Skip to content

Commit 8af2bdc

Browse files
Merge pull request #5667 from MicrosoftDocs/main
[AutoPublish] main to live - 11/19 01:33 PST | 11/19 15:03 IST
2 parents 3bacacb + 3f18557 commit 8af2bdc

File tree

7 files changed

+35
-3
lines changed

7 files changed

+35
-3
lines changed

defender-endpoint/microsoft-defender-endpoint-android.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ This article describes how to install, configure, update, and use Defender for E
5656

5757
- Intune Company Portal app should be downloaded from [Google Play](https://play.google.com/store/apps/details?id=com.microsoft.windowsintune.companyportal) and installed for seamless onboarding. Device enrollment is required for Intune device compliance policies to be enforced.
5858

59-
- Mobile phones and tablets running Android 8.0 and above. **(Note: Microsoft Defender is ending support for Android 8, 8.1 and 9 versions on April 30, 2025, after that device running on Android version < 10 won't be supported)**
59+
- Mobile phones and tablets running Android 10.0 and above.
6060

6161
**What does it mean devices running on unsupported Android version?** 
6262

defender-for-identity/link-unlink-account-to-identity.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -66,12 +66,13 @@ Follow these steps to manually link accounts to a selected identity.
6666

6767
:::image type="content" source="media/link-unlink-account-to-identity/accounts-observed-in-organization.png" alt-text="Screenshot that shows the accounts observed in an organization." lightbox="media/link-unlink-account-to-identity/accounts-observed-in-organization.png":::
6868

69-
1. Select one or more accounts from the table. You must select at least one account to continue.
69+
1. Select the **Link** button.
7070
1. You can search by:
7171
- Display name
7272
- User principal name (UPN)
7373
- Security identifier (SID)
7474
- Source provider account
75+
1. Select one account from the table.
7576
1. Select **Next**.
7677
1. Enter a short justification comment explaining why you're linking these accounts.
7778
1. Your justification must:
@@ -89,7 +90,7 @@ Follow these steps to manually unlink accounts from a selected identity.
8990

9091
1. Go to **Identity Inventory > Observed in organization**
9192
1. Open the **Accounts** tab.
92-
1. Select one or more account groups.
93+
1. Select one account set from the table.
9394
1. Select **Unlink account**.
9495
1. A confirmation dialog appears with the identity name.
9596
1. Review the message and select **Unlink accounts** to confirm.
34.2 KB
Loading
64.5 KB
Loading
99 KB
Loading
29.9 KB
Loading

defender-xdr/security-copilot-m365d-incident-summary.md

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -83,6 +83,37 @@ To summarize an incident:
8383

8484
:::image type="content" source="/defender/media/copilot-in-defender/incident-summary/incident-summary-options.png" alt-text="Screenshot that shows the actions available on the incident summary card.":::
8585

86+
### Manage Copilot incident summaries settings (preview)
87+
88+
By default, Copilot generates a summary for each incident the user opens, but you can change this setting to display incident summaries only in specific instances. You can choose to have summaries generated:
89+
90+
- Always (for every incident opened)
91+
- Based on the severity level of the incident
92+
- On demand only
93+
94+
To change the settings for Copilot incident summaries in Microsoft Sentinel, follow these steps:
95+
96+
1. Go to **System** > **Settings** > **Copilot in Defender** in the Microsoft Sentinel navigation pane.
97+
98+
:::image type="content" source="media/security-copilot-m365d-incident-summary/copilot-settings.png" alt-text="Screenshot that shows the Copilot settings page in Microsoft Sentinel.":::
99+
100+
1. Under **Preferences**, select **Incident Summary generation**.
101+
1. Select either **Auto-generate** or **Generate on demand**, depending on your preference.
102+
1. If you select **Auto-generate**, choose between **Always** or **Incident severity**. If you select **Incident severity**, choose the *minimum* severity level for which you want Copilot to generate incident summaries automatically.
103+
104+
:::image type="content" source="media/security-copilot-m365d-incident-summary/copilot-settings-preferences.png" alt-text="Screenshot that shows the Copilot settings preferences page in Microsoft Sentinel.":::
105+
106+
1. Select **Save**.
107+
108+
- When you select **Incident severity**, an estimate of the number of incidents of each severity level reviewed per day is displayed, along with the estimated SCU consumption.
109+
110+
:::image type="content" source="./media/security-copilot-m365d-incident-summary/incident-severity.png" alt-text="Screenshot that shows the approximate number of incidents of each severity level.":::
111+
112+
- Copilot saves generated incident summaries for a week. If you select an incident whose summary is in the cache, and the incident hasn't changed significantly, the summary is automatically redisplayed at no cost regardless of the setting.
113+
- To generate a summary on demand for an incident that's not automatically generated, select the **Generate** button.
114+
115+
:::image type="content" source="media/security-copilot-m365d-incident-summary/generate-summary.png" alt-text="Screenshot that shows the Generate summary button on the incident page.":::
116+
86117
## Sample incident summary prompt
87118

88119
In the Security Copilot standalone portal, you can use the following prompt to generate incident summaries:

0 commit comments

Comments
 (0)