Updated screenshots
Before Width: | Height: | Size: 112 KiB After Width: | Height: | Size: 117 KiB |
Before Width: | Height: | Size: 126 KiB After Width: | Height: | Size: 134 KiB |
Before Width: | Height: | Size: 52 KiB After Width: | Height: | Size: 54 KiB |
After Width: | Height: | Size: 35 KiB |
Before Width: | Height: | Size: 24 KiB After Width: | Height: | Size: 35 KiB |
Before Width: | Height: | Size: 112 KiB After Width: | Height: | Size: 121 KiB |
Before Width: | Height: | Size: 95 KiB After Width: | Height: | Size: 98 KiB |
Before Width: | Height: | Size: 43 KiB After Width: | Height: | Size: 46 KiB |
Before Width: | Height: | Size: 32 KiB |
Before Width: | Height: | Size: 104 KiB After Width: | Height: | Size: 151 KiB |
Before Width: | Height: | Size: 117 KiB After Width: | Height: | Size: 105 KiB |
Before Width: | Height: | Size: 261 KiB After Width: | Height: | Size: 86 KiB |
Before Width: | Height: | Size: 270 KiB After Width: | Height: | Size: 167 KiB |
After Width: | Height: | Size: 86 KiB |
After Width: | Height: | Size: 210 KiB |
Before Width: | Height: | Size: 97 KiB |
Before Width: | Height: | Size: 54 KiB After Width: | Height: | Size: 90 KiB |
Before Width: | Height: | Size: 99 KiB After Width: | Height: | Size: 97 KiB |
Before Width: | Height: | Size: 65 KiB After Width: | Height: | Size: 43 KiB |
Before Width: | Height: | Size: 14 KiB After Width: | Height: | Size: 14 KiB |
Before Width: | Height: | Size: 31 KiB After Width: | Height: | Size: 32 KiB |
Before Width: | Height: | Size: 13 KiB After Width: | Height: | Size: 11 KiB |
After Width: | Height: | Size: 106 KiB |
Before Width: | Height: | Size: 104 KiB |
Before Width: | Height: | Size: 78 KiB After Width: | Height: | Size: 78 KiB |
@ -55,7 +55,7 @@ You can also manage an alert and see alert metadata along with other information
|
|||||||
### Devices
|
### Devices
|
||||||
You can also investigate the devices that are part of, or related to, a given incident. For more information, see [Investigate devices](investigate-machines.md).
|
You can also investigate the devices that are part of, or related to, a given incident. For more information, see [Investigate devices](investigate-machines.md).
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
### Investigations
|
### Investigations
|
||||||
Select **Investigations** to see all the automatic investigations launched by the system in response to the incident alerts.
|
Select **Investigations** to see all the automatic investigations launched by the system in response to the incident alerts.
|
||||||
|
@ -43,7 +43,7 @@ When you investigate a specific device, you'll see:
|
|||||||
- Cards (active alerts, logged on users, security assessment)
|
- Cards (active alerts, logged on users, security assessment)
|
||||||
- Tabs (alerts, timeline, security recommendations, software inventory, discovered vulnerabilities)
|
- Tabs (alerts, timeline, security recommendations, software inventory, discovered vulnerabilities)
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
## Device details
|
## Device details
|
||||||
|
|
||||||
|
@ -27,52 +27,47 @@ ms.date: 04/24/2018
|
|||||||
|
|
||||||
## Investigate user account entities
|
## Investigate user account entities
|
||||||
|
|
||||||
Identify user accounts with the most active alerts (displayed on dashboard as "Users at risk") and investigate cases of potential compromised credentials, or pivot on the associated user account when investigating an alert or machine to identify possible lateral movement between machines with that user account.
|
Identify user accounts with the most active alerts (displayed on dashboard as "Users at risk") and investigate cases of potential compromised credentials, or pivot on the associated user account when investigating an alert or device to identify possible lateral movement between devices with that user account.
|
||||||
|
|
||||||
You can find user account information in the following views:
|
You can find user account information in the following views:
|
||||||
|
|
||||||
- Dashboard
|
- Dashboard
|
||||||
- Alert queue
|
- Alert queue
|
||||||
- Machine details page
|
- Device details page
|
||||||
|
|
||||||
A clickable user account link is available in these views, that will take you to the user account details page where more details about the user account are shown.
|
A clickable user account link is available in these views, that will take you to the user account details page where more details about the user account are shown.
|
||||||
|
|
||||||
When you investigate a user account entity, you'll see:
|
When you investigate a user account entity, you'll see:
|
||||||
|
|
||||||
- User account details, Azure Advanced Threat Protection (Azure ATP) alerts, and Logged on machines
|
- User account details, Azure Advanced Threat Protection (Azure ATP) alerts, and logged on devices, role, logon type, and other details
|
||||||
|
- Overview of the incidents and user's devices
|
||||||
- Alerts related to this user
|
- Alerts related to this user
|
||||||
- Observed in organization (machines logged on to)
|
- Observed in organization (devices logged on to)
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
The user account details, Azure ATP alerts, and logged on machines cards display various attributes about the user account.
|
|
||||||
|
|
||||||
### User details
|
### User details
|
||||||
|
|
||||||
The **User details** card provides information about the user, such as when the user was first and last seen. Depending on the integration features you've enabled, you'll see other details. For example, if you enable the Skype for business integration, you'll be able to contact the user from the portal.
|
The **User details** pane on left provides information about the user, such as related open incidents, active alerts, SAM name, SID, Azure ATP alerts, number of devices the user is logged on to, when the user was first and last seen, role, and logon types. Depending on the integration features you've enabled, you'll see other details. For example, if you enable the Skype for business integration, you'll be able to contact the user from the portal. The **Azure ATP alerts** section contains a link that will take you to the Azure ATP page, if you have enabled the Azure ATP feature, and there are alerts related to the user. The Azure ATP page will provide more information about the alerts.
|
||||||
|
|
||||||
### Azure Advanced Threat Protection
|
|
||||||
|
|
||||||
The **Azure Advanced Threat Protection** card will contain a link that will take you to the Azure ATP page, if you have enabled the Azure ATP feature, and there are alerts related to the user. The Azure ATP page will provide more information about the alerts. This card also provides details such as the last AD site, total group memberships, and login failure associated with the user.
|
|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>You'll need to enable the integration on both Azure ATP and Microsoft Defender ATP to use this feature. In Microsoft Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features.md).
|
>You'll need to enable the integration on both Azure ATP and Microsoft Defender ATP to use this feature. In Microsoft Defender ATP, you can enable this feature in advanced features. For more information on how to enable advanced features, see [Turn on advanced features](advanced-features.md).
|
||||||
|
|
||||||
### Logged on machines
|
The Overview, Alerts, and Observed in organization are different tabs that display various attributes about the user account.
|
||||||
|
|
||||||
The **Logged on machines** card shows a list of the machines that the user has logged on to. You can expand these to see details of the log-on events for each machine.
|
### Overview
|
||||||
|
|
||||||
## Alerts related to this user
|
The **Overview** tab shows the incidents details and a list of the devices that the user has logged on to. You can expand these to see details of the log-on events for each device.
|
||||||
|
|
||||||
The **Alerts related to this user** section provides a list of alerts that are associated with the user account. This list is a filtered view of the [Alert queue](alerts-queue.md), and shows alerts where the user context is the selected user account, the date when the last activity was detected, a short description of the alert, the machine associated with the alert, the alert's severity, the alert's status in the queue, and who is assigned the alert.
|
### Alerts
|
||||||
|
|
||||||
## Observed in organization
|
The **Alerts** tab provides a list of alerts that are associated with the user account. This list is a filtered view of the [Alert queue](alerts-queue.md), and shows alerts where the user context is the selected user account, the date when the last activity was detected, a short description of the alert, the device associated with the alert, the alert's severity, the alert's status in the queue, and who is assigned the alert.
|
||||||
|
|
||||||
The **Observed in organization** section allows you to specify a date range to see a list of machines where this user was observed logged on to, the most frequent and least frequent logged on user account for each of these machines, and total observed users on each machine.
|
### Observed in organization
|
||||||
|
|
||||||
Selecting an item on the Observed in organization table will expand the item, revealing more details about the machine. Directly selecting a link within an item will send you to the corresponding page.
|
The **Observed in organization** tab allows you to specify a date range to see a list of devices where this user was observed logged on to, the most frequent and least frequent logged on user account for each of these devices, and total observed users on each device.
|
||||||
|
|
||||||

|
Selecting an item on the Observed in organization table will expand the item, revealing more details about the device. Directly selecting a link within an item will send you to the corresponding page.
|
||||||
|
|
||||||
## Search for specific user accounts
|
## Search for specific user accounts
|
||||||
|
|
||||||
@ -80,7 +75,7 @@ Selecting an item on the Observed in organization table will expand the item, re
|
|||||||
2. Enter the user account in the **Search** field.
|
2. Enter the user account in the **Search** field.
|
||||||
3. Click the search icon or press **Enter**.
|
3. Click the search icon or press **Enter**.
|
||||||
|
|
||||||
A list of users matching the query text is displayed. You'll see the user account's domain and name, when the user account was last seen, and the total number of machines it was observed logged on to in the last 30 days.
|
A list of users matching the query text is displayed. You'll see the user account's domain and name, when the user account was last seen, and the total number of devices it was observed logged on to in the last 30 days.
|
||||||
|
|
||||||
You can filter the results by the following time periods:
|
You can filter the results by the following time periods:
|
||||||
|
|
||||||
@ -96,6 +91,6 @@ You can filter the results by the following time periods:
|
|||||||
- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md)
|
- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md)
|
||||||
- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md)
|
- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md)
|
||||||
- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files.md)
|
- [Investigate a file associated with a Microsoft Defender ATP alert](investigate-files.md)
|
||||||
- [Investigate machines in the Microsoft Defender ATP Machines list](investigate-machines.md)
|
- [Investigate devices in the Microsoft Defender ATP Devices list](investigate-machines.md)
|
||||||
- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip.md)
|
- [Investigate an IP address associated with a Microsoft Defender ATP alert](investigate-ip.md)
|
||||||
- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain.md)
|
- [Investigate a domain associated with a Microsoft Defender ATP alert](investigate-domain.md)
|
||||||
|
@ -26,7 +26,7 @@ ms.topic: article
|
|||||||
The devices status report provides high-level information about the devices in your organization. The report includes trending information showing the sensor health state, antivirus status, OS platforms, and Windows 10 versions.
|
The devices status report provides high-level information about the devices in your organization. The report includes trending information showing the sensor health state, antivirus status, OS platforms, and Windows 10 versions.
|
||||||
|
|
||||||
The dashboard is structured into two sections:
|
The dashboard is structured into two sections:
|
||||||

|

|
||||||
|
|
||||||
Section | Description
|
Section | Description
|
||||||
:---|:---
|
:---|:---
|
||||||
|