From fc73b3fa9a7602da2e908bbb753c54914abff352 Mon Sep 17 00:00:00 2001 From: Joey Caparas Date: Wed, 15 Feb 2017 19:56:48 -0800 Subject: [PATCH] add new topics --- windows/keep-secure/TOC.md | 83 ++++++++++--------- ...ows-defender-advacned-threat-protection.md | 33 ++++++++ ...ows-defender-advanced-threat-protection.md | 38 +++++++++ ...ows-defender-advanced-threat-protection.md | 32 +++++++ ...ows-defender-advanced-threat-protection.md | 32 +++++++ 5 files changed, 181 insertions(+), 37 deletions(-) create mode 100644 windows/keep-secure/advanced-features-windows-defender-advacned-threat-protection.md create mode 100644 windows/keep-secure/general-settings-windows-defender-advanced-threat-protection.md create mode 100644 windows/keep-secure/preferences-setup-windows-defender-advanced-threat-protection.md create mode 100644 windows/keep-secure/preview-settings-windows-defender-advanced-threat-protection.md diff --git a/windows/keep-secure/TOC.md b/windows/keep-secure/TOC.md index 2e5591dc1b..c07edd22e9 100644 --- a/windows/keep-secure/TOC.md +++ b/windows/keep-secure/TOC.md @@ -738,50 +738,59 @@ #### [Understand the Dashboard](dashboard-windows-defender-advanced-threat-protection.md) #### [Use the Windows Defender ATP portal](use-windows-defender-advanced-threat-protection.md) #### [Alerts queue overview](alerts-queue-windows-defender-advanced-threat-protection.md) -#### [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) -##### [Alert process tree](investigate-alerts-windows-defender-advanced-threat-protection.md#alert-process-tree) -##### [Incident graph](investigate-alerts-windows-defender-advanced-threat-protection.md#incident-graph) -##### [Alert timeline](investigate-alerts-windows-defender-advanced-threat-protection.md#alert-timeline) -#### [Consume alerts and create custom threat intelligence](configure-siem-windows-defender-advanced-threat-protection.md) -##### [Configure an Azure Active Directory application for SIEM integration](configure-aad-windows-defender-advanced-threat-protection.md) -##### [Configure Splunk to consume Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) -##### [Configure HP ArcSight to consume Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -##### [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -###### [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) -###### [Create custom threat intelligence using REST API](custom-ti-api-windows-defender-advanced-threat-protection.md) -###### [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) -#### [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +##### [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +###### [Alert process tree](investigate-alerts-windows-defender-advanced-threat-protection.md#alert-process-tree) +###### [Incident graph](investigate-alerts-windows-defender-advanced-threat-protection.md#incident-graph) +###### [Alert timeline](investigate-alerts-windows-defender-advanced-threat-protection.md#alert-timeline) +##### [Consume alerts and create custom threat intelligence](configure-siem-windows-defender-advanced-threat-protection.md) +###### [Configure an Azure Active Directory application for SIEM integration](configure-aad-windows-defender-advanced-threat-protection.md) +###### [Configure Splunk to consume Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) +###### [Configure HP ArcSight to consume Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) +###### [Understand threat intelligence concepts](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) +####### [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) +####### [Create custom threat intelligence using REST API](custom-ti-api-windows-defender-advanced-threat-protection.md) +####### [Troubleshoot custom threat intelligence issues](troubleshoot-custom-ti-windows-defender-advanced-threat-protection.md) +##### [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) #### [Machines view overview](machines-view-overview-windows-defender-advanced-threat-protection.md) -#### [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md) -##### [Search for specific alerts](investigate-machines-windows-defender-advanced-threat-protection.md#search-for-specific-alerts) -##### [Filter events from a specific date](investigate-machines-windows-defender-advanced-threat-protection.md#filter-events-from-a-specific-date) -##### [Export machine timeline events](investigate-machines-windows-defender-advanced-threat-protection.md#export-machine-timeline-events) -##### [Navigate between pages](investigate-machines-windows-defender-advanced-threat-protection.md#navigate-between-pages) -#### [Respond to machine alerts](respond-machine-alerts-windows-defender-advanced-threat-protection.md) -##### [Isolate machines from the network](respond-machine-alerts-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network) -##### [Undo machine isolation](respond-machine-alerts-windows-defender-advanced-threat-protection.md#undo-machine-isolation) -##### [Collect investigation package](respond-machine-alerts-windows-defender-advanced-threat-protection.md#collect-investigation-package) -##### [Check activity details in Action center](respond-machine-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) +##### [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md) +###### [Search for specific alerts](investigate-machines-windows-defender-advanced-threat-protection.md#search-for-specific-alerts) +###### [Filter events from a specific date](investigate-machines-windows-defender-advanced-threat-protection.md#filter-events-from-a-specific-date) +###### [Export machine timeline events](investigate-machines-windows-defender-advanced-threat-protection.md#export-machine-timeline-events) +###### [Navigate between pages](investigate-machines-windows-defender-advanced-threat-protection.md#navigate-between-pages) +##### [Respond to machine alerts](respond-machine-alerts-windows-defender-advanced-threat-protection.md) +###### [Isolate machines from the network](respond-machine-alerts-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network) +###### [Undo machine isolation](respond-machine-alerts-windows-defender-advanced-threat-protection.md#undo-machine-isolation) +###### [Collect investigation package](respond-machine-alerts-windows-defender-advanced-threat-protection.md#collect-investigation-package) +###### [Check activity details in Action center](respond-machine-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) +##### [Check sensor status](check-sensor-status-windows-defender-advanced-threat-protection.md) +###### [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md) +####### [Inactive machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#inactive-machines) +####### [Misconfigured machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#misconfigured-machines) #### [Investigate files](investigate-files-windows-defender-advanced-threat-protection.md) -#### [Respond to file related alerts](respond-file-alerts-windows-defender-advanced-threat-protection.md) -##### [Stop and quarantine files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#stop-and-quarantine-files-in-your-network) -##### [Remove file from quarantine](respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-quarantine) -##### [Block files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#block-files-in-your-network) -##### [Check activity details in Action center](respond-file-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) -##### [Deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis) -###### [Submit files for analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#submit-files-for-analysis) -###### [View deep analysis reports](respond-file-alerts-windows-defender-advanced-threat-protection.md#view-deep-analysis-reports) -###### [Troubleshoot deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#troubleshoot-deep-analysis) +##### [Respond to file related alerts](respond-file-alerts-windows-defender-advanced-threat-protection.md) +###### [Stop and quarantine files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#stop-and-quarantine-files-in-your-network) +###### [Remove file from quarantine](respond-file-alerts-windows-defender-advanced-threat-protection.md#remove-file-from-quarantine) +###### [Block files in your network](respond-file-alerts-windows-defender-advanced-threat-protection.md#block-files-in-your-network) +###### [Check activity details in Action center](respond-file-alerts-windows-defender-advanced-threat-protection.md#check-activity-details-in-action-center) +###### [Deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#deep-analysis) +####### [Submit files for analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#submit-files-for-analysis) +####### [View deep analysis reports](respond-file-alerts-windows-defender-advanced-threat-protection.md#view-deep-analysis-reports) +####### [Troubleshoot deep analysis](respond-file-alerts-windows-defender-advanced-threat-protection.md#troubleshoot-deep-analysis) #### [Investigate a user entity](investigate-user-entity-windows-defender-advanced-threat-protection.md) #### [Investigate an IP address](investigate-ip-windows-defender-advanced-threat-protection.md) #### [Investigate a domain](investigate-domain-windows-defender-advanced-threat-protection.md) -#### [Check sensor status](check-sensor-status-windows-defender-advanced-threat-protection.md) -##### [Fix unhealthy sensors](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md) -###### [Inactive machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#inactive-machines) -###### [Misconfigured machines](fix-unhealhty-sensors-windows-defender-advanced-threat-protection.md#misconfigured-machines) +#### [Windows Defender ATP preferences settings](preferences-setup-windows-defender-advanced-threat-protection.md) +##### [Update general settings](general-settings-windows-defender-advanced-threat-protection.md) +##### [Enable advanced features](advanced-features-windows-defender-advacned-threat-protection.md) +##### [Enable preview experience](preview-settings-windows-defender-advanced-threat-protection.md) +##### [Configure email notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) +##### [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) + + + #### [Windows Defender ATP settings](settings-windows-defender-advanced-threat-protection.md) #### [Windows Defender ATP service status](service-status-windows-defender-advanced-threat-protection.md) -#### [Configure email notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) + #### [Troubleshoot Windows Defender ATP](troubleshoot-windows-defender-advanced-threat-protection.md) #### [Review events and errors on endpoints with Event Viewer](event-error-codes-windows-defender-advanced-threat-protection.md) #### [Windows Defender compatibility](defender-compatibility-windows-defender-advanced-threat-protection.md) diff --git a/windows/keep-secure/advanced-features-windows-defender-advacned-threat-protection.md b/windows/keep-secure/advanced-features-windows-defender-advacned-threat-protection.md new file mode 100644 index 0000000000..d4932f4fe4 --- /dev/null +++ b/windows/keep-secure/advanced-features-windows-defender-advacned-threat-protection.md @@ -0,0 +1,33 @@ +--- +title: Enable advanced features in Windows Defender Advanced Threat Protection +description: Enable advanced features such as block file in Windows Defender Advanced Threat Protection. +keywords: advanced features, preferences setup, block file +search.product: eADQiWindows 10XVcnh +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +author: mjcaparas +localizationpriority: high +--- +# Enable advanced features in Windows Defender ATP + +**Applies to:** + +- Windows 10 Enterprise +- Windows 10 Education +- Windows 10 Pro +- Windows 10 Pro Education +- Windows Defender Advanced Threat Protection (Windows Defender ATP) + +[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.] + +1. In the navigation pane, select **Preferences setup** > **Advanced features**. +2. Select the advanced feature you want to configure and toggle the setting between **On** and **Off**. +3. Click **Save preferences**. + +## Related topics +- [General settings](general-settings-windows-defender-advanced-threat-protection.md) +- [Preview experience](preview-settings-windows-defender-advanced-threat-protection.md) +- [Configure email notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) diff --git a/windows/keep-secure/general-settings-windows-defender-advanced-threat-protection.md b/windows/keep-secure/general-settings-windows-defender-advanced-threat-protection.md new file mode 100644 index 0000000000..73f2e9f3b0 --- /dev/null +++ b/windows/keep-secure/general-settings-windows-defender-advanced-threat-protection.md @@ -0,0 +1,38 @@ +--- +title: Update general Windows Defender Advanced Threat Protection settings +description: Update your general Windows Defender Advanced Threat Protection settings after onboarding. +keywords: general settings, settings, update settings +search.product: eADQiWindows 10XVcnh +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +author: mjcaparas +localizationpriority: high +--- +# Update general Windows Defender ATP settings + +**Applies to:** + +- Windows 10 Enterprise +- Windows 10 Education +- Windows 10 Pro +- Windows 10 Pro Education +- Windows Defender Advanced Threat Protection (Windows Defender ATP) + +[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.] + +During the onboarding process, a wizard takes you through the general settings of Windows Defender ATP. After onboarding, you might want to update some settings which you'll be able to do through the **Preferences setup** menu. + +1. In the navigation pane, select **Preferences setup** > **General**. +2. Modify settings such as data retention policy or the industry that best describes your organization. + >[!NOTE] + >Other settings are not editable. +3. Click **Save preferences**. + + +## Related topics +- [Advanced features](advanced-features-windows-defender-advacned-threat-protection.md) +- [Preview experience](preview-settings-windows-defender-advanced-threat-protection.md) +- [Configure email notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md) diff --git a/windows/keep-secure/preferences-setup-windows-defender-advanced-threat-protection.md b/windows/keep-secure/preferences-setup-windows-defender-advanced-threat-protection.md new file mode 100644 index 0000000000..8c920f6077 --- /dev/null +++ b/windows/keep-secure/preferences-setup-windows-defender-advanced-threat-protection.md @@ -0,0 +1,32 @@ +--- +title: Setup Windows Defender Advanced Threat Protection preferences settings +description: Use the preferences setup to configure and update your preferences settings such as enabling advanced features, preview experience, email notifications, or custom threat intelligence. +keywords: preferences settings, settings, advanced features, preview experience, email notifications, custom threat intelligence +search.product: eADQiWindows 10XVcnh +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +author: mjcaparas +localizationpriority: high +--- +# Setup Windows Defender ATP preferences settings + +**Applies to:** + +- Windows 10 Enterprise +- Windows 10 Education +- Windows 10 Pro +- Windows 10 Pro Education +- Windows Defender Advanced Threat Protection (Windows Defender ATP) + +Use the **Preferences setup** menu to modify general settings, advanced features, enable the preview experience, email notifications, and the custom threat intelligence feature. + +## In this section + +Topic | Description +:---|:--- +General | Modify your general settings that were previously defined as part of the onboarding process. +Advanced features | Enable features such as **Block file** and other features that require integration with other products. +Preview experience | Allows you to turn on preview features so you can try upcoming features. +Email notifications | Enables you to configure and identify a group of individuals who will immediately be informed of new alerts through email notifications. diff --git a/windows/keep-secure/preview-settings-windows-defender-advanced-threat-protection.md b/windows/keep-secure/preview-settings-windows-defender-advanced-threat-protection.md new file mode 100644 index 0000000000..fe60252903 --- /dev/null +++ b/windows/keep-secure/preview-settings-windows-defender-advanced-threat-protection.md @@ -0,0 +1,32 @@ +--- +title: Enable the preview experience in Windows Defender Advanced Threat Protection +description: Enable the preview experience in Windows Defender Advanced Threat Protection to try upcoming features. +keywords: advanced features, preferences setup, block file +search.product: eADQiWindows 10XVcnh +ms.prod: w10 +ms.mktglfcycl: deploy +ms.sitesec: library +ms.pagetype: security +author: mjcaparas +localizationpriority: high +--- +# Enable the preview experience in Windows Defender ATP + +**Applies to:** + +- Windows 10 Enterprise +- Windows 10 Education +- Windows 10 Pro +- Windows 10 Pro Education +- Windows Defender Advanced Threat Protection (Windows Defender ATP) + +[Some information relates to pre-released product, which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.] + +1. In the navigation pane, select **Preferences setup** > **Preview experience**. +2. Toggle the setting between **On** and **Off** and select **Save preferences**. + +## Related topics +- [General settings](general-settings-windows-defender-advanced-threat-protection.md) +- [Advanced features](advanced-features-windows-defender-advacned-threat-protection.md) +- [Configure email notifications](configure-email-notifications-windows-defender-advanced-threat-protection.md) +- [Enable the custom threat intelligence application](enable-custom-ti-windows-defender-advanced-threat-protection.md)