Security operations
The Microsoft Managed Desktop Security Operations Center (SOC) partners with your information security staff to keep your desktop environment secure. Our Service Engineering Team receives and responds to all security alerts on managed devices with expert analysis. When needed, we drive security incident response activities. For more information about working with the SOC, review operational documentation in your admin portal.
Our Security Operations Center (SOC) Team offers 24/7/365 coverage with expertise in the current and emerging threat landscape, including common attack methods through software, network, or human adversaries.
Our SOC team provides the following services:
Service | Description |
---|---|
Quick response to detected events |
|
Drive the security incident response |
|
Advanced hunting |
|
Processes
Process | Description |
---|---|
Microsoft Managed Desktop Security Operations Center (SOC) | Microsoft Managed Desktop Security Operations is staffed by full-time Microsoft employees in partnership with Microsoft's Cyber Defense Operations Center. Our SOC uses collective signals from across our company, both internal and external, to protect your devices—even from things we haven't yet seen in Microsoft Managed Desktop. |
Microsoft Managed Desktop security solutions | Microsoft security solutions align to many cybersecurity protection standards. SOC operations are based on the National Institute of Standards and Technology Computer Security Incident Response Handling Guide (NIST 800-61 r2). The process allows for:
|
Microsoft Defender Threat Experts Service | Microsoft Managed Desktop customers are eligible to enroll in the Microsoft Defender Experts - Endpoint Attack Notification service. The SOC Team liaises with this service to understand better the complex threats affecting the Microsoft Managed Desktop environment, including:
|