Skip to content

Latest commit

 

History

History
127 lines (88 loc) · 6.93 KB

m365d-enable.md

File metadata and controls

127 lines (88 loc) · 6.93 KB
title description ms.service f1.keywords ms.author author ms.localizationpriority manager audience ms.collection ms.topic search.appverid ms.date
Turn on Microsoft Defender XDR
Learn how to enable Microsoft Defender XDR and start integrating your security incident and response.
defender-xdr
NOCSH
dansimp
dansimp
medium
dansimp
ITPro
m365-security
m365solution-getstarted
highpri
tier1
conceptual
MOE150
MET150
08/12/2024

Turn on Microsoft Defender XDR

[!INCLUDE Microsoft Defender XDR rebranding]

Applies to:

  • Microsoft Defender XDR

Microsoft Defender XDR unifies your incident response process by integrating key capabilities across Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity. This unified experience adds powerful features you can access in the Microsoft Defender portal.

Microsoft Defender XDR automatically turns on when eligible customers with the required permissions visit Microsoft Defender portal. Read this article to understand various prerequisites and how Microsoft Defender XDR is provisioned.

Check license eligibility and required permissions

A license to a Microsoft 365 security product generally entitles you to use Microsoft Defender XDR without additional licensing cost. We do recommend getting a Microsoft 365 E5, E5 Security, A5, or A5 Security license or a valid combination of licenses that provides access to all supported services.

For detailed licensing information, read the licensing requirements.

Check your role

You must be one of the following roles to turn on Microsoft Defender XDR:

  • Global Administrator
  • Security Administrator
  • Security Operator
  • Global Reader
  • Security Reader
  • Compliance Administrator
  • Compliance Data Administrator
  • Application Administrator
  • Cloud Application Administrator

View your roles in Microsoft Entra ID

Configure your network firewall

Configuring your network firewall ensures a smooth experience while navigating the Microsoft Defender portal https://security.microsoft.com.

Add to your firewall's allow list the outbound IP addresses in the following page:

In addition, ensure that other Defender services are properly configured. You can refer to the following pages for configuration information:

Supported services

Microsoft Defender XDR aggregates data from the various supported services that you've already deployed. It will process and store data centrally to identify new insights and make centralized response workflows possible. It does this without affecting existing deployments, settings, or data associated with the integrated services.

To get the best protection and optimize Microsoft Defender XDR, we recommend deploying all applicable supported services on your network. For more information, read about deploying supported services.

Onboard to the service

Onboarding to Microsoft Defender XDR is simple. From the navigation menu, select any item, such as Incidents & alerts, Hunting, Action center, or Threat analytics to initiate the onboarding process.

Data center location

Microsoft Defender XDR will store and process data in the same location used by Microsoft Defender for Endpoint. If you don't have Microsoft Defender for Endpoint, a new data center location is automatically selected based on the location of active Microsoft 365 security services. The selected data center location is shown in the screen.

Select Need help? in the Microsoft Defender portal to contact Microsoft support about provisioning Microsoft Defender XDR in a different data center location.

Note

In the past, Microsoft Defender for Endpoint automatically provisioned in European Union (EU) data centers when turned on through Microsoft Defender for Cloud. Microsoft Defender XDR will automatically provision in the same EU data center for customers who have provisioned Defender for Endpoint in this manner in the past.

Confirm that the service is on

Once the service is provisioned, it adds:

:::image type="content" source="/defender/media/overview-incident.png" alt-text="The navigation pane in the Microsoft Defender portal with Microsoft Defender XDR features" lightbox="/defender/media/overview-incident.png"::: Microsoft Defender portal with incidents management and other capabilities

Getting Microsoft Defender for Identity data

To enable the integration with Microsoft Defender for Cloud Apps, you'll need to log in to the Microsoft Defender for Cloud Apps at least once.

Get assistance

To get answers to the most commonly asked questions about turning on Microsoft Defender XDR, read the FAQ.

Microsoft support staff can help provision or deprovision the service and related resources on your tenant. For assistance, select Need help? in the Microsoft Defender portal. When contacting support, mention Microsoft Defender XDR.

Related topics