You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: Instructions/Labs/LAB_AK_07_Lab1_Ex04_Connect_Defender_XDR.md
+19-19Lines changed: 19 additions & 19 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -29,72 +29,72 @@ You're a Security Operations Analyst working at a company that deployed both Mic
29
29
30
30
In this task, you deploy the Microsoft Defender XDR connector.
31
31
32
-
1.Login to WIN1 virtual machine as Admin with the password: **Pa55w.rd**.
32
+
1.Sign in to **WIN1** virtual machine as Admin using the provided credentials.
33
33
34
34
1. In the Microsoft Edge browser, open the simulated environment by selecting this link: [Azure portal](https://app.highlights.guide/start/1c894b46-4b0a-40cb-b0f0-1e1c86c615f3?token=16d48b6c-eace-4a1f-8050-098d29d23a89).
35
35
36
-
1. On the Azure portal*Home* page, select the **Microsoft Sentinel** icon.
36
+
1. On the **Azure portal** Home page, select the **Microsoft Sentinel** icon.
37
37
38
-
1. On the *Microsoft Sentinel* page, select the **Woodgrove-LogAnalyiticWorkspace** Workspace.
38
+
1. On the **Microsoft Sentinel** page, select the **Woodgrove-LogAnalyiticWorkspace** Workspace.
39
39
40
-
1. In the Microsoft Sentinel left menus, scroll down to the **Content management** section and select **Content Hub**.
40
+
1. In the Microsoft Sentinel left menus, scroll down to the **Content management** section and select **Content hub**.
41
41
42
-
1. In the *Content hub*, search for the **Microsoft Defender XDR** solution and select it from the list.
42
+
1. In the **Content hub**, search for the **Microsoft Defender XDR** solution and select it from the list.
43
43
44
-
1. On the *Microsoft Defender XDR* solution details page, select **Install**.
44
+
1. On the **Microsoft Defender XDR** solution details page, select **Install**.
45
45
46
46
1. When the installation completes, search for the **Microsoft Defender XDR** solution and select it.
47
47
48
-
1. On the *Microsoft Defender XDR* solution details page, select **Manage**
48
+
1. On the **Microsoft Defender XDR** solution details page, select **Manage**
49
49
50
-
1. Select the *Microsoft Defender XDR* Data connector check-box, and select **Open connector page**.
50
+
1. Select the **Microsoft Defender XDR** Data connector check-box, and select **Open connector page**.
51
51
52
52
1. You should see a message that the connection was successful.
53
53
54
54
### Task 2: Connect Microsoft Sentinel and Microsoft Defender XDR
55
55
56
56
In this task, you continue with the simulation and connect a Microsoft Sentinel workspace to Microsoft Defender XDR.
57
57
58
-
1. Navigate back to the Microsoft Sentinel *Content Hub* (using the "breadcrumb" menu link at the top of the page), and select **Overview (Preview)** from the navigation menu General section.
58
+
1. Navigate back to the Microsoft Sentinel **Content hub** (using the "breadcrumb" menu link at the top of the page), and select **Overview (Preview)** from the navigation menu General section.
59
59
60
60
1. Select the **Learn more** button on the *Get your SIEM and XDR in one place* message.
61
61
62
62
1. Selecting the **Learn more** button opens a new tab in the browser for the *Microsoft Defender XDR* portal.
63
63
64
-
1. On the **Defender Defender** portal **Home** screen, you should see a banner at the top with the message, *Get your SIEM and XDR in one place*. Select the **Connect a workspaces** button.
64
+
1. On the **Defender XDR** portal **Home** screen, you should see a banner at the top with the message, *Get your SIEM and XDR in one place*. Select the **Connect a workspaces** button.
65
65
66
-
1. On the *Choose a workspace* page, select the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace.
66
+
1. On the **Choose a workspace** page, select the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace.
67
67
68
68
1. Select the **Next** button.
69
69
70
70
1. On the **Set a primary workspace** page, you should see the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace in the drop-down menu. Select the **Next** button.
71
71
72
-
1. On the *Review and finish* page, verify that the *Workspace* selection is correct and review the bulleted items under the *What to expect when the workspace is connected* section. Select the **Connect** button.
72
+
1. On the **Review and finish** page, verify that the *Workspace* selection is correct and review the bulleted items under the *What to expect when the workspace is connected* section. Select the **Connect** button.
73
73
74
74
1. You should see a *You're about to connect a workspace* message. Select the **Connect** button.
75
75
76
-
1. You should now be on the *Workspace successfully connected* page.
76
+
1. You should now be on the **Workspace successfully connected** page.
77
77
78
78
1. Select the **Close** button.
79
79
80
80
1. On the **Defender XDR** portal **Home** screen, you should see a banner at the top with the message, *Your unified SIEM and XDR is ready*. Select the **Start Hunting** button.
81
81
82
-
1. In *Advanced hunting*, you should see a message to "Explore your content from Microsoft Sentinel". In the *Advanced hunting* navigation menu, you can find the *Microsoft Sentinel* tables, functions, and queries under the corresponding tabs.
82
+
1. In the **Advanced hunting** navigation menu, you should see a message to "Explore your content from Microsoft Sentinel". you can find the Microsoft Sentinel tables, functions, and queries under the corresponding tabs.
83
83
84
84
1. Scroll down under the **Schema** tab to the **Microsoft Sentinel** heading, and then double-click the **ThreatIntelligenceIndicator** table.
85
85
86
-
1. In the *Query* pane, you should see a (KQL) query that returns threat intelligence indicators. Select the **Run query** button.
86
+
1. In the **Query** pane, you should see a (KQL) query that returns threat intelligence indicators. Select the **Run query** button.
87
87
88
-
1. You should see results returned in the *Results* pane.
88
+
1. You should see results returned in the **Results** pane.
89
89
90
90
1. Expand the left main menu pane if collapsed and expand the new **Microsoft Sentinel** menu items. You should see *Search*, *Threat management*, *Content management*, and *Configuration* selections.
91
91
92
92
>**Note:** Be aware that there are capability differences between the azure Microsoft Sentinel portal and Sentinel in the Microsoft Defender XDR portal **[Portal capability differences](https://learn.microsoft.com/azure/sentinel/microsoft-sentinel-defender-portal#capability-differences-between-portals)**.
93
93
94
-
1.From the Microsoft Defender XDR**Microsoft Sentinel** menu items, then select **Configuration** and then **Data connectors**.
94
+
1.In Microsoft Defender XDR, from the **Microsoft Sentinel** menu, select **Configuration**, and then select**Data connectors**.
95
95
96
-
1. In the *Data connectors* page, you should see the **Azure Activity** and other data connectors listed with a status of **Connected**.
96
+
1. In the **Data connectors** page, you should see the **Azure Activity** and other data connectors listed with a status of **Connected**.
97
97
98
-
>**Note:** Feel free to explore and compare the other Microsoft Sentinel capabilities, but as this is a simulation, your ability to explore Microsoft Sentinel in the Microsoft Defender portal is limited. In a real environment, you would be able to explore the full Microsoft Sentinel capabilities in the Microsoft Defender portal..
98
+
>**Note:** Feel free to explore and compare the other Microsoft Sentinel capabilities, but as this is a simulation, your ability to explore Microsoft Sentinel in the Microsoft Defender portal is limited. In a real environment, you would be able to explore the full Microsoft Sentinel capabilities in the Microsoft Defender portal.
99
99
100
100
## You completed the lab - Please proceed to Learning Path 9 - Lab 1 - Exercise 1 - Modify a Microsoft Security rule
0 commit comments