Now, let’s implement/trial Windows Defender Advanced Threat Protection

Slides:



Advertisements
Similar presentations
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Advertisements

© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
© 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
MIX 09 4/15/ :14 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Co- location Mass Market Managed Hosting ISV Hosting.
Multitenant Model Request/Response General Model.
Session 1.
Built by Developers for Developers…. © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
Connect with life Connect with life
© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or.
Feature: Suggested Item Enhancements – Sales Script and Additional Information © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows.
Feature: Customer Combiner and Modifier © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.
demo Instance AInstance B Read “7” Write “8”

customer.
demo © 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names.
demo Demo.
demo QueryForeign KeyInstance /sm:body()/x:Order/x:Delivery/y:TrackingId1Z
Feature: Suggested Item Enhancements – Analysis and Assignment © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and.
projekt202 © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are.
© 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks.
© 2008 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or.

Boris Ulík Technology Solutions Professional Microsoft Slovakia Microsoft ® System Center 2012: System Center Endpoint Protection 2012.
Making of the Ignite Bot
The Zen of Package Management
How Microsoft uses Windows Defender ATP–Welcome to a SecOps world!
6/10/2018 5:07 PM THR2218 Deploying Windows Defender AV and more with Intune and Configuration Manager Amitai Senior Program Manager,
Microsoft Virtual Academy
Microsoft Virtual Academy
Securing, Governing, and Protecting Your Office 365 Investments
Understanding Windows Analytics Update Compliance
Automated Response with Windows Defender ATP
Microsoft Dynamics NAV 2018 – what’s new
Microsoft Virtual Academy
Project Portfolio Management Vision and Product Roadmap
SkyDrive Pro Chris Gideon Architect Microsoft 9/16/2018
Возможности Excel 2010, о которых следует знать
Title of Presentation 11/22/2018 3:34 PM
MIX 09 11/24/2018 9:18 PM © 2009 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
Twenty Windows Tools You Never Knew Existed
Disaster Recovery as a Service
Title of Presentation 12/2/2018 3:48 PM
Microsoft Virtual Academy
Microsoft Virtual Academy
1/2/2019 5:20 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
What’s new in the Fall Creators Update for Windows Defender ATP
What is Visual Studio Code?
Building SaaS Solutions on Windows Azure
2/27/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
8/04/2019 9:13 PM © 2006 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered.
4/27/17, Bell #8 What amount of net pay has been earned this period?
Виктор Хаджийски Катедра “Металургия на желязото и металолеене”
PENSACOLA ENERGY WORK PLAN OCTOBER 10, 2016
Title of Presentation 5/12/ :53 PM
(c) 2011 Microsoft. All rights reserved.
Шитманов Дархан Қаражанұлы Тарих пәнінің
Title of Presentation 5/24/2019 1:26 PM
5/24/2019 6:44 PM 1/8/18 Bell #10 In a world governed by the gods, is there any room for human will? Do human choices make a difference? EXPLAIN © 2007.
Microsoft Virtual Academy
Microsoft Data Insights Summit
Microsoft Virtual Academy
Securing ASP.NET in an Azure Environment
Title of Presentation 7/24/2019 8:53 PM
Build /27/2019 © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION.
What’s New in Visual Studio 2012 for Web Developers
Presentation transcript:

Now, let’s implement/trial Windows Defender Advanced Threat Protection Paul Kristensen Jake Mowrer

Windows Defender Advanced Threat Protection Windows Defender ATP helps our customers to detect, investigate and remediate data breaches on their networks. It provides detailed endpoint visibility and threat detection against ever increasingly sophisticated attacks. Built in to Windows 10, scale as you go. It’s easy to deploy and manage. Windows Defender ATP is built in to Windows 10, with very low performance impact on your users experience, network and memory. It’s powered by the cloud, which makes it easy to onboard your endpoints; it required no on-premises infrastructure, the service grows as your needs grow. Cut through the noise with correlated, precise alerts Based on behavior detections, Windows Defender ATP provides intelligent, actionable alerts for known and unknown adversaries, fueled by Microsoft security experts. Rich toolset for investigation and response Windows Defender ATP enables rapid host triage, by providing the required tools and a comprehensive timeline to easily understand the scope of breach. Windows Defender ATP enables focused response and enterprise threat containment. Single pain of glass The Windows Defender ATP portal gives you detailed endpoint visibility, by surfacing additional alerts and events from the Windows security stack and by integrating with other Microsoft Security solutions. © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

HIGH LEVEL ARCHITECTURE 5/19/2018 HIGH LEVEL ARCHITECTURE Security analytics Behavioral IOAs Dictionary Files and URLs detonation Known adversaries unknown Threat Intelligence from partnerships Threat Intelligence by Microsoft hunters Always-on endpoint behavioral sensors Forensic collection Exploration Alerts SecOps console Response Customers' Windows Defender ATP tenant SIEM SIEM / central UX Windows APT Hunters, MCS Cyber © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Step 1 – Sign up for a tenant 5/19/2018 7:25 PM Step 1 – Sign up for a tenant © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Sign up for the trial @ https://aka.ms/wdatp 5/19/2018 © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Step 2 – Provision your tenant 5/19/2018 7:25 PM Step 2 – Provision your tenant © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

PROVISIONING 5/19/2018 AAD Provisioning Asking for existing/new company AAD Get Started Sign-in to Windows Security Center © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

5/19/2018 PROVISIONING © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

Step 3 – Onboard endpoints 5/19/2018 7:25 PM Step 3 – Onboard endpoints © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Endpoint Requirements Windows 10 Anniversary Edition (1607) Can be Enterprise, Education, Pro, or Pro Education Internet connectivity from the endpoint (can proxy) Telemetry service must be started, but full telemetry not required

Onboarding Script System Center Config Mgr Intune GPO Local script

5/19/2018 ONBOARDING © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

Demo - Onboarding Microsoft Ignite 2016 5/19/2018 7:25 PM © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Step 4 – Finishing touches 5/19/2018 7:25 PM Step 4 – Finishing touches © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Assigning Console Permissions 5/19/2018 Assigning Console Permissions © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

5/19/2018 Email Alerts © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

SIEM INTEGRATION REST APIs Alert display ArcSight and Splunk 5/19/2018 SIEM INTEGRATION REST APIs Alert display ArcSight and Splunk Email alert notifications Info on TechNet © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION

5/19/2018 7:25 PM FAQ © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Is Windows Defender AV Required? No but it enhances the experience Integrated alerting Response: Block File We can run side by side with 3rd party AV

Do I have to crank up telemetry to full? No Don’t disable the service in services.msc

Will this work with Windows 10 build 1511? No, Anniversary (1607) is required.

Is my cloud tenant shared? No, it is your private tenant!

What makes you the best EDR? Well, since you asked: Built in, not bolted on Best TCO – No on-premises infrastructure, no agent deployment Rich Threat Intelligence (Microsoft + iSIGHT) Integration for the end to end story (Office ATP + ATA)

So what now? Sign up for a trial! 5/19/2018 7:25 PM So what now? Sign up for a trial! © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Sign up for the trial @ https://aka.ms/wdatp TechNet resources @ 5/19/2018 Sign up for the trial @ https://aka.ms/wdatp TechNet resources @ https://aka.ms/technet-wdatp Read MSFT Case Study @ https://t.co/paX7MQhezU © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

Continue your Ignite learning path 5/19/2018 7:25 PM Continue your Ignite learning path Visit Channel 9 to access a wide range of Microsoft training and event recordings https://channel9.msdn.com/ Head to the TechNet Eval Centre to download trials of the latest Microsoft products http://Microsoft.com/en-us/evalcenter/ Visit Microsoft Virtual Academy for free online training visit https://www.microsoftvirtualacademy.com © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

5/19/2018 7:25 PM Thank you Chat with me in the Speaker Lounge Find me on Twitter @JakeMowrerMSFT © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.