Skip to content

Commit b3710c6

Browse files
committed
Fix: Lab 07 Ex04 - Connect Defender XDR
1 parent ee5e0bd commit b3710c6

File tree

1 file changed

+19
-19
lines changed

1 file changed

+19
-19
lines changed

Instructions/Labs/LAB_AK_07_Lab1_Ex04_Connect_Defender_XDR.md

Lines changed: 19 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -29,72 +29,72 @@ You're a Security Operations Analyst working at a company that deployed both Mic
2929

3030
In this task, you deploy the Microsoft Defender XDR connector.
3131

32-
1. Login to WIN1 virtual machine as Admin with the password: **Pa55w.rd**.
32+
1. Sign in to **WIN1** virtual machine as Admin using the provided credentials.
3333

3434
1. In the Microsoft Edge browser, open the simulated environment by selecting this link: [Azure portal]( https://app.highlights.guide/start/1c894b46-4b0a-40cb-b0f0-1e1c86c615f3?token=16d48b6c-eace-4a1f-8050-098d29d23a89).
3535

36-
1. On the Azure portal *Home* page, select the **Microsoft Sentinel** icon.
36+
1. On the **Azure portal** Home page, select the **Microsoft Sentinel** icon.
3737

38-
1. On the *Microsoft Sentinel* page, select the **Woodgrove-LogAnalyiticWorkspace** Workspace.
38+
1. On the **Microsoft Sentinel** page, select the **Woodgrove-LogAnalyiticWorkspace** Workspace.
3939

40-
1. In the Microsoft Sentinel left menus, scroll down to the **Content management** section and select **Content Hub**.
40+
1. In the Microsoft Sentinel left menus, scroll down to the **Content management** section and select **Content hub**.
4141

42-
1. In the *Content hub*, search for the **Microsoft Defender XDR** solution and select it from the list.
42+
1. In the **Content hub**, search for the **Microsoft Defender XDR** solution and select it from the list.
4343

44-
1. On the *Microsoft Defender XDR* solution details page, select **Install**.
44+
1. On the **Microsoft Defender XDR** solution details page, select **Install**.
4545

4646
1. When the installation completes, search for the **Microsoft Defender XDR** solution and select it.
4747

48-
1. On the *Microsoft Defender XDR* solution details page, select **Manage**
48+
1. On the **Microsoft Defender XDR** solution details page, select **Manage**
4949

50-
1. Select the *Microsoft Defender XDR* Data connector check-box, and select **Open connector page**.
50+
1. Select the **Microsoft Defender XDR** Data connector check-box, and select **Open connector page**.
5151

5252
1. You should see a message that the connection was successful.
5353

5454
### Task 2: Connect Microsoft Sentinel and Microsoft Defender XDR
5555

5656
In this task, you continue with the simulation and connect a Microsoft Sentinel workspace to Microsoft Defender XDR.
5757

58-
1. Navigate back to the Microsoft Sentinel *Content Hub* (using the "breadcrumb" menu link at the top of the page), and select **Overview (Preview)** from the navigation menu General section.
58+
1. Navigate back to the Microsoft Sentinel **Content hub** (using the "breadcrumb" menu link at the top of the page), and select **Overview (Preview)** from the navigation menu General section.
5959

6060
1. Select the **Learn more** button on the *Get your SIEM and XDR in one place* message.
6161

6262
1. Selecting the **Learn more** button opens a new tab in the browser for the *Microsoft Defender XDR* portal.
6363

64-
1. On the **Defender Defender** portal **Home** screen, you should see a banner at the top with the message, *Get your SIEM and XDR in one place*. Select the **Connect a workspaces** button.
64+
1. On the **Defender XDR** portal **Home** screen, you should see a banner at the top with the message, *Get your SIEM and XDR in one place*. Select the **Connect a workspaces** button.
6565

66-
1. On the *Choose a workspace* page, select the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace.
66+
1. On the **Choose a workspace** page, select the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace.
6767

6868
1. Select the **Next** button.
6969

7070
1. On the **Set a primary workspace** page, you should see the **woodgrove-loganalyiticsworkspace** Microsoft Sentinel workspace in the drop-down menu. Select the **Next** button.
7171

72-
1. On the *Review and finish* page, verify that the *Workspace* selection is correct and review the bulleted items under the *What to expect when the workspace is connected* section. Select the **Connect** button.
72+
1. On the **Review and finish** page, verify that the *Workspace* selection is correct and review the bulleted items under the *What to expect when the workspace is connected* section. Select the **Connect** button.
7373

7474
1. You should see a *You're about to connect a workspace* message. Select the **Connect** button.
7575

76-
1. You should now be on the *Workspace successfully connected* page.
76+
1. You should now be on the **Workspace successfully connected** page.
7777

7878
1. Select the **Close** button.
7979

8080
1. On the **Defender XDR** portal **Home** screen, you should see a banner at the top with the message, *Your unified SIEM and XDR is ready*. Select the **Start Hunting** button.
8181

82-
1. In *Advanced hunting*, you should see a message to "Explore your content from Microsoft Sentinel". In the *Advanced hunting* navigation menu, you can find the *Microsoft Sentinel* tables, functions, and queries under the corresponding tabs.
82+
1. In the **Advanced hunting** navigation menu, you should see a message to "Explore your content from Microsoft Sentinel". you can find the Microsoft Sentinel tables, functions, and queries under the corresponding tabs.
8383

8484
1. Scroll down under the **Schema** tab to the **Microsoft Sentinel** heading, and then double-click the **ThreatIntelligenceIndicator** table.
8585

86-
1. In the *Query* pane, you should see a (KQL) query that returns threat intelligence indicators. Select the **Run query** button.
86+
1. In the **Query** pane, you should see a (KQL) query that returns threat intelligence indicators. Select the **Run query** button.
8787

88-
1. You should see results returned in the *Results* pane.
88+
1. You should see results returned in the **Results** pane.
8989

9090
1. Expand the left main menu pane if collapsed and expand the new **Microsoft Sentinel** menu items. You should see *Search*, *Threat management*, *Content management*, and *Configuration* selections.
9191

9292
>**Note:** Be aware that there are capability differences between the azure Microsoft Sentinel portal and Sentinel in the Microsoft Defender XDR portal **[Portal capability differences](https://learn.microsoft.com/azure/sentinel/microsoft-sentinel-defender-portal#capability-differences-between-portals)**.
9393
94-
1. From the Microsoft Defender XDR **Microsoft Sentinel** menu items, then select **Configuration** and then **Data connectors**.
94+
1. In Microsoft Defender XDR, from the **Microsoft Sentinel** menu, select **Configuration**, and then select **Data connectors**.
9595

96-
1. In the *Data connectors* page, you should see the **Azure Activity** and other data connectors listed with a status of **Connected**.
96+
1. In the **Data connectors** page, you should see the **Azure Activity** and other data connectors listed with a status of **Connected**.
9797

98-
>**Note:** Feel free to explore and compare the other Microsoft Sentinel capabilities, but as this is a simulation, your ability to explore Microsoft Sentinel in the Microsoft Defender portal is limited. In a real environment, you would be able to explore the full Microsoft Sentinel capabilities in the Microsoft Defender portal..
98+
>**Note:** Feel free to explore and compare the other Microsoft Sentinel capabilities, but as this is a simulation, your ability to explore Microsoft Sentinel in the Microsoft Defender portal is limited. In a real environment, you would be able to explore the full Microsoft Sentinel capabilities in the Microsoft Defender portal.
9999
100100
## You completed the lab - Please proceed to Learning Path 9 - Lab 1 - Exercise 1 - Modify a Microsoft Security rule

0 commit comments

Comments
 (0)