Updated: July 24, 2020 (May 7, 2019)
SidebarEngaging with Microsoft Threat Experts
Microsoft Threat Experts allows an organization to engage with security domain experts within Microsoft regarding a specific Microsoft Defender ATP system or security event.
From within the Azure portal, an organization’s own employees can escalate an issue into a question using the “Ask a threat expert” menu option.
After enough information has been provided in the request and a support ticket has formally been opened, it can be submitted.
In order to elicit a rapid and accurate response, these questions should be as specific and direct as possible rather than open-ended.
Microsoft has provided sample questions that it believes to be suitable for Threat Experts scenarios, including the following:
“Can you please help answer why we see “Unknown process observed?” This is seen quite frequently on many machines and we would appreciate input on whether this is related to malicious activity.”
“This morning, we detected a phishing email that delivered a malicious Word document to a user. This caused a series of suspicious events which triggered multiple Windows Defender alerts for [malware name] malware. Do you have any information on this malware? If yes, can you please send me a link?”
Atlas Members have full access
Get access to this and thousands of other unbiased analyses, roadmaps, decision kits, infographics, reference guides, and more, all included with membership. Comprehensive access to the most in-depth and unbiased expertise for Microsoft enterprise decision-making is waiting.
Membership OptionsAlready have an account? Login Now