セキュリティ運用– tag –
-
Microsoft Defender AIR設定の更新ポイント|Defender XDRで確認すべき自動調査と対応
Microsoft Defender の「Configure automated investigation and response capabilities in Microsoft Defender XDR」でまず確認すべきポイントは、自動調査と対応(AIR... -
Microsoft Defender Security Alert Triage Agent更新ポイント解説|権限変更・影響範囲・管理者チェック
Microsoft Defender の「Microsoft Security Copilot Security Alert Triage Agent in Microsoft Defender」は、SOC のアラート一次判定を AI エージェントで自動化する... -
Detection and automation, reimagined の管理者向け確認事項|Microsoft Sentinelの影響とチェックリスト
Microsoft Sentinel の「Detection and automation, reimagined」で管理者がまず押さえるべき結論は、既存の分析ルールやプレイブックを慌てて作り直す話ではなく、検出... -
Microsoft Defender for Endpoint standard connectivity URLsの更新点と管理者の対応ポイント
Microsoft Defender for Endpointの接続先URLをファイアウォールやプロキシで厳しく制御している環境では、Microsoft Defender for Endpoint standard connectivity URL... -
Microsoft Sentinel unified RBACとは?SOCチームのアクセス範囲変更と移行ポイントを解説
Microsoft Sentinel unified RBACの要点は、SOCチームのアクセス範囲を「ワークスペース単位」だけで分けるのではなく、Microsoft Defenderポータル上のUnified RBACと... -
Microsoft DefenderのLocal AI agent discoveryとは?管理者が確認すべき影響範囲と対応ポイント
Microsoft DefenderのLocal AI agent discoveryは、端末上で動くAIコーディング支援ツール、デスクトップAIアプリ、IDE拡張、MCPサーバー設定を棚卸しするためのプレビ... -
Microsoft Purview JIT Auditスコープ指定とは?Endpoint DLP更新の影響と対応ポイント
Microsoft PurviewのEndpoint Data Loss Prevention(Endpoint DLP)でJIT Auditを使っている組織は、2026年7月予定の更新に向けて、監査対象のユーザー・ユーザーグル... -
Microsoft Defender for EndpointをGroup Policyでオンボードする手順と注意点
Windows ServerをMicrosoft Defender for Endpointにグループポリシーでオンボードする場合、結論から言えば「GPOでオンボード用スクリプトを配布するだけ」で終わらせ... -
Microsoft DefenderポータルのMultiple workspacesとは?Sentinel複数ワークスペース運用の影響と確認点
Microsoft Defenderポータルの「Multiple workspaces - Microsoft Sentinel in Defender portal」で最初に押さえるべき結論は、Microsoft Sentinelのワークスペースを複...
