Create a capability profile for the Microsoft Defender for Endpoint integration
Create a profile and select the Microsoft Defender for Endpoint capabilities that you want the profile to run.
Before you begin
Role required: sn_si.admin
About this task
Profiles are created to club or group the capabilities together,
which would help Analysts perform the investigation or remediation easily. You can
add the following capabilities to the profile:
- Get Host Details
- Get Logged On Users
- Isolate Host
- Remove Isolation
You cannot club Isolate Host and Remove Host Isolation capabilities with other
capabilities while creating a profile. Profiles for these capabilities have to be
individually created. While on the other hand, the Get Host Details and Get Logged
on Users capabilities can be clubbed together. You could create profiles
individually or by clubbing them in full or parts as per your
requirement.
Note:
After a capability is included in a profile, it cannot be
included in any other profile from the same source.
Procedure
What to do next
The next step is to configure your profile. Before you configure the settings for the profile, you may prefer to review the how profiles and configured and triggering conditions. For more information, see Trigger conditions in a configuration item.