Skip to main content
Ministry of Education New Zealand

Microsoft Defender for Endpoint

When configured properly, Microsoft Defender for Endpoint (DfE) should be able to block most malicious software (malware) that tries to infect your laptops and computers.

Contact Cyclone to get access to the Microsoft ‘Defender for Endpoint’ antivirus software if you do not already have it.

Microsoft Defender for Endpoint form

Email: [email protected]

Importance of AV and endpoint protection

We recommend you set up a process to monitor any alerts that come up from your anti-virus software. If you have an information technology (IT) provider or IT lead, we recommend making this is one of their responsibilities. This means accessing the Microsoft DfE Portal and making sure all malware has been blocked as expected.

Microsoft Defender for Endpoint portal pre-requisites

To monitor the alerts, you will need:

  • a Microsoft Entra Account (formerly Azure AD) within the Microsoft tenant you are monitoring and/or responding to security alerts in
  • an account with the Microsoft Entra ID role with one of the following
  • Security Reader
  • Security Operator
  • Security Administrator.

The Security Operator or Administrator Operator role is required for staff who are monitoring and responding to security alerts generated by the Microsoft Defender for Endpoint solution.

Assign Microsoft Entra roles to users – Microsoft

Accessing the Microsoft Defender for Endpoint portal

  1. Log in to the Microsoft account for the environment you are monitoring and/or responding to security alerts for.

    Microsoft 365 Copilot app – Microsoft

  2. Click sign in/account widget in the top right of the webpage.

    Click sign in
    Sign in screen
  3. Log in with your school or kura Microsoft account.

    Login
    Login
  4. Once logged in to Office 365, navigate to the Security Portal by searching for ‘Security’ in the Office 365 search bar as shown below.

    Security portal
    Security portal
  5. Click the ‘Security’ app. This will open a new tab in your browser. The new tab will load to a dashboard which looks like the one below.

    It’s a good idea to bookmark this page so in future you can access the portal directly.

    Security app new page
    Security app page

Setting up email alerts

We recommend setting up email alerts so you can be alerted if malware is detected on any of your school devices.

  1. In the security portal, navigate to ‘Settings’ in the menu and then ‘Endpoints’.

    Endpoints
    Endpoints
  2. Next select ‘General’ and then ‘Email Notifications’.

  3. Create a notification rule with the email addresses of staff you want to be alerted.

    Remember to refer to your incident response plan if you have an alert that requires you to respond.

    Create a notification rule
    Notification rule

Monitoring security alerts

  1. Once logged into the Microsoft Defender for Endpoint Portal, navigate to ‘Incident & Alerts' under the 'Investigation & Response’ option in the sidebar menu.

    Incidents and alerts
    Incidents and Alerts
  2. Under this ‘Incident & Alerts' dropdown, you will see several different types of alerts. The primary ones for Defender for Endpoint Security Alerts are 'Alerts’ and 'Incidents'.

    • Alerts are standalone security detections.
    • Incidents are similar detections that have been grouped together. They may be alerts occurring on the same device, from the same user or appear to be similar in what is being alerted on.
    Incidents or Alerts
    Incidents or Alerts
  3. In the alerts or incident pages, you’ll see a list of all alerts/incidents within the selected time period. The default is 1 week. This can be changed to different periods of 1 day to 6 months.

    Alerts
    Alerts
  4. Clicking on an alert will open a sidebar with initial information. This side bar will include the following at the top:

    • status of the alert
    • severity of the alert
    • state of the detected behaviour/activity.

    Additionally, within the side bar will be information specific to the alert, such as the user, device involved, what the detected behaviour was and recommendations.

    Sidebar
    Sidebar
  5. The buttons at the top of the sidebar are:

    • Open Alert Page – this will pivot you into the full view of the alert, providing more information on the detected activity.
    • Manage Alert – this will open a new sidebar, where you can set the attributes of the alert such as status, assigned to, classification and comment.

    Open the ‘recommendation’ tab of the alert page, as shown below. Follow the listed actions, checking the alert ‘details' tab of the alert page for the required information.

    Manage alert
    Manage alert
Connection to a custom network indicator screen
Connection to a custom network indicator screen

Responding to security alerts

If you have the capability to respond to alerts within DfE – for example your IT provider or IT lead is confident doing so – we recommend following the response actions provided in the ‘recommendation’ tab on the alert page.

For detailed explanations on each of the response actions, see the Microsoft guidance below.

Take response actions on a device – Microsoft

THIS PAGE IS FOR
  • Suppliers and providers