Updated: July 24, 2020 (May 7, 2019)

  Sidebar

Engaging with Microsoft Threat Experts

My Atlas / Sidebar

274 wordsTime to read: 2 min
Wes Miller by
Wes Miller

Wes Miller analyzes and writes about Microsoft’s security, identity management, and systems management technologies. Before joining Directions on Microsoft, Wes... more

Microsoft Threat Experts allows an organization to engage with security domain experts within Microsoft regarding a specific Microsoft Defender ATP system or security event.

From within the Azure portal, an organization’s own employees can escalate an issue into a question using the “Ask a threat expert” menu option.

After enough information has been provided in the request and a support ticket has formally been opened, it can be submitted.

In order to elicit a rapid and accurate response, these questions should be as specific and direct as possible rather than open-ended.

Microsoft has provided sample questions that it believes to be suitable for Threat Experts scenarios, including the following:

“Can you please help answer why we see “Unknown process observed?” This is seen quite frequently on many machines and we would appreciate input on whether this is related to malicious activity.”

“This morning, we detected a phishing email that delivered a malicious Word document to a user. This caused a series of suspicious events which triggered multiple Windows Defender alerts for [malware name] malware. Do you have any information on this malware? If yes, can you please send me a link?”

Atlas Members have full access

Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.

Membership Options

Already have an account? Login Now