Exploring the Microsoft 365 Defender portal
Microsoft 365 Defender is provisioned automatically when the administrator of a licensed tenant visits security.microsoft.com. Several Azure AD administrative roles allow this, but the most common ones are Global Administrator, Security Administrator, or their Reader equivalents.
MDE is provisioned when the administrator clicks on any of the menus under the Endpoints banner. For example, you’ll see Vulnerability management and others. Clicking one begins the provisioning process of your tenant’s MDE instance. The geography of data storage is determined automatically based on your tenant’s location. If a change is required, you must get in touch with support and start from scratch:
Figure 3.1 – Endpoints option navigation in the Microsoft 365 Defender portal
Microsoft Defender for Cloud
In the next chapter, you will learn that Azure-managed devices can be onboarded using Microsoft...