
12 | +Windows Advanced Threat Protection failed to apply the default configuration. | +Service was unable to apply configuration from the processing servers. | +This is a server error and should resolve after a short period. | +
13 | +Service machine ID calculated: ```variable``` | +Normal operating process. | +Normal operating notification; no action required. | +
14 | +Service cannot calculate machine ID. Failure code: ```variable``` | +Internal error. | +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
15 | +Windows Advanced Threat Protection cannot start command channel with URL: ```variable``` | +variable = URL of the Windows Defender ATP processing servers. +The service could not contact the external processing servers at that URL. |
+Check the connection to the URL. See [Configure proxy and Internet connectivity](#configure-proxy-and-Internet-connectivity). | +
17 | +Windows Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: ```variable``` | +An error occurred with the Windows telemetry service. | +[Ensure the telemetry service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-the-telemetry-and-diagnostics-service-is-enabled) +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
18 | +OOBE (Windows Welcome) is completed. | +Service will only start after any Windows updates have finished installing. | +Normal operating notification; no action required. | +
19 | +OOBE (Windows Welcome) has not yet completed. | +Service will only start after any Windows updates have finished installing. | +Normal operating notification; no action required. +If this error persists after a system restart, ensure all Windows updates have full installed. |
+
20 | +Cannot wait for OOBE (Windows Welcome) to complete. Failure code: ```variable``` | +Internal error. | +If this error persists after a system restart, ensure all Windows updates have full installed. | +
25 | +Windows Advanced Threat Protection service failed to reset health status in the registry, causing the onboarding process to fail. Failure code: ```variable``` | +The endpoint did not onboard correctly and will not be reporting to the portal. | +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
26 | +Windows Advanced Threat Protection service failed to set the onboarding status in the registry. Failure code: ```variable``` | +The endpoint did not onboard correctly. +It will report to the portal, however the service may not appear as registered in SCCM or the registry. |
+Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
27 | +Windows Advanced Threat Protection service failed to enable SENSE aware mode in Windows Defender. Onboarding process failed. Failure code: ```variable``` | +Normally, Windows Defender will enter a special passive state if another real-time antimalware product is running properly on the endpoint, and the endpoint is reporting to Windows Defender ATP. | +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +Ensure real-time antimalware protection is running properly. |
+
28 | +Windows Advanced Threat Protection Connected User Experiences and Telemetry service registration failed. Failure code: ```variable``` | +An error occurred with the Windows telemetry service. | +[Ensure the telemetry service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-the-telemetry-and-diagnostics-service-is-enabled). +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
30 | +Windows Advanced Threat Protection service failed to disable SENSE aware mode in Windows Defender. Failure code: ```variable``` | +Normally, Windows Defender will enter a special passive state if another real-time antimalware product is running properly on the endpoint, and the endpoint is reporting to Windows Defender ATP. | +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) +Ensure real-time antimalware protection is running properly. |
+
31 | +Windows Advanced Threat Protection Connected User Experiences and Telemetry service unregistration failed. Failure code: ```variable``` | +An error occurred with the Windows telemetry service. | +[Check for errors with the Windows telemetry service](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-the-telemetry-and-diagnostics-service-is-enabled). | +
33 | +Windows Advanced Threat Protection service failed to persist SENSE GUID. Failure code: ```variable``` | +A unique identifier is used to represent each endpoint that is reporting to the portal. +If the identifier does not persist, the same machine might appear twice in the portal. |
+Check registry permissions on the endpoint to ensure the service can update the registry. | +
34 | +Windows Advanced Threat Protection service failed to add itself as a dependency on the Connected User Experiences and Telemetry service, causing onboarding process to fail. Failure code: ```variable``` | +An error occurred with the Windows telemetry service. | +[Ensure the telemetry service is enabled](troubleshoot-onboarding-windows-defender-advanced-threat-protection.md#ensure-that-the-telemetry-and-diagnostics-service-is-enabled). +Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. +See [Configure Windows Defender ATP endpoints](configure-endpoints-windows-defender-advanced-threat-protection.md) |
+
Topic | -Description | -
---|---|
[AppLocker](applocker-overview.md) |
-This topic provides a description of AppLocker and can help you decide if your organization can benefit from deploying AppLocker application control policies. AppLocker helps you control which apps and files users can run. These include executable files, scripts, Windows Installer files, dynamic-link libraries (DLLs), packaged apps, and packaged app installers. |
-
[BitLocker](bitlocker-overview.md) |
-This topic provides a high-level overview of BitLocker, including a list of system requirements, practical applications, and deprecated features. |
-
[Encrypted Hard Drive](encrypted-hard-drive.md) |
-Encrypted Hard Drive uses the rapid encryption that is provided by BitLocker Drive Encryption to enhance data security and management. |
-
[Security auditing](security-auditing-overview.md) |
-Topics in this section are for IT professionals and describes the security auditing features in Windows and how your organization can benefit from using these technologies to enhance the security and manageability of your network. |
-
[Security policy settings](security-policy-settings.md) |
-This reference topic describes the common scenarios, architecture, and processes for security settings. |
-
[Trusted Platform Module](trusted-platform-module-overview.md) |
-This topic for the IT professional describes the Trusted Platform Module (TPM) and how Windows uses it for access control and authentication. The topic provides links to other resources about the TPM. |
-
[User Account Control](user-account-control-overview.md) |
-User Account Control (UAC) helps prevent malware from damaging a PC and helps organizations deploy a better-managed desktop. With UAC, apps and tasks always run in the security context of a non-administrator account, unless an administrator specifically authorizes administrator-level access to the system. UAC can block the automatic installation of unauthorized apps and prevent inadvertent changes to system settings. |
-
[Windows Defender in Windows 10](windows-defender-in-windows-10.md) |
-This topic provides an overview of Windows Defender, including a list of system requirements and new features. |
-