Scenario 2 – Monitoring with Windows Defender ATP

Windows Defender Advanced Threat Protection is basically designed to prevent, detect, investigate, and respond to advanced threats. We can also use it to detect and identify sensitive information, especially on client systems.

To work with this feature, we need to configure it and onboard the two test clients:

  1. Visit https://securitycenter.windows.com/ and log in as global administrator to start the configuration as shown in the image here:
    • Click Next:

Windows Security Center portal
    • Choose your storage location based on your needs:
Data storage configuration
    • Select the data retention ...

Get Mastering Identity and Access Management with Microsoft Azure - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.