Skip to main content Link Menu Expand (external link) Document Search Copy Copied

Task 05: Capture before/after metrics and assign owners/SLAs


Security Architecture Team

  1. In the leftmost pane, go to Exposure management > Secure score.

  2. Near the top of the page, select the History tab.

    l8p2dbkd.jpg

  3. In the upper-right corner of the table’s search box, enter phish.

  4. In the upper-left corner of the table, select Export.

    hm07sfto.jpg

  5. Define the Owners and SLAs for keeping these controls enforced.


Security Engineering and Administration

  1. In the leftmost pane, go to Email & collaboration > Explorer.

  2. In the upper-right corner of the table, select Export.

    kb034648.jpg

  3. At the bottom of the flyout pane, select Export.

  4. In the table, select one of the TEST: URL + Attachment…. emails that were quarantined.

  5. At the top of the flyout pane, select Open email entity.

    1yxp2vlz.jpg

  6. You can take screenshots of required information for the package to the CISO.

  7. Close the browser tab to return to the Defender XDR portal.


SOC Analyst

  1. In the leftmost pane, go to Investigation & response > Actions & submissions > Action center.

  2. At the top of the page, select the History tab.

  3. In the upper-left corner of the table, select Export.

    53xcpjrz.jpg

    This would be attached with your report.