Getting started with security operations
Before we jump into practical examples, it’s important to first familiarize yourself with the portal, including dashboards and reports that are available to you. We’ll also want to have a SOC structure in mind so that tasks and responsibilities can be mapped back to your own environment as you move through the chapter.
Portal familiarization
The portal at https://security.microsoft.com provides a unified interface to all Microsoft 365 Defender (M365D) products. In Chapter 4, Understanding Endpoint Detection and Response, you learned about what the knobs and dials do. In Chapter 6, Considerations for Deployment and Configuration, you learned about all the configurable options for MDE, and subsequently, have been able to perform basic configuration of the portal experience.
Now is a good time to get some practical experience with the portal if you haven’t already – but instead of jumping right into your production...