On this page
Microsoft Defender for Endpoint
When configured properly, Microsoft Defender for Endpoint (DfE) should be able to block most malicious software (malware) that tries to infect your laptops and computers.
Contact Cyclone to get access to the Microsoft ‘Defender for Endpoint’ antivirus software if you do not already have it.
Microsoft Defender for Endpoint form
Email: [email protected]
Importance of AV and endpoint protection
We recommend you set up a process to monitor any alerts that come up from your anti-virus software. If you have an information technology (IT) provider or IT lead, we recommend making this is one of their responsibilities. This means accessing the Microsoft DfE Portal and making sure all malware has been blocked as expected.
Microsoft Defender for Endpoint portal pre-requisites
To monitor the alerts, you will need:
- a Microsoft Entra Account (formerly Azure AD) within the Microsoft tenant you are monitoring and/or responding to security alerts in
- an account with the Microsoft Entra ID role with one of the following
- Security Reader
- Security Operator
- Security Administrator.
The Security Operator or Administrator Operator role is required for staff who are monitoring and responding to security alerts generated by the Microsoft Defender for Endpoint solution.
Assign Microsoft Entra roles to users – Microsoft
Accessing the Microsoft Defender for Endpoint portal
Log in to the Microsoft account for the environment you are monitoring and/or responding to security alerts for.
Click sign in/account widget in the top right of the webpage.
Click sign inLog in with your school or kura Microsoft account.
LoginOnce logged in to Office 365, navigate to the Security Portal by searching for ‘Security’ in the Office 365 search bar as shown below.
Security portalClick the ‘Security’ app. This will open a new tab in your browser. The new tab will load to a dashboard which looks like the one below.
It’s a good idea to bookmark this page so in future you can access the portal directly.
Security app new page
Setting up email alerts
We recommend setting up email alerts so you can be alerted if malware is detected on any of your school devices.
In the security portal, navigate to ‘Settings’ in the menu and then ‘Endpoints’.
EndpointsNext select ‘General’ and then ‘Email Notifications’.
Create a notification rule with the email addresses of staff you want to be alerted.
Remember to refer to your incident response plan if you have an alert that requires you to respond.
Create a notification rule
Monitoring security alerts
Once logged into the Microsoft Defender for Endpoint Portal, navigate to ‘Incident & Alerts' under the 'Investigation & Response’ option in the sidebar menu.
Incidents and alertsUnder this ‘Incident & Alerts' dropdown, you will see several different types of alerts. The primary ones for Defender for Endpoint Security Alerts are 'Alerts’ and 'Incidents'.
- Alerts are standalone security detections.
- Incidents are similar detections that have been grouped together. They may be alerts occurring on the same device, from the same user or appear to be similar in what is being alerted on.
Incidents or AlertsIn the alerts or incident pages, you’ll see a list of all alerts/incidents within the selected time period. The default is 1 week. This can be changed to different periods of 1 day to 6 months.
AlertsClicking on an alert will open a sidebar with initial information. This side bar will include the following at the top:
- status of the alert
- severity of the alert
- state of the detected behaviour/activity.
Additionally, within the side bar will be information specific to the alert, such as the user, device involved, what the detected behaviour was and recommendations.
SidebarThe buttons at the top of the sidebar are:
- Open Alert Page – this will pivot you into the full view of the alert, providing more information on the detected activity.
- Manage Alert – this will open a new sidebar, where you can set the attributes of the alert such as status, assigned to, classification and comment.
Open the ‘recommendation’ tab of the alert page, as shown below. Follow the listed actions, checking the alert ‘details' tab of the alert page for the required information.
Manage alert
Responding to security alerts
If you have the capability to respond to alerts within DfE – for example your IT provider or IT lead is confident doing so – we recommend following the response actions provided in the ‘recommendation’ tab on the alert page.
For detailed explanations on each of the response actions, see the Microsoft guidance below.