Skip to content

Commit 1b31ef1

Browse files
authored
Merge branch 'main' into WI91984-fix-generate-report-current-configurations-powershell
2 parents 58b3b96 + 5817382 commit 1b31ef1

File tree

174 files changed

+1629
-3013
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

174 files changed

+1629
-3013
lines changed

.openpublishing.redirection.defender-endpoint.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -165,5 +165,15 @@
165165
"redirect_url": "/defender-xdr/contact-defender-support",
166166
"redirect_document_id": false
167167
},
168+
{
169+
"source_path": "defender-endpoint/microsoft-defender-endpoint-linux.md",
170+
"redirect_url": "/defender-endpoint/install-defender-endpoint-linux",
171+
"redirect_document_id": false
172+
},
173+
{
174+
"source_path": "defender-endpoint/mde-linux-prerequisites.md",
175+
"redirect_url": "/defender-endpoint/install-defender-endpoint-linux#prerequisites",
176+
"redirect_document_id": false
177+
}
168178
]
169179
}

.openpublishing.redirection.defender-identity.json

Lines changed: 246 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -869,6 +869,252 @@
869869
"source_path": "defender-for-identity/support.md",
870870
"redirect_url": "/defender-xdr/contact-defender-support",
871871
"redirect_document_id": false
872+
},
873+
{
874+
"source_path": "defender-for-identity/assign-multi-factor-authentication-okta-privileged-user-accounts.md",
875+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
876+
"redirect_document_id": false
877+
},
878+
{
879+
"source_path": "defender-for-identity/change-okta-password-privileged-user-accounts.md",
880+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
881+
"redirect_document_id": false
882+
},
883+
{
884+
"source_path": "defender-for-identity/high-number-of-okta-accounts-with-privileged-role-assigned.md",
885+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
886+
"redirect_document_id": false
887+
},
888+
{
889+
"source_path": "defender-for-identity/highly-privileged-okta-api-token.md",
890+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
891+
"redirect_document_id": false
892+
},
893+
{
894+
"source_path": "defender-for-identity/limit-number-okta-super-admin-accounts.md",
895+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
896+
"redirect_document_id": false
897+
},
898+
{
899+
"source_path": "defender-for-identity/remove-dormant-okta-privileged-accounts.md",
900+
"redirect_url": "/defender-for-identity/security-posture-assessments/cloud-identities",
901+
"redirect_document_id": false
902+
},
903+
{
904+
"source_path": "defender-for-identity/accounts-with-non-default-pgid.md",
905+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
906+
"redirect_document_id": false
907+
},
908+
{
909+
"source_path": "defender-for-identity/security-assessment-remove-suspicious-access-rights.md",
910+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
911+
"redirect_document_id": false
912+
},
913+
{
914+
"source_path": "defender-for-identity/change-password-krbtgt-account.md",
915+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
916+
"redirect_document_id": false
917+
},
918+
{
919+
"source_path": "defender-for-identity/change-password-domain-administrator-account.md",
920+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
921+
"redirect_document_id": false
922+
},
923+
{
924+
"source_path": "defender-for-identity/security-assessment-dormant-entities.md",
925+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
926+
"redirect_document_id": false
927+
},
928+
{
929+
"source_path": "defender-for-identity/security-assessment-non-admin-accounts-dcsync.md",
930+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
931+
"redirect_document_id": false
932+
},
933+
{
934+
"source_path": "defender-for-identity/ensure-privileged-accounts-with-sensitive-flag.md",
935+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
936+
"redirect_document_id": false
937+
},
938+
{
939+
"source_path": "defender-for-identity/security-assessment-clear-text.md",
940+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
941+
"redirect_document_id": false
942+
},
943+
{
944+
"source_path": "defender-for-identity/security-assessment-laps.md",
945+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
946+
"redirect_document_id": false
947+
},
948+
{
949+
"source_path": "defender-for-identity/remove-discoverable-passwords-active-directory-account-attributes.md",
950+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
951+
"redirect_document_id": false
952+
},
953+
{
954+
"source_path": "defender-for-identity/remove-inactive-service-account.md",
955+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
956+
"redirect_document_id": false
957+
},
958+
{
959+
"source_path": "defender-for-identity/security-assessment-riskiest-lmp.md",
960+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
961+
"redirect_document_id": false
962+
},
963+
{
964+
"source_path": "defender-for-identity/security-assessment-unconstrained-kerberos.md",
965+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
966+
"redirect_document_id": false
967+
},
968+
{
969+
"source_path": "defender-for-identity/security-assessment-unsecure-sid-history-attribute.md",
970+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
971+
"redirect_document_id": false
972+
},
973+
{
974+
"source_path": "defender-for-identity/security-assessment-unsecure-account-attributes.md",
975+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
976+
"redirect_document_id": false
977+
},
978+
{
979+
"source_path": "defender-for-identity/security-assessment-weak-cipher.md",
980+
"redirect_url": "/defender-for-identity/security-posture-assessments/accounts",
981+
"redirect_document_id": false
982+
},
983+
{
984+
"source_path": "defender-for-identity/security-assessment-enforce-encryption-rpc.md",
985+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
986+
"redirect_document_id": false
987+
},
988+
{
989+
"source_path": "defender-for-identity/security-assessment-insecure-adcs-certificate-enrollment.md",
990+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
991+
"redirect_document_id": false
992+
},
993+
{
994+
"source_path": "defender-for-identity/security-assessment-edit-misconfigured-owner.md",
995+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
996+
"redirect_document_id": false
997+
},
998+
{
999+
"source_path": "defender-for-identity/security-assessment-edit-misconfigured-ca-acl.md",
1000+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1001+
"redirect_document_id": false
1002+
},
1003+
{
1004+
"source_path": "defender-for-identity/security-assessment-edit-misconfigured-acl.md",
1005+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1006+
"redirect_document_id": false
1007+
},
1008+
{
1009+
"source_path": "defender-for-identity/security-assessment-edit-misconfigured-enrollment-agent.md",
1010+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1011+
"redirect_document_id": false
1012+
},
1013+
{
1014+
"source_path": "defender-for-identity/security-assessment-edit-overly-permissive-template.md",
1015+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1016+
"redirect_document_id": false
1017+
},
1018+
{
1019+
"source_path": "defender-for-identity/prevent-certificate-enrollment-esc15.md",
1020+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1021+
"redirect_document_id": false
1022+
},
1023+
{
1024+
"source_path": "defender-for-identity/security-assessment-prevent-users-request-certificate.md",
1025+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1026+
"redirect_document_id": false
1027+
},
1028+
{
1029+
"source_path": "defender-for-identity/security-assessment-edit-vulnerable-ca-setting.md",
1030+
"redirect_url": "/defender-for-identity/security-posture-assessments/certificates",
1031+
"redirect_document_id": false
1032+
},
1033+
{
1034+
"source_path": "defender-for-identity/gpo-assigns-unprivileged-identities.md",
1035+
"redirect_url": "/defender-for-identity/security-posture-assessments/group-policy",
1036+
"redirect_document_id": false
1037+
},
1038+
{
1039+
"source_path": "defender-for-identity/modified-unprivileged-accounts-gpo.md",
1040+
"redirect_url": "/defender-for-identity/security-posture-assessments/group-policy",
1041+
"redirect_document_id": false
1042+
},
1043+
{
1044+
"source_path": "defender-for-identity/reversible-passwords-group-policy.md",
1045+
"redirect_url": "/defender-for-identity/security-posture-assessments/group-policy",
1046+
"redirect_document_id": false
1047+
},
1048+
{
1049+
"source_path": "defender-for-identity/built-in-active-directory-guest-account-is-enabled.md",
1050+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1051+
"redirect_document_id": false
1052+
},
1053+
{
1054+
"source_path": "defender-for-identity/domain-controller-account-password-change.md",
1055+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1056+
"redirect_document_id": false
1057+
},
1058+
{
1059+
"source_path": "defender-for-identity/security-assessment-print-spooler.md",
1060+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1061+
"redirect_document_id": false
1062+
},
1063+
{
1064+
"source_path": "defender-for-identity/security-assessment-remove-local-admins.md",
1065+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1066+
"redirect_document_id": false
1067+
},
1068+
{
1069+
"source_path": "defender-for-identity/security-assessment-unmonitored-domain-controller.md",
1070+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1071+
"redirect_document_id": false
1072+
},
1073+
{
1074+
"source_path": "defender-for-identity/unmonitored-active-directory-certificate-services-server.md",
1075+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1076+
"redirect_document_id": false
1077+
},
1078+
{
1079+
"source_path": "defender-for-identity/unmonitored-active-directory-federation-services-servers.md",
1080+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1081+
"redirect_document_id": false
1082+
},
1083+
{
1084+
"source_path": "defender-for-identity/unmonitored-entra-connect-servers.md",
1085+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1086+
"redirect_document_id": false
1087+
},
1088+
{
1089+
"source_path": "defender-for-identity/security-assessment-unsecure-domain-configurations.md",
1090+
"redirect_url": "/defender-for-identity/security-posture-assessments/identity-infrastructure",
1091+
"redirect_document_id": false
1092+
},
1093+
{
1094+
"source_path": "defender-for-identity/remove-replication-permissions-microsoft-entra-connect.md",
1095+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1096+
"redirect_document_id": false
1097+
},
1098+
{
1099+
"source_path": "defender-for-identity/remove-unsafe-permissions-sensitive-entra-connect.md",
1100+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1101+
"redirect_document_id": false
1102+
},
1103+
{
1104+
"source_path": "defender-for-identity/replace-entra-connect-default-admin.md",
1105+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1106+
"redirect_document_id": false
1107+
},
1108+
{
1109+
"source_path": "defender-for-identity/change-password-microsoft-entra-seamless-single-sign-on.md",
1110+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1111+
"redirect_document_id": false
1112+
},
1113+
{
1114+
"source_path": "defender-for-identity/rotate-password-microsoft-entra-connect.md",
1115+
"redirect_url": "/defender-for-identity/security-posture-assessments/hybrid-security",
1116+
"redirect_document_id": false
8721117
}
1118+
8731119
]
8741120
}

defender-endpoint/TOC.yml

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,10 @@
88
items:
99
- name: What is Microsoft Defender for Endpoint?
1010
items:
11-
- name: Defender for Endpoint on Windows
11+
- name: Defender for Endpoint
1212
href: microsoft-defender-endpoint.md
1313
- name: Defender for Endpoint on macOS
1414
href: microsoft-defender-endpoint-mac.md
15-
- name: Defender for Endpoint on Linux
16-
href: microsoft-defender-endpoint-linux.md
1715
- name: Defender for Endpoint on Android
1816
href: microsoft-defender-endpoint-android.md
1917
- name: Defender for Endpoint on iOS
@@ -261,9 +259,9 @@
261259
items:
262260
- name: Deploy Defender for Endpoint on Linux
263261
items:
264-
- name: Prerequisites
265-
href: mde-linux-prerequisites.md
266-
- name: Choose a deployment method
262+
- name: Install Defender for Endpoint on Linux
263+
href: install-defender-endpoint-linux.md
264+
- name: Choose a deployment method
267265
items:
268266
- name: Enabling deployment to a custom location
269267
href: linux-custom-location-installation.md

defender-endpoint/android-configure.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ ms.collection:
1515
ms.topic: how-to
1616
ms.subservice: android
1717
search.appverid: met150
18-
ms.date: 10/23/2025
18+
ms.date: 11/06/2025
1919
appliesto:
2020
- Microsoft Defender for Endpoint Plan 1
2121
- Microsoft Defender for Endpoint Plan 2
@@ -33,7 +33,7 @@ For more information about how to set up Defender for Endpoint on Android and Co
3333
## Configure custom indicators
3434

3535
> [!NOTE]
36-
> Defender for Endpoint on Android only supports creating custom indicators for IP addresses and URLs/domains.
36+
> Defender for Endpoint on Android supports creating custom indicators only for URLs and domains. IP-based custom indicators aren't supported on Android.
3737
>
3838
> IP `245.245.0.1` is an internal Defender IP and should not be included in custom indicators by customers to avoid any functionality issues.
3939
> Also, alerts for custom indicators are currently not supported for Defender for Endpoint on Android.

defender-endpoint/api/exposed-apis-create-app-webapp.md

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,8 @@ Having the [Microsoft Entra role](/entra/identity/role-based-access-control/mana
5050

5151
## Step 2: Add a secret to your app
5252

53+
This section describes authenticating your app using an app secret. To authenticate your app using a certificate, see [Create a self-signed public certificate to authenticate your application](/entra/identity-platform/howto-create-self-signed-certificate).
54+
5355
1. From the application page, select *Certificates & secrets* > *New client secret*.
5456

5557
2. In the *Add a client secret* pane, add a description and expiration date.
@@ -163,11 +165,3 @@ var request = new HttpRequestMessage(HttpMethod.Get, "https://api.securitycenter
163165
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", token);
164166
var response = httpClient.SendAsync(request).GetAwaiter().GetResult();
165167
```
166-
167-
## See also
168-
169-
* [Get access with user context](exposed-apis-create-app-nativeapp.md)
170-
171-
* [Supported Microsoft Defender for Endpoint APIs](exposed-apis-list.md)
172-
173-
* [Access Microsoft Defender for Endpoint on behalf of a user](exposed-apis-create-app-nativeapp.md)

defender-endpoint/configure-proxy-internet.md

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ title: Configure your devices to connect to the Defender for Endpoint service us
33
description: Learn how to configure your devices to enable communication with the cloud service using a proxy.
44
search.appverid: met150
55
ms.service: defender-endpoint
6-
ms.author: bagol
7-
author: batamig
6+
ms.author: painbar
7+
author: paulinbar
88
ms.localizationpriority: medium
99
manager: bagol
1010
audience: ITPro
@@ -13,12 +13,12 @@ ms.collection:
1313
- tier1
1414
ms.topic: how-to
1515
ms.subservice: onboard
16-
ms.date: 07/01/2024
16+
ms.date: 11/09/2025
1717
appliesto:
1818
- Microsoft Defender for Endpoint Plan 1
1919
- Microsoft Defender for Endpoint Plan 2
20-
2120
---
21+
2222
# STEP 2: Configure your devices to connect to the Defender for Endpoint service using a proxy
2323

2424

@@ -126,7 +126,9 @@ Configure the static proxy using the Group Policy available in Administrative Te
126126
>
127127
> For resiliency purposes and the real-time nature of cloud-delivered protection, Microsoft Defender Antivirus caches the last known working proxy. Ensure your proxy solution does not perform SSL inspection, as that breaks the secure cloud connection.
128128
>
129-
> Microsoft Defender Antivirus doesn't use the static proxy to connect to Windows Update or Microsoft Update for downloading updates. Instead, it uses a system-wide proxy if configured to use Windows Update, or the configured internal update source according to the [configured fallback order](manage-protection-updates-microsoft-defender-antivirus.md). If necessary, you can use **Administrative Templates > Windows Components > Microsoft Defender Antivirus > Define proxy auto-config (.pac)** for connecting to the network. If you need to set up advanced configurations with multiple proxies, use **Administrative Templates > Windows Components > Microsoft Defender Antivirus > Define addresses to bypass proxy server** and prevent Microsoft Defender Antivirus from using a proxy server for those destinations.
129+
> Microsoft Defender Antivirus doesn't use the static proxy to connect to Windows Update or Microsoft Update for downloading updates. Instead, it uses a system-wide proxy if configured to use Windows Update, or the configured internal update source according to the [configured fallback order](manage-protection-updates-microsoft-defender-antivirus.md).
130+
>
131+
> If necessary, you can use **Administrative Templates > Windows Components > Microsoft Defender Antivirus > Define proxy auto-config (.pac)** for connecting to the network. If you need to set up advanced configurations with multiple proxies, use **Administrative Templates > Windows Components > Microsoft Defender Antivirus > Define addresses to bypass proxy server** and prevent Microsoft Defender Antivirus from using a proxy server for those destinations.
130132
>
131133
> You can use PowerShell with the `Set-MpPreference` cmdlet to configure these options:
132134
> - `ProxyBypass`

0 commit comments

Comments
 (0)