You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/microsoft-defender-endpoint-android.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -56,7 +56,7 @@ This article describes how to install, configure, update, and use Defender for E
56
56
57
57
- Intune Company Portal app should be downloaded from [Google Play](https://play.google.com/store/apps/details?id=com.microsoft.windowsintune.companyportal) and installed for seamless onboarding. Device enrollment is required for Intune device compliance policies to be enforced.
58
58
59
-
- Mobile phones and tablets running Android 8.0 and above. **(Note: Microsoft Defender is ending support for Android 8, 8.1 and 9 versions on April 30, 2025, after that device running on Android version < 10 won't be supported)**
59
+
- Mobile phones and tablets running Android 10.0 and above.
60
60
61
61
**What does it mean devices running on unsupported Android version?**
Copy file name to clipboardExpand all lines: defender-for-identity/link-unlink-account-to-identity.md
+3-2Lines changed: 3 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -66,12 +66,13 @@ Follow these steps to manually link accounts to a selected identity.
66
66
67
67
:::image type="content" source="media/link-unlink-account-to-identity/accounts-observed-in-organization.png" alt-text="Screenshot that shows the accounts observed in an organization." lightbox="media/link-unlink-account-to-identity/accounts-observed-in-organization.png":::
68
68
69
-
1. Select one or more accounts from the table. You must select at least one account to continue.
69
+
1. Select the **Link** button.
70
70
1. You can search by:
71
71
- Display name
72
72
- User principal name (UPN)
73
73
- Security identifier (SID)
74
74
- Source provider account
75
+
1. Select one account from the table.
75
76
1. Select **Next**.
76
77
1. Enter a short justification comment explaining why you're linking these accounts.
77
78
1. Your justification must:
@@ -89,7 +90,7 @@ Follow these steps to manually unlink accounts from a selected identity.
89
90
90
91
1. Go to **Identity Inventory > Observed in organization**
91
92
1. Open the **Accounts** tab.
92
-
1. Select one or more account groups.
93
+
1. Select one account set from the table.
93
94
1. Select **Unlink account**.
94
95
1. A confirmation dialog appears with the identity name.
95
96
1. Review the message and select **Unlink accounts** to confirm.
Copy file name to clipboardExpand all lines: defender-xdr/security-copilot-m365d-incident-summary.md
+31Lines changed: 31 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -83,6 +83,37 @@ To summarize an incident:
83
83
84
84
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/incident-summary-options.png" alt-text="Screenshot that shows the actions available on the incident summary card.":::
By default, Copilot generates a summary for each incident the user opens, but you can change this setting to display incident summaries only in specific instances. You can choose to have summaries generated:
89
+
90
+
- Always (for every incident opened)
91
+
- Based on the severity level of the incident
92
+
- On demand only
93
+
94
+
To change the settings for Copilot incident summaries in Microsoft Sentinel, follow these steps:
95
+
96
+
1. Go to **System** > **Settings** > **Copilot in Defender** in the Microsoft Sentinel navigation pane.
97
+
98
+
:::image type="content" source="media/security-copilot-m365d-incident-summary/copilot-settings.png" alt-text="Screenshot that shows the Copilot settings page in Microsoft Sentinel.":::
99
+
100
+
1. Under **Preferences**, select **Incident Summary generation**.
101
+
1. Select either **Auto-generate** or **Generate on demand**, depending on your preference.
102
+
1. If you select **Auto-generate**, choose between **Always** or **Incident severity**. If you select **Incident severity**, choose the *minimum* severity level for which you want Copilot to generate incident summaries automatically.
103
+
104
+
:::image type="content" source="media/security-copilot-m365d-incident-summary/copilot-settings-preferences.png" alt-text="Screenshot that shows the Copilot settings preferences page in Microsoft Sentinel.":::
105
+
106
+
1. Select **Save**.
107
+
108
+
- When you select **Incident severity**, an estimate of the number of incidents of each severity level reviewed per day is displayed, along with the estimated SCU consumption.
109
+
110
+
:::image type="content" source="./media/security-copilot-m365d-incident-summary/incident-severity.png" alt-text="Screenshot that shows the approximate number of incidents of each severity level.":::
111
+
112
+
- Copilot saves generated incident summaries for a week. If you select an incident whose summary is in the cache, and the incident hasn't changed significantly, the summary is automatically redisplayed at no cost regardless of the setting.
113
+
- To generate a summary on demand for an incident that's not automatically generated, select the **Generate** button.
114
+
115
+
:::image type="content" source="media/security-copilot-m365d-incident-summary/generate-summary.png" alt-text="Screenshot that shows the Generate summary button on the incident page.":::
116
+
86
117
## Sample incident summary prompt
87
118
88
119
In the Security Copilot standalone portal, you can use the following prompt to generate incident summaries:
0 commit comments