Updates from: 08/04/2023 03:34:30
Category Microsoft Docs article Related commit history on GitHub Change details
pull_request_template Pull_Request_Template https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/.github/pull_request_template.md
+<!--
+Microsoft Entra rebrand: Please do not submit pull requests containing branding updates from Azure Active Directory, Azure AD, AAD, etc, to their respective Microsoft Entra equivalents at this time.
+
+Microsoft Entra rebranding is being coordinated across the Learn platform and will be applied to this repo automatically when we receive confirmation that product UIs have been updated. If you have questions regarding the rebrand project, contact dstrome.
+
+This text can be deleted.
+-->
threat-intelligence Gathering Threat Intelligence And Infrastructure Chaining https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/defender/threat-intelligence/gathering-threat-intelligence-and-infrastructure-chaining.md
But because our virtual users capture the DOM and find all the dynamic links and
![Tutorial Infra Chain My Piltowcom 2 Whois](media/tutorialInfraChainMyPiltowcom2Whois.png) 2. mypiltow[.]com+ 3. If you select the Whois record from October of 2018, you will find that mypiltow[.]com was registered in Hong Kong SAR, China and is privacy protected by Domain ID Shield Service CO.+ 4. mypiltow[.]comΓÇÖs registrar is OnlineNIC, Inc. ![Tutorial Infra Chain My Piltowcom 2 Whois](media/tutorialInfraChainMyPiltowcom2Whois.png)
threat-intelligence What Is Microsoft Defender Threat Intelligence Defender Ti https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/defender/threat-intelligence/what-is-microsoft-defender-threat-intelligence-defender-ti.md
Vulnerability Articles also include a Defender TI Priority Score and severity in
## Reputation scoring
-Defender TI provides proprietary reputation scores for any Host, Domain, or IP Address. Whether validating the reputation of a known or unknown entity, this score helps users quickly understand any detected ties to malicious or suspicious infrastructure. The platform provides quick information about the activity of these entities, such as First and Last Seen timestamps, ASN, country, associated infrastructure, and a list of rules that impact the reputation score when applicable.
+Defender TI provides proprietary reputation scores for any Host, Domain, or IP Address. Whether validating the reputation of a known or unknown entity, this score helps users quickly understand any detected ties to malicious or suspicious infrastructure. The platform provides quick information about the activity of these entities, such as First and Last Seen timestamps, ASN, country/region, associated infrastructure, and a list of rules that impact the reputation score when applicable.
![Reputation Summary Card](media/reputationSummaryCard.png)
admin Sign Up For Office 365 https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/admin-overview/sign-up-for-office-365.md
You don't need to cancel your trial. If you don't buy the trial subscription, it
- **The address and contact information for your subscription:**
- - **Country** where the services will be used. You **won't** be able to change the country later, even during the sign-up process; you'll have to restart the sign-up wizard.
+ - **Country** where the services will be used. You **won't** be able to change the country/region later, even during the sign-up process; you'll have to restart the sign-up wizard.
- **Email** and **phone number** so we can contact you if needed about your subscription. For example, if you forget your password, we would use this information to send you a temporary one. We also send your billing information to the email address you specify.
admin Compare Groups https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/admin/create-groups/compare-groups.md
Shared mailboxes can receive external emails if the administrator has enabled th
Shared mailboxes include a calendar that can be used for collaboration.
-Users with permissions to the group mailbox can send as or send on behalf of the mailbox email address, if the administrator has given that user permissions to do that. This is especially useful for help and support mailboxes because users can send emails from "Contoso Support" or "Building A Reception Desk."
+Users with permissions to the shared mailbox can send as or send on behalf of the mailbox email address, if the administrator has given that user permissions to do that. This is especially useful for help and support mailboxes because users can send emails from "Contoso Support" or "Building A Reception Desk."
It's not possible to migrate a shared mailbox to a Microsoft 365 group.
commerce Pay For Your Subscription https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/commerce/billing-and-payments/pay-for-your-subscription.md
You can use a credit or debit card, or bank account to pay for your Microsoft bu
> [!IMPORTANT] > > - As of April 1, 2023, we no longer accept checks as a payment method for subscriptions paid by invoice. Pay by check is no longer available as a payment option, and check payment instructions have been removed from invoices. You can still pay for your invoice by wire transfer. See your invoice for wire transfer payment information. If you're an existing customer who currently pays by check, you have until September 30, 2023 to change to paying by wire transfer, and avoid possible service disruption.
-> - As of January 26, 2021, new bank accounts are no longer supported for customers in Belgium, France, Italy, Luxembourg, Portugal, Spain, and the United States. If you're an existing customer in one of those countries, you can continue paying for your subscription with an existing bank account that is in good standing. However, you can't add new subscriptions to the bank account.
+> - As of January 26, 2021, new bank accounts are no longer supported for customers in Belgium, France, Italy, Luxembourg, Portugal, Spain, and the United States. If you're an existing customer in one of those countries/regions, you can continue paying for your subscription with an existing bank account that is in good standing. However, you can't add new subscriptions to the bank account.
> [!TIP] > If you need help with the steps in this topic, consider [working with a Microsoft small business specialist](https://go.microsoft.com/fwlink/?linkid=2186871). With Business Assist, you and your employees get around-the-clock access to small business specialists as you grow your business, from onboarding to everyday use.
commerce Volume Licensing Invoices https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/commerce/licenses/volume-licensing-invoices.md
The invoice recon file is a CSV file that includes the same information as the I
|Extended Amount|The quantity multiplied by the unit price.| |Commitment Usage|The amount of monetary commitment that was used.| |Net Amount|The extended amount minus the commitment usage.|
-|Tax Rate|The tax rate applicable to the product based on the country of billing.|
+|Tax Rate|The tax rate applicable to the product based on the country/region of billing.|
|Tax Amount|The net amount multiplied by tax rate.| |Total|The sum of the net amount and tax amount.| |Is Third Party|Indicates whether the product or service is a third-party product.|
If the amount billed is different than expected, that can happen for a few reaso
## What is the tax rate applied to my invoice?
-The tax rate applied to the invoice depends on the country of billing. You can check the invoice recon file for the tax rate applied to each
+The tax rate applied to the invoice depends on the country/region of billing. You can check the invoice recon file for the tax rate applied to each
item. For more information, contact your Microsoft partner. ## Who can I contact for questions related to pricing and the coverage period?
commerce Understand Proposal Workflow https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/commerce/understand-proposal-workflow.md
The checkout page contains the following sections:
### Sold to
-This section shows the billing account used for the proposal. If you need to change any information, select the **Edit** link. You can also use the **Edit** link to add your organization's Tax ID. The Tax ID must be related to the country listed in the **Sold to** section. If you have a tax exemption, you must open a support ticket to request tax-exempt status.
+This section shows the billing account used for the proposal. If you need to change any information, select the **Edit** link. You can also use the **Edit** link to add your organization's Tax ID. The Tax ID must be related to the country/region listed in the **Sold to** section. If you have a tax exemption, you must open a support ticket to request tax-exempt status.
To learn more about Tax IDs, and how to apply for tax-exempt status, see [Microsoft 365 tax information](billing-and-payments/tax-information.md).
enterprise Implementing Expressroute https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/implementing-expressroute.md
For outbound traffic, the people access Microsoft 365 in one of three ways:
1. Through a meet-me location in North America for the people in California.
-2. Through a meet-me location in Hong Kong for the people in Hong Kong.
+2. Through a meet-me location in Hong Kong Special Administrative Region for the people in Hong Kong SAR.
3. Through the internet in Bangladesh where there are fewer people and no ExpressRoute circuit provisioned.
Similarly, the inbound network traffic from Microsoft 365 returns in one of thre
1. Through a meet-me location in North America for the people in California.
-2. Through a meet-me location in Hong Kong for the people in Hong Kong.
+2. Through a meet-me location in Hong Kong Special Administrative Region for the people in Hong Kong SAR.
3. Through the internet in Bangladesh where there are fewer people and no ExpressRoute circuit provisioned.
enterprise M365 Dr Legacy Move Program https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/m365-dr-legacy-move-program.md
| Brazil <br/> | Nov. 1, 2022 <br/> | Apr. 30, 2023 <br/> | May 1, 2025 <br/> | | Sweden <br/> | Nov. 1, 2022 <br/> | Apr. 30, 2023 <br/> | May 1, 2025 <br/> |
-## Remaining Countries in the Move Program
+## Remaining Countries/regions in the Move Program
> [!NOTE]
-> Even though the Move Program is officially ending, we still have some in-flight geographies that we will see through to completion, based on the original 24-month migration commitment. Please refer to the table below for the remaining countries and their migration deadlines.
+> Even though the Move Program is officially ending, we still have some in-flight geographies that we will see through to completion, based on the original 24-month migration commitment. Please refer to the table below for the remaining countries/regions and their migration deadlines.
|**Customers with signup country/region in**|**Original Opt-in: migration commitment date**|**Final Opt-in (above): migration commitment date**| |:--|:--|:--|
In addition to Exchange Online, SharePoint Online, and OneDrive for Business; Mi
- Teams chat messages, including private messages and channel messages. - Teams images used in chats.
-Teams files are stored in SharePoint Online and Teams chat files are stored in OneDrive for Business. Voicemail, calendar, and contacts are stored in Exchange Online. In many cases, Exchange Online, SharePoint Online, and OneDrive for Business are already used by the customer in the local datacenter geo and are also part of the Microsoft 365 migration program for eligible customer countries.
+Teams files are stored in SharePoint Online and Teams chat files are stored in OneDrive for Business. Voicemail, calendar, and contacts are stored in Exchange Online. In many cases, Exchange Online, SharePoint Online, and OneDrive for Business are already used by the customer in the local datacenter geo and are also part of the Microsoft 365 migration program for eligible customer countries/regions.
</details>
No, this is not possible. Customers who have been moved to new geo datacenters c
### Will Microsoft 365 _Tenants_ hosted in the new datacenters be available to users outside of the country/region? <details><summary>Click to expand</summary>
-Yes. Microsoft maintains a large global network with public Internet connections in more than 130 locations in 35 countries around the world with peering agreements with more than 2,700 Internet Service Providers (ISPs). Users will be able to access the datacenters from wherever they are on the Internet.
+Yes. Microsoft maintains a large global network with public Internet connections in more than 130 locations in 35 countries/regions around the world with peering agreements with more than 2,700 Internet Service Providers (ISPs). Users will be able to access the datacenters from wherever they are on the Internet.
</details>
enterprise M365 Dr Overview https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/m365-dr-overview.md
In order to promote clarity in the capability descriptions on data residency fun
|:--|:--| |Macro Region Geography <br/> |Macro Region Geography 1 ΓÇô EMEA, Macro Region Geography ΓÇô Asia Pacific, Macro Region Geography - Americas <br/> | |Macro Region Geography 1 - EMEA <br/> |Data centers in Austria, Finland, France, Ireland, Netherlands, Poland, Sweden <br/> |
-|Macro Region Geography 2 - Asia Pacific <br/> |Data centers in Hong Kong, Japan, Malaysia, Singapore, South Korea <br/> |
+|Macro Region Geography 2 - Asia Pacific <br/> |Data centers in Hong Kong Special Administrative Region, Japan, Malaysia, Singapore, South Korea <br/> |
|Macro Region Geography 3 - Americas <br/> |Data centers in Brazil, Chile, United States <br/> | |Local Region Geography <br/> |Australia, Brazil, Canada, France, Germany, India, Japan, Poland, Qatar, South Korea, Norway, South Africa, Sweden, Switzerland, United Arab Emirates, United Kingdom <br/> | |Expanded Local Region Geography <br/> | Future planned data center regions: Italy, Indonesia, Israel, Spain, Mexico, Malaysia, Austria, Chile, New Zealand, Denmark, Greece, Taiwan <br/> |
In order to promote clarity in the capability descriptions on data residency fun
|Satellite Geography <br/> |If a customer subscribes to the Multi Geo service, then they can cause defined user customer data to be stored in other Geographies outside of the _Tenant_ _Primary Provisioned Geography_ <br/> | |AAD <br/> |Azure Active Directory <br/> | |Tenant <br/> |A _Tenant_ represents an organization in Azure Active Directory. It's a reserved Azure AD service instance that an organization receives and owns when it signs up for a Microsoft cloud service such as Azure or Microsoft 365. Each Azure AD _Tenant_ is distinct and separate from other Azure AD _Tenant's_ <br/> |
-|Default Geography <br/> |When an _AAD Tenant_ is created, a country is provided by the customer during the sign-up process. This country determines the default Geography for all Microsoft 365 services. In some cases, not all services are able to provision in this single _Default Geography_. See _Microsoft 365 Service provisioning mapping_ below for a description. <br/> |
+|Default Geography <br/> |When an _AAD Tenant_ is created, a country/region is provided by the customer during the sign-up process. This country/region determines the default Geography for all Microsoft 365 services. In some cases, not all services are able to provision in this single _Default Geography_. See _Microsoft 365 Service provisioning mapping_ below for a description. <br/> |
|Microsoft 365 Service provisioning mapping <br/> |All Microsoft 365 Services use the _Default Geography_ to determine where a given _Tenant's_ specified data will be provisioned and stored. <br/> | |Microsoft 365 Service provisioning country mapping <br/> |Refer to [data maps](https://aka.ms/datamaps) to learn where a given service provisions specified customer data, based on the _Tenant Default Geography._ <br/> | |Primary Provisioned Geography <br/> |A given Microsoft 365 service use the _Tenant Default Geography_ combined with the _Microsoft 365 Service provisioning country mapping_ to determine which _Geography_ to provision customer data into. <br/> |
In order to promote clarity in the capability descriptions on data residency fun
## Overview of Data Residency
-Microsoft 365 Cloud services run on our data centers around the world and provide services to customers around the world. Customer data may be stored in multiple data centers. Data residency refers to the geographic location where customer data is stored at rest. Data residency is important for government, public sector, education and regulated commercial entities to help ensure protection of personal and/or sensitive information. In many countries, customers are expected to comply with laws, regulations or industry standards that explicitly govern the location of data storage.
+Microsoft 365 Cloud services run on our data centers around the world and provide services to customers around the world. Customer data may be stored in multiple data centers. Data residency refers to the geographic location where customer data is stored at rest. Data residency is important for government, public sector, education and regulated commercial entities to help ensure protection of personal and/or sensitive information. In many countries/regions, customers are expected to comply with laws, regulations or industry standards that explicitly govern the location of data storage.
Microsoft makes decisions on where to persistently store customer data based on two factors:
Microsoft makes decisions on where to persistently store customer data based on
### _Default Geography_ of the AAD _Tenant_
-When a customer creates a new AAD _Tenant_, the customer enters a country during the creation process. This country is what defines the _Default Geography_ for the _Tenant_. There are multiple paths to creating _Tenants_. They can be created through AAD forms, they can be created when trying out new Microsoft 365 services (trials), etc. Once a _Tenant_ is created, the _Default Geography_ cannot be changed.
+When a customer creates a new AAD _Tenant_, the customer enters a country/region during the creation process. This country/region is what defines the _Default Geography_ for the _Tenant_. There are multiple paths to creating _Tenants_. They can be created through AAD forms, they can be created when trying out new Microsoft 365 services (trials), etc. Once a _Tenant_ is created, the _Default Geography_ cannot be changed.
### Available Geographies for a given service
In order to understand where your data, for a given service is stored, your prim
Some examples:
-**Example 1:** For a _Tenant_ with the sign-up country as "France" that has a new subscription that includes Exchange Online, SharePoint Online and Microsoft Teams, then the customer data for those services will be provisioned into the French _Local Region Geography_. Why? Because those services are deployed into the French data centers and the _Tenant_ has a France sign up country.
+**Example 1:** For a _Tenant_ with the sign-up country/region as "France" that has a new subscription that includes Exchange Online, SharePoint Online and Microsoft Teams, then the customer data for those services will be provisioned into the French _Local Region Geography_. Why? Because those services are deployed into the French data centers and the _Tenant_ has a France sign up country/region.
-**Example 2:** For a _Tenant_ with the sign-up country as "Belgium" that has a new subscription that includes Exchange Online, SharePoint Online and Microsoft Teams, then the customer data for those services will be provisioned into the _Macro Region Geography 1 ΓÇô EMEA_. Why? Because there are no Microsoft 365 data centers in Belgium and the closest Geography is _Macro Region Geography 1 - EMEA_.
+**Example 2:** For a _Tenant_ with the sign-up country/region as "Belgium" that has a new subscription that includes Exchange Online, SharePoint Online and Microsoft Teams, then the customer data for those services will be provisioned into the _Macro Region Geography 1 ΓÇô EMEA_. Why? Because there are no Microsoft 365 data centers in Belgium and the closest Geography is _Macro Region Geography 1 - EMEA_.
-**Example 3:** For a _Tenant_ with the sign-up country as "Japan" that has a new subscription that includes Microsoft Forms, then the customer data for Forms will be provisioned into the _Macro Region Geography 3 - Americas_. Why? Because Forms is only deployed in _Macro Region Geography 3 - Americas_ and _Macro Region Geography 1 ΓÇô EMEA_ (EU _Tenants_ only).
+**Example 3:** For a _Tenant_ with the sign-up country/region as "Japan" that has a new subscription that includes Microsoft Forms, then the customer data for Forms will be provisioned into the _Macro Region Geography 3 - Americas_. Why? Because Forms is only deployed in _Macro Region Geography 3 - Americas_ and _Macro Region Geography 1 ΓÇô EMEA_ (EU _Tenants_ only).
-**Example 4a:** For a _Tenant_ with the sign-up country as "Sweden" that has a new subscription that includes Microsoft Viva Engage, then the customer data for Viva Engage will be provisioned into the _Macro Region Geography 1 - EMEA_. Why? Because Viva Engage is deployed in _Macro Region Geography 1 - EMEA_ and Swedish _Tenants_ are best served out of that _Geography_.
+**Example 4a:** For a _Tenant_ with the sign-up country/region as "Sweden" that has a new subscription that includes Microsoft Viva Engage, then the customer data for Viva Engage will be provisioned into the _Macro Region Geography 1 - EMEA_. Why? Because Viva Engage is deployed in _Macro Region Geography 1 - EMEA_ and Swedish _Tenants_ are best served out of that _Geography_.
-**Example 4b:** For a _Tenant_ with the sign-up country as "Sweden" that has a subscription that includes Microsoft Viva Engage from before Viva Engage was deployed to _Macro Regional Geography 1 - EMEA_, then the customer data for Viva Engage will be located in _Macro Region Geography 3 - Americas_. Why? Because, at that time, Viva Engage only had a single deployment for all customers in _Macro Region Geography 3 - Americas_.
+**Example 4b:** For a _Tenant_ with the sign-up country/region as "Sweden" that has a subscription that includes Microsoft Viva Engage from before Viva Engage was deployed to _Macro Regional Geography 1 - EMEA_, then the customer data for Viva Engage will be located in _Macro Region Geography 3 - Americas_. Why? Because, at that time, Viva Engage only had a single deployment for all customers in _Macro Region Geography 3 - Americas_.
### Migrations/Moves
Once a Microsoft 365 service provisions a _Tenant_ into a particular _Geography_
1. The Microsoft 365 service decides to move the data to a new _Geography_ for service operations reasons, if there are no other policies in place to prevent the move. 1. If a _Tenant_ subscribes to the _Multi-Geo_ service, then _Tenants_ user's data for Exchange Online, SharePoint Online and Microsoft Teams can be assigned to _Satellite Geographies_.
-1. If a _Tenant_ has sign up country as a _Local Region Geography_ and has a subscription to the _Advanced Data Residency_ service add-on, then the _Tenant_ data for the included services will be migrated from the _Regional Geography_ to the relevant _Local Region Geography_.
+1. If a _Tenant_ has sign up country/region as a _Local Region Geography_ and has a subscription to the _Advanced Data Residency_ service add-on, then the _Tenant_ data for the included services will be migrated from the _Regional Geography_ to the relevant _Local Region Geography_.
### Durable commitments on data location
There are three methods for ensuring that the _Tenant_ data location for a parti
| Viva Topics <br/> |- <br/> |- <br/> |X<sup>3</sup> <br/> | | Microsoft Purview <br/> |- <br/> |- <br/> |X<sup>3</sup> <br/> |
-1. Only available in the following countries/region: Australia, Brazil, Canada, France, Germany, India, Japan, Poland, Qatar, South Korea, Norway, South Africa, Sweden, Switzerland, United Arab Emirates, United Kingdom, European Union and the United States.
+1. Only available in the following countries/regions: Australia, Brazil, Canada, France, Germany, India, Japan, Poland, Qatar, South Korea, Norway, South Africa, Sweden, Switzerland, United Arab Emirates, United Kingdom, European Union and the United States.
1. Available in _Local Region Geography_, _Expanded Local Region Geography_ (when the future data center is launched) and _Regional Geography countries/regions_
-1. Only available for _Local Region Geography_ and _Expanded Local Region Geography_ (when the future data center is launced) countries.
+1. Only available for _Local Region Geography_ and _Expanded Local Region Geography_ (when the future data center is launced) countries/regions.
>[!NOTE] >See the [Workload Data Residency Capabilities section](m365-dr-workload-exo.md) for more details on these topics.
-**Table 3: Available Data Residency by Country**
+**Table 3: Available Data Residency by Country/Region**
-| Country | Exchange Online | SharePoint Online | Teams | MDO P1 | Office for the web | Viva Connections | Viva Topics | Purview |
+| Country/Region | Exchange Online | SharePoint Online | Teams | MDO P1 | Office for the web | Viva Connections | Viva Topics | Purview |
| | | | | | | | | | | Australia | P-M-A | P-M-A | P-M-A | A | A | A | A | A | | Brazil | P-M-A | P-M-A | P-M-A | A | A | A | A | A |
The following Regional Geographies can store data at rest.
|**Regional Geographies** |**Locations where customer data may be stored** | ||| |Macro Region Geography 1 - EMEA (Europe, Middle East and Africa) | Austria, Finland, France, Ireland, Netherlands, Poland, Sweden |
-|Macro Region Geography 2 - Asia Pacific | Hong Kong, Japan, Malaysia, Singapore, South Korea |
+|Macro Region Geography 2 - Asia Pacific | Hong Kong SAR, Japan, Malaysia, Singapore, South Korea |
|Macro Region Geography 3 - Americas | Brazil, Chile, United States | **Table 5: Current Local Geographies and Region specific Datacenter locations**
-|Country |Datacenter Location |
+|Country/Region |Datacenter Location |
||| |Australia |Sydney, Melbourne | |Brazil |Rio, Campinas |
enterprise M365 Dr Workload Other https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/m365-dr-workload-other.md
Please refer to [Data Residency - Viva Engage | Microsoft Learn](/viva/engage/ma
| HM | Heard and Mcdonald Islands | AMER<sup>3</sup>| AMER<sup>3</sup>| AMER<sup>3</sup>| | VA | Holy See (Vatican City State) | EUR<sup>1</sup>| EUR<sup>1</sup>| EUR<sup>1</sup>| | HN | Honduras | AMER<sup>3</sup>| AMER<sup>3</sup>| AMER<sup>3</sup>|
-| HK | Hong Kong, SAR China | APC<sup>2</sup>| APC<sup>2</sup>| APC<sup>2</sup>|
+| HK | Hong Kong SAR | APC<sup>2</sup>| APC<sup>2</sup>| APC<sup>2</sup>|
| HU | Hungary | EUR<sup>1</sup>| EUR<sup>1</sup>| EUR<sup>1</sup>| | IS | Iceland | EUR<sup>1</sup>| EUR<sup>1</sup>| EUR<sup>1</sup>| | IN | India | APC<sup>2</sup>| APC<sup>2</sup>| IND<sup>7</sup>|
Please refer to [Data Residency - Viva Engage | Microsoft Learn](/viva/engage/ma
| LI | Liechtenstein | EUR<sup>1</sup>| EUR<sup>1</sup>| EUR<sup>1</sup>| | LT | Lithuania | EUR<sup>1</sup>| EUR<sup>1</sup>| EUR<sup>1</sup>| | LU | Luxembourg | EUR<sup>1</sup>| EUR<sup>1</sup>| EUR<sup>1</sup>|
-| MO | Macao, SAR China | APC<sup>2</sup>| APC<sup>2</sup>| APC<sup>2</sup>|
+| MO | Macao, SAR | APC<sup>2</sup>| APC<sup>2</sup>| APC<sup>2</sup>|
| MG | Madagascar | EUR<sup>1</sup>| EUR<sup>1</sup>| EUR<sup>1</sup>| | MW | Malawi | EUR<sup>1</sup>| EUR<sup>1</sup>| EUR<sup>1</sup>| | MY | Malaysia | APC<sup>2</sup>| APC<sup>2</sup>| APC<sup>2</sup>|
enterprise M365 Dr Workload Spo https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/m365-dr-workload-spo.md
Required Conditions: -- _Tenant_ has a sign up country included in _Local Region Geography_, the European Union or the United States.
+- _Tenant_ has a sign up country/region included in _Local Region Geography_, the European Union or the United States.
**Commitment:**
_For current language please refer to the [Privacy and Security Product Terms](h
Required Conditions:
-1. _Tenant_ has a sign up country included in _Local Region Geography_ or _Expanded Local Region Geography_.
+1. _Tenant_ has a sign up country/region included in _Local Region Geography_ or _Expanded Local Region Geography_.
1. _Tenant_ has a valid Advanced Data Residency subscription for all users in the _Tenant_. 1. The SharePoint Online subscription customer data is provisioned in _Local Region Geography_ or _Expanded Local Region Geography_.
enterprise Microsoft 365 Exchange Monitoring Service Advisories https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/microsoft-365-exchange-monitoring-service-advisories.md
f1.keywords: - NOCSH description: "Service advisory explains surge in eDiscovery cmdlet exceptions affecting Compliance Search PowerShell cmdlets."- # Service advisories for eDiscovery cmdlet exception spike in Exchange Online monitoring
enterprise Multi Tenant People Search https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/multi-tenant-people-search.md
The Multi-Tenant Organization (MTO) People Search is a collaboration feature tha
![AAD sync](../media/mt-people-search/aad-sync.png)
-> _Fig 1: Azure AD cross tenant synchronization illustration
+> _Fig 1: Azure AD cross tenant synchronization illustration_
## Example scenario
enterprise Office 365 Network Mac Perf Onboarding Tool https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/enterprise/office-365-network-mac-perf-onboarding-tool.md
We recommend that these insights be used together where networking quality statu
### Office location identification
-When you click the *Run test* button, we show the running test page and identify the office location. You can type in your location by city, state, and country or choose to have it detected for you. If you detect the office location, the tool requests the latitude and longitude from the web browser and limits the accuracy to 300 meters by 300 meters before use. It's not necessary to identify the location more accurately than the building to measure network performance.
+When you click the *Run test* button, we show the running test page and identify the office location. You can type in your location by city, state, and country/region or choose to have it detected for you. If you detect the office location, the tool requests the latitude and longitude from the web browser and limits the accuracy to 300 meters by 300 meters before use. It's not necessary to identify the location more accurately than the building to measure network performance.
### JavaScript tests
The executable accepts the following command line parameters:
- -h to show a link to this help documentation - -testlist &lt;test&gt; Specifies tests to run. By default only basic tests are run. Valid test names include: all, dnsConnectivityPerf, dnsResolverIdentification, bufferBloat, traceroute, proxy, vpn, skype, connectivity, networkInterface - -filepath &lt;filedir&gt; Directory path of test result files. Allowed value is absolute or relative path of an accessible directory-- -city &lt;city&gt; For the city, state, and country fields the specified value will be used if provided. If not provided then Windows Location Services (WLS) will be queried. If WLS fails the location will be detected fromthe machines network egress
+- -city &lt;city&gt; For the city, state, and country/region fields the specified value will be used if provided. If not provided then Windows Location Services (WLS) will be queried. If WLS fails the location will be detected fromthe machines network egress
- -state &lt;state&gt; - -country &lt;country&gt; - -proxy &lt;account&gt; &lt;password&gt; Proxy account name and password can be provided if you require a proxy to access the Internet
On a CMD.EXE command prompt window you can type the path and name of the executa
In Windows Task Scheduler you can add a task to launch the standalone test executable. You should specify the current working directory of the task to be where you have created the EULA accepted file since the executable will block until the EULA is accepted. You cannot interactively accept the EULA if the process is started in the background with no console. ### More details on the standalone executable
-The commandline tool uses Windows Location Services to find the users City State Country information for determining some distances. If Windows Location Services is disabled in the control panel then user location based assessments will be blank. In Windows Settings "Location services" must be on and "Let desktop apps access your location" must also be on.
+The commandline tool uses Windows Location Services to find the users City State Country/region information for determining some distances. If Windows Location Services is disabled in the control panel then user location based assessments will be blank. In Windows Settings "Location services" must be on and "Let desktop apps access your location" must also be on.
The commandline tool will attempt to install the .NET Framework if it is not already installed. It will also download the main testing executable from the Microsoft 365 network connectivity test tool and launch that.
frontline Advanced Virtual Appointments Activity Report https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/advanced-virtual-appointments-activity-report.md
Title: Microsoft Teams Advanced Virtual Appointments activity report---+++ audience: Admin
frontline Browser Join https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/browser-join.md
Title: Manage the join experience for Teams Virtual Appointments on browsers---+++ audience: ITPro
frontline Collab Features Apps Toolkit https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/collab-features-apps-toolkit.md
Title: Help your frontline workers use collaboration apps and features---+++ audience: ITPro
frontline Deploy Dynamic Teams At Scale https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/deploy-dynamic-teams-at-scale.md
Title: Deploy frontline dynamic teams at scale--+++ - audience: admin
frontline Deploy Teams At Scale https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/deploy-teams-at-scale.md
Title: Deploy frontline static teams at scale with PowerShell for frontline workers--+++ - audience: admin
frontline Ehr Admin Epic https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/ehr-admin-epic.md
Title: Virtual Appointments with Teams - Integration into Epic EHR---+++ audience: ITPro
frontline Ehr Admin Oracle Health https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/ehr-admin-oracle-health.md
Title: Virtual Appointments with Teams - Integration into Oracle Health EHR---+++ audience: ITPro
frontline Ehr Connector Report https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/ehr-connector-report.md
Title: Microsoft Teams EHR connector Virtual Appointments report---+++ audience: ITPro
frontline Ehr Connector Troubleshoot Setup Configuration https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/ehr-connector-troubleshoot-setup-configuration.md
Title: Troubleshoot Microsoft Teams EHR connector setup and configuration---+++ audience: ITPro
frontline Flw Choose Scenarios https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-choose-scenarios.md
Title: Choose your scenarios for Microsoft 365 for frontline workers description: Learn about scenarios you can easily implement for the frontline workers in your organization. search.appverid: MET150---+++ audience: admin
frontline Flw Corp Comms https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-corp-comms.md
Title: Corporate communications with frontline workers description: Learn how you can use Viva Connections and Viva Engage to connect your frontline team to your broader organization. --+++ audience: admin- f1.keywords: - NOCSH
frontline Flw Deploy Overview https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-deploy-overview.md
Title: Learn where to start with a frontline deployment--+++ - audience: admin
frontline Flw Devices https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-devices.md
Title: Manage devices for frontline workers--+++ - audience: admin
frontline Flw Licensing Options https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-licensing-options.md
Title: Understand frontline worker user types and licensing--+++ - audience: admin
frontline Flw Onboarding Training https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-onboarding-training.md
Title: Provide initial and ongoing training to help onboard your frontline workers description: Learn how you can plan, build, and launch your frontline worker onboarding experience. --+++ audience: admin- f1.keywords: - NOCSH
frontline Flw Overview https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-overview.md
Title: Get started with Microsoft 365 for frontline workers description: Learn how you can use Microsoft 365 and Teams to empower the frontline workers in your organization. search.appverid: MET150---+++ audience: admin
frontline Flw Pilot https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-pilot.md
Title: Start with a pilot deployment of Microsoft 365 for frontline workers description: Learn how to run a pilot deployment for the frontline workers in your organization. --+++ - audience: admin
frontline Flw Scenario Posters https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-scenario-posters.md
Title: Microsoft 365 for frontline workers - scenario posters description: Download these PDF posters to learn about scenarios you can easily implement for the frontline workers in your organization. search.appverid: MET150---+++ audience: admin
frontline Flw Setup Microsoft 365 https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-setup-microsoft-365.md
Title: Set up Microsoft 365 for frontline workers--+++ - audience: admin
frontline Flw Team Collaboration https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-team-collaboration.md
Title: Frontline team collaboration description: Learn how your frontline teams can communicate and collaborate effectively within or across locations. --+++ audience: admin- f1.keywords: - NOCSH
frontline Flw Trial https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-trial.md
Title: Manage the Frontline Trial in Teams--+++ - audience: admin
frontline Flw Wellbeing Engagement https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/flw-wellbeing-engagement.md
Title: Engage your frontline employees and focus on wellbeing description: Learn how to use Viva Connections, SharePoint, Microsoft Teams, and the Praise app to increase frontline worker wellbeing and engagement. --+++ audience: admin- f1.keywords: - NOCSH
frontline Frontline Team Options https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/frontline-team-options.md
Title: How to find the best frontline team solution for your organization--+++ - audience: admin
frontline Get Up And Running https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/get-up-and-running.md
Title: Managers - Get your team started with Microsoft 365 for frontline workers--+++ - audience: admin
frontline Hc Delegates https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/hc-delegates.md
Title: Use a Teams status message to assign a delegate---+++ audience: ITPro
frontline Manage Shift Based Access Flw https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/manage-shift-based-access-flw.md
Title: Manage shift-based access for frontline workers in Teams----+++ audience: admin
frontline Messaging Policies Hc https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/messaging-policies-hc.md
Title: Secure Messaging for healthcare organizations using Microsoft Teams---+++ audience: ITPro
frontline Pin Teams Apps Based On License https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/pin-teams-apps-based-on-license.md
Title: Tailor Teams apps for your frontline workers--+++ - audience: admin
frontline Schedule Owner For Shift Management https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/schedule-owner-for-shift-management.md
Title: Manage schedule owners for shift management----+++ audience: admin
frontline Shifts Connector Blue Yonder Admin Center Manage https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-blue-yonder-admin-center-manage.md
Title: Use the Microsoft 365 admin center to manage your Shifts connection to Blue Yonder Workforce Management (Preview)--+++ - audience: admin
frontline Shifts Connector Blue Yonder Known Issues https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-blue-yonder-known-issues.md
Title: Teams Shifts connector for Blue Yonder known issues--+++ - audience: admin
frontline Shifts Connector Blue Yonder Powershell Setup https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-blue-yonder-powershell-setup.md
Title: Use PowerShell to connect Shifts to Blue Yonder Workforce Management--+++ - audience: admin
frontline Shifts Connector Powershell Manage https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-powershell-manage.md
Title: Use PowerShell to manage your Shifts connection to Blue Yonder Workforce Management--+++ - audience: admin
frontline Shifts Connector Ukg Admin Center Manage https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-ukg-admin-center-manage.md
Title: Use the Microsoft 365 admin center to manage your Shifts connection to UKG Dimensions (Preview)--+++ - audience: admin
frontline Shifts Connector Ukg Known Issues https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-ukg-known-issues.md
Title: Team Shifts connector for UKG Dimensions known issues--+++ - audience: admin
frontline Shifts Connector Ukg Powershell Manage https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-ukg-powershell-manage.md
Title: Use PowerShell to manage your Shifts connection to UKG Dimensions--+++ - audience: admin
frontline Shifts Connector Ukg Powershell Setup https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-ukg-powershell-setup.md
Title: Use PowerShell to connect Shifts to UKG Dimensions--+++ - audience: admin
frontline Shifts Connector Wizard Ukg https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-wizard-ukg.md
Title: Use the Shifts connector wizard to connect Shifts to UKG Dimensions (Preview)--+++ - audience: admin
frontline Shifts Connector Wizard https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connector-wizard.md
Title: Use the Shifts connector wizard to connect Shifts to Blue Yonder Workforce Management (Preview)--+++ - audience: admin
frontline Shifts Connectors https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-connectors.md
Title: Shifts connectors----+++ audience: admin
frontline Shifts For Teams Landing Page https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-for-teams-landing-page.md
Title: Shifts for frontline workers description: Get the admin guidance you need to set up and manage Shifts, the schedule management tool, in Microsoft Teams. --+++ audience: admin- f1.keywords: - NOCSH
frontline Shifts Toolkit https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/shifts-toolkit.md
Title: Help your frontline workers track time and attendance---+++ audience: ITPro
frontline Simplify Business Processes https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/simplify-business-processes.md
Title: Simplify business processes for frontline teams description: Learn how your frontline workforce can simplify their business processes with Microsoft Teams. --+++ audience: admin- f1.keywords: - NOCSH
frontline Sms Notifications Usage Report https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/sms-notifications-usage-report.md
Title: Microsoft Teams SMS notifications usage report---+++ audience: Admin
frontline Switch From Enterprise To Frontline https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/switch-from-enterprise-to-frontline.md
Title: Changing from a Microsoft 365 E plan to a Microsoft 365 F plan----+++ audience: admin
frontline Teams For Financial Services https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/teams-for-financial-services.md
Title: Microsoft 365 for Financial Services description: Learn about the admin resources available to manage and get the most out of Teams for your frontline financial services workforce. --+++ audience: admin- f1.keywords: - NOCSH
frontline Teams For Manufacturing https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/teams-for-manufacturing.md
Title: Microsoft 365 for Manufacturing description: Learn about the admin resources available to manage and get the most out of Teams for your frontline manufacturing workforce. --+++ audience: admin- f1.keywords: - NOCSH
frontline Teams For Retail Landing Page https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/teams-for-retail-landing-page.md
Title: Microsoft 365 for retail organizations description: Learn about the admin resources available to manage and get the most out of Teams for your retail stores and workforce. --++
+audience: admin
f1.keywords: - NOCSH
frontline Teams In Hc https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/teams-in-hc.md
Title: Get started with Microsoft 365 for healthcare organizations---+++ audience: ITPro
frontline Virtual Appointments App https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/virtual-appointments-app.md
Title: Use the Virtual Appointments app in Microsoft Teams---+++ audience: ITPro
frontline Virtual Appointments Call Quality https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/virtual-appointments-call-quality.md
Title: Microsoft Teams Virtual Appointments Call Quality Dashboard---+++ audience: Admin
frontline Virtual Appointments Toolkit https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/virtual-appointments-toolkit.md
Title: Help your clients and customers use virtual appointments scheduled with the Bookings app in Teams---+++ audience: ITPro
frontline Virtual Appointments Usage Report https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/virtual-appointments-usage-report.md
Title: Microsoft Teams Virtual Appointments usage report---+++ audience: Admin
frontline Virtual Appointments https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/frontline/virtual-appointments.md
Title: Virtual Appointments with Microsoft Teams--+++ - audience: admin
security Configure Proxy Internet https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/configure-proxy-internet.md
The following downloadable spreadsheet lists the services and their associated U
| Microsoft Defender for Endpoint URL list for Gov/GCC/DoD | Spreadsheet of specific DNS records for service locations, geographic locations, and OS for Gov/GCC/DoD customers. <p> [Download the spreadsheet here.](https://download.microsoft.com/download/6/e-urls-gov.xlsx) If a proxy or firewall has HTTPS scanning (SSL inspection) enabled, exclude the domains listed in the above table from HTTPS scanning.
-In your firewall, open all the URLs where the geography column is WW. For rows where the geography column isn't WW, open the URLs to your specific data location. To verify your data location setting, see [Verify data storage location and update data retention settings for Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/data-retention-settings). Don't exclude the URL `*.blob.core.windows.net` from any kind of network inspection.
+In your firewall, open all the URLs where the geography column is WW. For rows where the geography column isn't WW, open the URLs to your specific data location. To verify your data location setting, see [Verify data storage location and update data retention settings for Microsoft Defender for Endpoint](/microsoft-365/security/defender-endpoint/data-retention-settings).
> [!NOTE] > Windows devices running with version 1803 or earlier needs `settings-win.data.microsoft.com`. <br>
security Customize Exploit Protection https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/customize-exploit-protection.md
For the associated PowerShell cmdlets for each mitigation, see the [PowerShell r
> Josie configures **Data Execution Prevention (DEP)** in the **System settings** section to be **Off by default**. Josie then adds the app *test.exe* to the **Program settings** section. In the options for that app, under **Data Execution Prevention (DEP)**, she enables the **Override system settings** option and sets the switch to **On**. Josie also adds the app *miles.exe* to the **Program settings** section and configures **Control flow guard (CFG)** to **On**. She doesn't enable the **Override system settings** option for DEP or any other mitigations for that app. The result will be that DEP will be enabled for *test.exe*. DEP will not be enabled for any other app, including *miles.exe*. CFG will be enabled for *miles.exe*. > [!NOTE]
-> If you have found any issues in this article, you can report it directly to a Windows Server/Windows Client partner or use the Microsoft technical support numbers for your country.
+> If you have found any issues in this article, you can report it directly to a Windows Server/Windows Client partner or use the Microsoft technical support numbers for your country/region.
### Configure system-level mitigations with the Windows Security app
security Prevent Changes To Security Settings With Tamper Protection https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/prevent-changes-to-security-settings-with-tamper-protection.md
Title: Protect security settings with tamper protection-+ description: Use tamper protection to prevent malicious apps from changing important security settings.
To learn more about Microsoft Defender Vulnerability Management, see [Dashboard
- [Frequently asked questions on tamper protection](faqs-on-tamper-protection.yml) - [Troubleshoot problems with tamper protection](troubleshoot-problems-with-tamper-protection.yml) [!INCLUDE [Microsoft Defender for Endpoint Tech Community](../../includes/defender-mde-techcommunity.md)]+
security Technological Partners https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender-endpoint/technological-partners.md
search.appverid: met150 Previously updated : 09/28/2022 Last updated : 08/03/2023 # Technological partners of Microsoft 365 Defender
The following are the solution's categories:
|[Vulcan Cyber risk management platform](https://go.microsoft.com/fwlink/?linkid=2201770)|Vulcan Cyber|Vulcan Cyber gives you the tools to effectively manage the vulnerability and risk lifecycle for all your cyber assets, including application, cloud, and infrastructure.| |[Extended Security Posture Management (XSPM)](https://go.microsoft.com/fwlink/?linkid=2201771)|Cymulate|Cymulate's Extended Security Posture Management enables companies to challenge, assess, and optimize their cybersecurity posture.| |[Illusive Platform](https://go.microsoft.com/fwlink/?linkid=2201778)|Illusive Networks|Illusive continuously discovers and automatically remediates identity vulnerabilities, and it detects attacks using deceptive controls.|
+|[ServiceNow vulnerability response](https://go.microsoft.com/fwlink/?linkid=2243580)| ServiceNow | Use the Microsoft Threat and vulnerability management integration to import third-party scanner data about your assets and vulnerabilities. You can then view reports about vulnerabilities and vulnerable items on the Vulnerability Response dashboards.
### Secure service edge
security Alert Grading Password Spray Attack https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender/alert-grading-password-spray-attack.md
This section contains step-by-step guidance to respond to the alert and take the
### 2. Investigate suspicious user activity
- - **Are there unusual events with uncommon properties?** Unique properties for an impacted user, like unusual ISP, country, or city, might indicate suspicious sign-in patterns.
+ - **Are there unusual events with uncommon properties?** Unique properties for an impacted user, like unusual ISP, country/region, or city, might indicate suspicious sign-in patterns.
- **Is there a marked increase in email or file-related activities?** Suspicious events like increased attempts in mail access or send activity or an increase in uploading of files to SharePoint or OneDrive for an impacted user are some signs to look for.
This section contains step-by-step guidance to respond to the alert and take the
- [Classifying alerts for suspicious email forwarding activity](alert-grading-playbook-email-forwarding.md) - [Classifying alerts for suspicious inbox forwarding rules](alert-grading-playbook-inbox-forwarding-rules.md) - [Classifying alerts for suspicious inbox manipulation rules](alert-grading-playbook-inbox-manipulation-rules.md)
- - **Check whether the user received other alerts before the password spray activity.** Having these alerts indicate that the user account might be compromised. Examples include impossible travel alert, activity from infrequent country, and suspicious email deletion activity, among others.
+ - **Check whether the user received other alerts before the password spray activity.** Having these alerts indicate that the user account might be compromised. Examples include impossible travel alert, activity from infrequent country/region, and suspicious email deletion activity, among others.
## Advanced hunting queries
security Alert Grading Password Spray https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender/alert-grading-password-spray.md
Filter all successful attempts to sign in from the IP address around and shortly
- Alerts
- **Check whether the user received other alerts preceding the password spray activity.** Having these alerts indicate that the user account might be compromised. Examples include impossible travel alert, activity from infrequent country, and suspicious email deletion activity, among others.
+ **Check whether the user received other alerts preceding the password spray activity.** Having these alerts indicate that the user account might be compromised. Examples include impossible travel alert, activity from infrequent country/region, and suspicious email deletion activity, among others.
- Incident
security Alert Grading Playbook Inbox Forwarding Rules https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/defender/alert-grading-playbook-inbox-forwarding-rules.md
CloudAppEvents
| make-series ActivityCount = count() default = 0 on Timestamp from (alert_date-timeback) to (alert_date-1h) step 12h by ISP ```
-Run this query to check whether the country is common for the user by looking at the history of the user.
+Run this query to check whether the country/region is common for the user by looking at the history of the user.
```kusto let alert_date = now(); //enter alert date
security Supply Chain Malware https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/intelligence/supply-chain-malware.md
Attackers hunt for unsecure network protocols, unprotected server infrastructure
Because software is built and released by trusted vendors, these apps and updates are signed and certified. In software supply chain attacks, vendors are likely unaware that their apps or updates are infected with malicious code when they're released to the public. The malicious code then runs with the same trust and permissions as the app.
-The number of potential victims is significant, given the popularity of some apps. A case occurred where a free file compression app was poisoned and deployed to customers in a country where it was the top utility app.
+The number of potential victims is significant, given the popularity of some apps. A case occurred where a free file compression app was poisoned and deployed to customers in a country/region where it was the top utility app.
### Types of supply chain attacks
security Anti Spam Protection About https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/anti-spam-protection-about.md
You can also use the following suggestions to help prevent false positives:
## Anti-spam legislation
-At Microsoft, we believe that the development of new technologies and self-regulation requires the support of effective government policy and legal frameworks. The worldwide spam proliferation has spurred numerous legislative bodies to regulate commercial email. Many countries now have spam-fighting laws in place. The United States has both federal and state laws governing spam, and this complementary approach is helping to curtail spam while enabling legitimate e-commerce to prosper. The CAN-SPAM Act expands the tools available for curbing fraudulent and deceptive email messages.
+At Microsoft, we believe that the development of new technologies and self-regulation requires the support of effective government policy and legal frameworks. The worldwide spam proliferation has spurred numerous legislative bodies to regulate commercial email. Many countries/regions now have spam-fighting laws in place. The United States has both federal and state laws governing spam, and this complementary approach is helping to curtail spam while enabling legitimate e-commerce to prosper. The CAN-SPAM Act expands the tools available for curbing fraudulent and deceptive email messages.
security Mcas Saas Access Policies https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/mcas-saas-access-policies.md
You might want to apply additional monitoring and controls to specific SaaS apps
For example, you can protect your Box environment with these types of built-in anomaly detection policy templates: - Activity from anonymous IP addresses-- Activity from infrequent country
+- Activity from infrequent country/region
- Activity from suspicious IP addresses - Impossible travel - Activity performed by terminated user (requires AAD as IdP)
security Quarantine About https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/quarantine-about.md
description: Admins can learn about quarantine in Exchange Online Protection (EOP) that holds potentially dangerous or unwanted messages. Previously updated : 6/19/2023 Last updated : 7/24/2023 appliesto: - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/eop-about" target="_blank">Exchange Online Protection</a> - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/microsoft-defender-for-office-365-product-overview#microsoft-defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 plan 1 and plan 2</a>
appliesto:
In Microsoft 365 organizations with mailboxes in Exchange Online or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, quarantine is available to hold potentially dangerous or unwanted messages.
+> [!NOTE]
+> Quarantine isn't available in Microsoft 365 operated by 21Vianet.
+ Whether a detected message is quarantined by default depends on the following factors: - The protection feature that detected the message. For example, the following detections are always quarantined:
security Quarantine Admin Manage Messages Files https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/quarantine-admin-manage-messages-files.md
description: Admins can learn how to view and manage quarantined messages for all users in Exchange Online Protection (EOP). Admins in organizations with Microsoft Defender for Office 365 can also manage quarantined files in SharePoint Online, OneDrive for Business, and Microsoft Teams. Previously updated : 7/7/2023 Last updated : 8/2/2023 appliesto: - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/eop-about" target="_blank">Exchange Online Protection</a> - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/microsoft-defender-for-office-365-product-overview#microsoft-defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 plan 1 and plan 2</a>
When you select multiple quarantined messages on the **Email** tab by selecting
:::image type="content" source="../../media/quarantine-message-bulk-actions.png" alt-text="The available actions when selecting multiple messages on the Email tab in quarantine." lightbox="../../media/quarantine-message-bulk-actions.png":::
+### Find who deleted a quarantined message
+
+By default, many security policy verdicts allow users to delete their quarantined messages (messages where they're a recipient). For more information, see the table at [Manage quarantined messages and files as a user](quarantine-end-user.md).
+
+Admins can search the audit log to find events for messages that were deleted from quarantine by using the following procedures:
+
+1. In the Defender portal at <https://security.microsoft.com>, go to **Audit**. Or, to go directly to the **Audit** page, use <https://security.microsoft.com/auditlogsearch>.
+
+ > [!TIP]
+ > You can also get to the **Audit** page in the Microsoft Purview compliance portal at <https://compliance.microsoft.com/auditlogsearch>
+
+2. On the **Audit** page, verify that the **New Search** tab is selected, and then configure the following settings:
+
+ - **Date and time range (UTC)**
+ - **Activities - friendly names**: Click in the box, start typing "quarantine" in the :::image type="icon" source="../../media/m365-cc-sc-search-icon.png" border="false"::: **Search** box that appears, and then select **Deleted Quarantine message** from the results.
+ - **Users**: If know who deleted the message from quarantine, you can further filter the results by user.
+
+3. When you're finished entering the search criteria, select **Search** to generate the search.
+
+For complete instructions for audit log searches, see [Audit New Search](/purview/audit-new-search).
+ ## Use the Microsoft 365 Defender portal to manage quarantined files in Defender for Office 365 > [!NOTE]
security Quarantine End User https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/quarantine-end-user.md
description: Users can learn how to view and manage quarantined messages in Exch
adobe-target: true Previously updated : 6/30/2023 Last updated : 8/2/2023 appliesto: - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/eop-about" target="_blank">Exchange Online Protection</a> - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/microsoft-defender-for-office-365-product-overview#microsoft-defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 plan 1 and plan 2</a>
If you don't release or remove a message, it's automatically deleted from quaran
After you select the message, use either of the following methods to request its release: - **On the Email tab**: Select :::image type="icon" source="../../media/m365-cc-sc-edit-icon.png" border="false"::: **Request release**.-- **In the details flyout of the selected message**: Select :::image type="icon" source="../../media/m365-cc-sc-more-actions-icon.png" border="false"::: **More options** \> :::image type="icon" source="../../media/m365-cc-sc-edit-icon.png" border="false"::: **Request release**..
+- **In the details flyout of the selected message**: Select :::image type="icon" source="../../media/m365-cc-sc-more-actions-icon.png" border="false"::: **More options** \> :::image type="icon" source="../../media/m365-cc-sc-edit-icon.png" border="false"::: **Request release**.
In the **Request release** flyout that opens, review the information, select **Request release**. In the **Release requested** flyout that opens, select **Done**.
In the **Delete (n) messages from quarantine** flyout that opens, use one of the
After you select **Delete** on the **Delete (n) messages from quarantine** flyout, you return to the **Email** tab where the message is no longer listed.
+> [!TIP]
+> Admins can find out who deleted a quarantined message by searching the admin audit log. For instructions, see [Find who deleted a quarantined message](quarantine-admin-manage-messages-files.md#find-who-deleted-a-quarantined-message).
+ #### Preview email from quarantine After you select the message, use either of the following methods to preview it:
Select the **Microsoft Message Header Analyzer** link to analyze the header fiel
#### Block email senders from quarantine
-The Block senders action adds the message sender to the Blocked Senders list in the your mailbox. For more information about blocking senders, see [Block a mail sender](https://support.microsoft.com/office/b29fd867-cac9-40d8-aed1-659e06a706e4).
+The Block senders action adds the message sender to the Blocked Senders list in your mailbox. For more information about blocking senders, see [Block a mail sender](https://support.microsoft.com/office/b29fd867-cac9-40d8-aed1-659e06a706e4).
After you select the message, use either of the following methods to add the message sender to the Blocked Senders list in your mailbox:
When you select multiple quarantined messages on the **Email** tab by selecting
## Manage quarantined messages in Microsoft Teams
-When a potentially malicious chat message is detected in Microsoft Teams, zero-hour auto purge (ZAP) removes the message and quarantines it. Users can now view and manage these quarantined Teams messages in the Microsoft 365 Defender portal. Note that end user quarantine notifications are not supported for Teams workload.
+When a potentially malicious chat message is detected in Microsoft Teams, zero-hour auto purge (ZAP) removes the message and quarantines it. Users can now view and manage these quarantined Teams messages in the Microsoft 365 Defender portal. Quarantine notifications aren't supported for quarantined Teams messages.
### View your quarantined messages in Microsoft Teams
You can sort the entries by clicking on an available column header. Select :::im
- **Date quarantined**: Showed when the message was quarantined. - **Status**: Shows whether the message is already reviewed and released or needs review. - **Sender**: The person who sent the message that was quarantined.-- **Quarantine reason**: Available options are "High confidence phish" and "Malware".
+- **Quarantine reason**: Available options are **High confidence phish** and **Malware**.
- **Expires**: Indicates the time after which the message is removed from quarantine. By default, this value is 30 days. To filter the entries, select :::image type="icon" source="../../media/m365-cc-sc-filter-icon.png" border="false"::: **Filter**. The following filters are available in the **Filters** flyout that opens:
On the **Teams messages** tab, select the quarantined message by selecting the c
- **Delete**: You can request to delete the message from the list of quarantined messages. - **Preview message**: You can view the details of the message you selected.
-Note that if you don't release or remove a message, it's automatically deleted from quarantine after the date shown in the **Expires** column.
+If you don't release or remove a message, it's automatically deleted from quarantine after the date shown in the **Expires** column.
security Quarantine Policies https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/quarantine-policies.md
description: Admins can learn how to use quarantine policies to control what users are able to do to quarantined messages. Previously updated : 7/12/2023 Last updated : 8/2/2023 appliesto: - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/eop-about" target="_blank">Exchange Online Protection</a> - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/microsoft-defender-for-office-365-product-overview#microsoft-defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 plan 1 and plan 2</a>
appliesto:
In Exchange Online Protection (EOP) and Microsoft Defender for Office 365, _quarantine policies_ allow admins to define the user experience for quarantined messages: - What users are allowed to do to their own quarantined messages (messages where they're a recipient) based on why the message was quarantined.-- Whether users receive periodic notifications about their quarantined messages via [quarantine notifications](quarantine-quarantine-notifications.md).
+- Whether users receive periodic (every four hours, daily, or weekly) notifications about their quarantined messages via [quarantine notifications](quarantine-quarantine-notifications.md).
Traditionally, users have been allowed or denied levels of interactivity with quarantine messages based on why the message was quarantined. For example, users can view and release messages that were quarantined as spam or bulk, but they can't view or release messages that were quarantined as high confidence phishing or malware.
You create and assign quarantine policies in the Microsoft 365 Defender portal o
## What do you need to know before you begin?
+- Quarantine isn't available in Microsoft 365 operated by 21Vianet.
+ - You open the Microsoft 365 Defender portal at <https://security.microsoft.com>. To go directly to the **Quarantine policies** page, use <https://security.microsoft.com/quarantinePolicies>. - To connect to Exchange Online PowerShell, see [Connect to Exchange Online PowerShell](/powershell/exchange/connect-to-exchange-online-powershell). To connect to standalone EOP PowerShell, see [Connect to Exchange Online Protection PowerShell](/powershell/exchange/connect-to-exchange-online-protection-powershell).
To create customized quarantine notifications for up to three languages, do the
Although this box is in the middle of the page, you need to select it first. If you enter values in the **Sender display name**, **Subject**, or **Disclaimer** boxes before you select the language value, the other values are removed and you start over when you select the language value.
+ > [!NOTE]
+ > The language value **English** maps to every English language code except en-US. If you have users with en-US mailboxes only, use the value **Default**. If you have a mix of mailboxes with en-US and other English languages codes (en-GB, en-CA, en-AU, etc.), use the language value **Default** in one customized quarantine notification, and the language value **English** in another customized quarantine notification.
+ 2. Enter values for **Sender display name**, **Subject**, and **Disclaimer**. The values must be unique for each language. If you try to reuse a value in a different language, you'll get an error when you select **Save**. 3. Select the **Add** button. 4. Repeat the previous steps to create a maximum of three customized quarantine notifications based on the recipient's language. An unlabeled box shows the languages that you've configured:
If the **Delete** permission is enabled:
If the **Delete** permission is disabled, users can't delete their own messages from quarantine (the action isn't available).
+> [!TIP]
+> Admins can find out who deleted a quarantined message by searching the admin audit log. For instructions, see [Find who deleted a quarantined message](quarantine-admin-manage-messages-files.md#find-who-deleted-a-quarantined-message).
+ ##### Preview permission The **Preview** permission (_PermissionToPreview_) allows users to preview their messages in quarantine.
security Quarantine Quarantine Notifications https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/quarantine-quarantine-notifications.md
description: Admins can learn about end-user spam notifications for quarantined messages in Exchange Online Protection (EOP). Previously updated : 6/19/2023 Last updated : 7/24/2023 appliesto: - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/eop-about" target="_blank">Exchange Online Protection</a> - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/microsoft-defender-for-office-365-product-overview#microsoft-defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 plan 1 and plan 2</a>
appliesto:
In Microsoft 365 organizations with mailboxes in Exchange Online or standalone Exchange Online Protection (EOP) organizations without Exchange Online mailboxes, quarantine holds potentially dangerous or unwanted messages. For more information, see [Quarantined messages in EOP](quarantine-about.md).
+> [!NOTE]
+> Quarantine isn't available in Microsoft 365 operated by 21Vianet.
+ For [supported protection features](quarantine-policies.md#step-2-assign-a-quarantine-policy-to-supported-features), _quarantine policies_ define what users are allowed to do to quarantined messages based on why the message was quarantined. Default quarantine policies enforce the historical capabilities for the security feature that quarantined the message as described in the table [here](quarantine-end-user.md). Admins can create and apply custom quarantine policies that define less restrictive or more restrictive capabilities for users. For more information, see [Create quarantine policies](quarantine-policies.md#step-1-create-quarantine-policies-in-the-microsoft-365-defender-portal). Quarantine notifications aren't turned on in the default quarantine notifications named AdminOnlyAccessPolicy or DefaultFullAccessPolicy. Quarantine notifications are turned on in the following default quarantine policies:
Quarantine notifications aren't turned on in the default quarantine notification
Otherwise, to turn on quarantine notifications in quarantine policies, you need to [create and configure a new quarantine policy](quarantine-policies.md#step-1-create-quarantine-policies-in-the-microsoft-365-defender-portal).
-Admins can also use the global settings in quarantine policies to customize quarantine notifications in up to three languages, and to customize the sender and logo that's used. For instructions, see [Configure global quarantine notification settings](quarantine-policies.md#configure-global-quarantine-notification-settings-in-the-microsoft-365-defender-portal).
+Admins can also use the global settings in quarantine policies to customize quarantine notifications in the following ways:
+
+- Add translations in up to three languages.
+- Customize the sender and logo that's used in the notification.
+- Notification frequency (every four hours, daily, or weekly).
+
+For instructions, see [Configure global quarantine notification settings](quarantine-policies.md#configure-global-quarantine-notification-settings-in-the-microsoft-365-defender-portal).
For shared mailboxes, quarantine notifications are supported only for users who are granted FullAccess permission to the mailbox. For more information, see [Use the EAC to edit shared mailbox delegation](/Exchange/collaboration-exo/shared-mailboxes#use-the-eac-to-edit-shared-mailbox-delegation).
security Quarantine Shared Mailbox Messages https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/quarantine-shared-mailbox-messages.md
description: Users can learn how to view and act on quarantined messages that were sent to shared mailboxes that they have permissions to. Previously updated : 6/22/2023 Last updated : 7/24/2023 appliesto: - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/eop-about" target="_blank">Exchange Online Protection</a> - ✅ <a href="https://learn.microsoft.com/microsoft-365/security/office-365-security/microsoft-defender-for-office-365-product-overview#microsoft-defender-for-office-365-plan-1-vs-plan-2-cheat-sheet" target="_blank">Microsoft Defender for Office 365 plan 1 and plan 2</a>
Now, automapping is no longer required for users to manage quarantined messages
## Things to keep in mind
+- Quarantine isn't available in Microsoft 365 operated by 21Vianet.
+ - _Quarantine policies_ define what users are allowed to do or not do to quarantined messages based on why the message was quarantined for [supported features](quarantine-policies.md#step-2-assign-a-quarantine-policy-to-supported-features). Default quarantine policies enforce the historical capabilities for the security feature that quarantined the message as described in the table [here](quarantine-end-user.md). Admins can create and apply custom quarantine policies that define less restrictive or more restrictive capabilities for users. For more information, see [Create quarantine policies](quarantine-policies.md#step-1-create-quarantine-policies-in-the-microsoft-365-defender-portal). - The first user to act on the quarantined message decides the fate of the message for everyone who uses the shared mailbox. For example, if a shared mailbox is accessed by 10 users, and a user decides to delete the quarantine message, the message is deleted for all 10 users. Likewise, if a user decides to release the message, it's released to the shared mailbox and is accessible by all other users of the shared mailbox.
security Recommended Settings For Eop And Office365 https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/security/office-365-security/recommended-settings-for-eop-and-office365.md
Admins can create or use quarantine policies with more restrictive or less restr
|**Increase spam score** settings|Off|Off|Off|All of these settings are part of the Advanced Spam Filter (ASF). For more information, see the [ASF settings in anti-spam policies](#asf-settings-in-anti-spam-policies) section in this article.| |**Mark as spam** settings|Off|Off|Off|Most of these settings are part of ASF. For more information, see the [ASF settings in anti-spam policies](#asf-settings-in-anti-spam-policies) section in this article.| |**Contains specific languages** (_EnableLanguageBlockList_ and _LanguageBlockList_)|**Off** (`$false` and Blank)|**Off** (`$false` and Blank)|**Off** (`$false` and Blank)|We have no specific recommendation for this setting. You can block messages in specific languages based on your business needs.|
-|**From these countries** (_EnableRegionBlockList_ and _RegionBlockList_)|**Off** (`$false` and Blank)|**Off** (`$false` and Blank)|**Off** (`$false` and Blank)|We have no specific recommendation for this setting. You can block messages from specific countries based on your business needs.|
+|**From these countries** (_EnableRegionBlockList_ and _RegionBlockList_)|**Off** (`$false` and Blank)|**Off** (`$false` and Blank)|**Off** (`$false` and Blank)|We have no specific recommendation for this setting. You can block messages from specific countries/regions based on your business needs.|
|**Test mode** (_TestModeAction_)|**None**|**None**|**None**|This setting is part of ASF. For more information, see the [ASF settings in anti-spam policies](#asf-settings-in-anti-spam-policies) section in this article.| |**Actions**||||| |**Spam** detection action (_SpamAction_)|**Move message to Junk Email folder** (`MoveToJmf`)|**Move message to Junk Email folder** (`MoveToJmf`)|**Quarantine message** (`Quarantine`)||
solutions Collaborate Guests Cross Cloud https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/solutions/collaborate-guests-cross-cloud.md
To configure inbound settings for an organization
##### Configure outbound settings for the organization
-Use the outbound settings to specify which users or groups from the external organization can access resources in your organization.
+Use the outbound settings to specify which users or groups from your organization can access resources in the external organization.
To configure outbound settings for an organization
test-base Validate Monthly Security Updates https://github.com/MicrosoftDocs/microsoft-365-docs/commits/public/microsoft-365/test-base/validate-monthly-security-updates.md
+
+ Title: 'Test against Windows monthly security updates'
+description: This section shows you how to set up your own scheduled tests against Windows monthly security updates
+search.appverid: MET150
+++
+audience: Software-Vendor
+ Last updated : 07/27/2023+
+ms.localizationpriority: medium
+++
+f1.keywords: NOCSH
++
+# Test against Windows monthly security updates
+
+Test Base provides scheduled automatic tests against these fixed issues in a proactive way, so that you can get more assurance and have a chance to fix the issue before any damage happens, and your organization or your users can stay productive and protected.
+
+This section shows you how to set up your own scheduled tests against Windows monthly security updates.
+
+## Prepare your package
+
+1. **Define content:** Depending on your package type, you may select below instructions:
+- [Creating and Testing Binary Files on Test Base](testapplication.md)
+- [Test your Intune application on Test Base](testintuneapplication.md)
+- [Uploading a pre-built zip package](uploadapplication.md)
+2. **Configure test:** Both *Out-of-Box* test and *Functional* test are supported. Selecting *Out-of-Box* leverages the officially suggested test flow and automatically generate install / uninstall / launch / close test scripts for you; *Functional* tests allow you more flexibility to set up your own test flow. You may also select both.
+3. **Edit package:** Edit test scripts and test flow as you need.
+ > [!NOTE]
+ > To better mimic the update process, Test Base allows you to update from previous monthΓÇÖs OS (or your own image, see in [Custom Image documentation](https://aka.ms/tbcustomimage)). If you have selected Functional tests in the Configure test step, you may further decide when you would like the Windows update to happen in your test flow.
+
+## Sign-up for Windows monthly security updates
+
+Scheduled tests against Windows monthly updates are set in the **Test matrix** step. By selecting **Security update**, your package would be tested against incremental churns of Windows monthly security updates.
+
+Then, you may specify the Windows product(s) you want to test against from the dropdown list of ΓÇ£*OS versions to test*ΓÇ¥.
+> [!div class="mx-imgBorder"]
+> [![Screenshot of dropdown list of the 'OS versions to test'.](Media/validate-monthly-security-updates-1.png)](Media/validate-monthly-security-updates-1.png#lightbox)
+
+Your selection registers your application for automatic test runs against the B release of Windows monthly security updates of selected product(s).
+
+- For customers who have Default Access customers on Test Base, their applications are validated against the final release version of the B release security updates, starting from Patch Tuesday.
+- For early validation before the official release, you may request to become a Full Access customer on Test Base. Your applications would be validated against the pre-release versions of the B release security updates, starting up to 3-weeks before prior to Patch Tuesday. This allows more lead time to take proactive steps in resolving any issues found during testing before in advance of the final release on Patch Tuesday. (How to become a Full Access customer? Please refer to [Request to change access level \| Microsoft Docs](accesslevel.md))
+- To protect your devices from unpatched vulnerabilities, Microsoft also offers more types of update releases other than B release security updates (See in [Update release cycle for Windows clients](/windows/deployment/update/release-cycle)). If you would like to test against optional non-security preview releases, please contact us via [testbasepreview@microsoft.com](mailto:testbasepreview@microsoft.com).
+- If the OS youΓÇÖre looking for didnΓÇÖt show up in our current supported product list, feel free to [Let us know your request](https://forms.office.com/r/ZeGihXBXHk)).
+
+## Check test results for monthly security updates
+
+A test run will be executed after the package passes the validation. On a monthly basis, an automated run will be scheduled on each patch Tuesday when the latest Windows security update gets released. (For Full Access customer, your tests will be triggered more frequently when there is a new release available.)
+
+You can view the results of the test runs under the **Test summary** page by clicking the link on the package name.
+
+> [!div class="mx-imgBorder"]
+> [![Screenshot of test summary.](Media/validate-monthly-security-updates-2.png)](Media/validate-monthly-security-updates-2.png#lightbox)
+
+You may use the release number / release version / KB number to map with the update version pushed to your organization. You will not only get the detailed script execution results with test logs but also compare regressively with previousΓÇÖ monthΓÇÖs execution result to deep dive into any further performance risks. In case you might need to reproduce the failure and see in detail the execution process in video, you may click on **Re-run test**.
+
+> [!div class="mx-imgBorder"]
+> [![Screenshot of the 'Re-run test' link.](Media/validate-monthly-security-updates-3.png)](Media/validate-monthly-security-updates-3.png#lightbox)
+
+For on-demand tests against certain OS version, you may also go to Package catalog \> Manage packages \> Run on request.
+
+> [!div class="mx-imgBorder"]
+> [![Screenshot of Run on request button on Package catalog > Manage packages page.](Media/validate-monthly-security-updates-4.png)](Media/validate-monthly-security-updates-4.png#lightbox)