diff --git a/defender-xdr/TOC.yml b/defender-xdr/TOC.yml
index eebdb5da23..1f31a88eb8 100644
--- a/defender-xdr/TOC.yml
+++ b/defender-xdr/TOC.yml
@@ -338,6 +338,8 @@
href: access-den-graph-api.md
- name: Ask Defender Experts
href: experts-on-demand.md
+ - name: Frequently asked questions
+ href: faq-defender-experts-hunting.md
- name: Understand Defender Experts for Hunting reports
href: defender-experts-report.md
- name: Collaborate with Microsoft Defender Experts for XDR
diff --git a/defender-xdr/before-you-begin-defender-experts.md b/defender-xdr/before-you-begin-defender-experts.md
index e93e6b72ca..59283ba502 100644
--- a/defender-xdr/before-you-begin-defender-experts.md
+++ b/defender-xdr/before-you-begin-defender-experts.md
@@ -1,7 +1,7 @@
---
title: Key infrastructure requirements before enrolling in the Microsoft Defender Experts for Hunting service
ms.reviewer:
-description: This section outlines the key infrastructure requirements you must meet and important information on data access and compliance
+description: This section outlines the key infrastructure requirements you must meet and important information on data access and compliance.
ms.service: defender-experts-for-hunting
ms.author: vpattnaik
author: vpattnai
@@ -18,7 +18,7 @@ ms.custom:
- cx-ti
- cx-ean
search.appverid: met150
-ms.date: 08/14/2024
+ms.date: 01/09/2025
---
# Before you begin using Defender Experts for Hunting
@@ -28,19 +28,26 @@ ms.date: 08/14/2024
**Applies to:**
- [Microsoft Defender XDR](microsoft-365-defender.md)
+- [Microsoft Defender Experts for XDR](dex-xdr-overview.md)
-This document outlines the key infrastructure requirements you must meet and important information on data access and compliance you must know before purchasing the Microsoft Defender Experts for Hunting service. Microsoft understands that customers who use our managed services entrust us with their most valued asset, their data.
+[Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md) is a managed service that provides hunting capabilities for novel emerging threats that aren't yet well known in the industry. The analysts for the hunting service review trends in the threat actor evolution based on world-renowned Microsoft Threat Intelligence and Research. They then apply the insights they gather to hunt for emerging attack vectors within the customer ecosystem.
+
+With deep product expertise powered by threat intelligence, we're uniquely positioned to help you:
-## Check if your environment meets licensing and access prerequisites
+1. Focus on novel threat actor evolution in the context of your ecosystem.
+1. Get detailed, step-by-step, and actionable guidance from our experts so you can respond to these emerging threats.
+1. [Seek assistance](#ask-defender-experts) from Defender Experts.
-Microsoft Defender Experts for Hunting is a separate service from your existing Defender products. Before enrolling in this service, make sure that you have the necessary license and access.
+This document outlines the key infrastructure requirements you must meet and important information on data access and compliance you must know before purchasing the Microsoft Defender Experts for Hunting service. Microsoft understands that customers who use our managed services entrust us with their most valued asset, their data.
-### Eligibility and licensing
+## Eligibility and licensing
-To enable us to get started with this threat hunting service, we require the following licensing prerequisites:
+Defender Experts for Hunting is a separate service from your existing Microsoft Defender products. Before enrolling in this service, make sure that you have the necessary license and access.
+
+We require the following licensing prerequisites to enable us to get started with this threat hunting service:
- Microsoft Defender for Endpoint P2 must be licensed and enabled on eligible devices
-- Microsoft Defender Antivirus must be licensed and enabled in active mode on devices onboarded to Defender for Endpoint (required for endpoint detection and response capabilities)
+- Microsoft Defender Antivirus must be licensed and enabled in active mode on devices onboarded to Defender for Endpoint (required for endpoint detection)
The following products are also eligible to get Defender Experts for Hunting coverage, and you must have their appropriate product licenses to get started with the service:
@@ -51,23 +58,31 @@ The following products are also eligible to get Defender Experts for Hunting cov
The following product is **not** covered by this service:
- Microsoft Defender for IoT
+- Other Microsoft services not mentioned in the previous lists
+
+### Defender Experts for Hunting coverage
-### Server coverage
+Defender Experts for Hunting relies on event signals from Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Identity. It also relies on proprietary Microsoft Threat Intelligence sources.
-Defender Experts for Hunting also covers servers—whether on premises or on a hyperscale cloud service provider—that have Defender for Endpoint deployed on them with a Microsoft Defender for Endpoint for Servers license. For Defender Experts coverage, a server is considered as a user account for billing. The service doesn't cover Microsoft Defender for Cloud.
-[Learn more about specific hardware and software requirements](/defender-endpoint/minimum-requirements)
+This service also covers servers—whether on premises or on a hyperscale cloud service provider—that have Defender for Endpoint deployed on them with a Microsoft Defender for Endpoint for Servers license.
+
+Any detection that's not from Microsoft Defender products (for example, detections from other security vendors) isn't within the scope of Defender Experts for Hunting.
### Ask Defender Experts
-Defender Experts for Hunting customers are assigned 10 **Ask Defender Experts** credits, which you can use to submit questions, at the start of each calendar quarter. Unused credits from the current quarter roll up to the next one. You can use up to 20 credits only per quarter. All unused credits expire by the end of the calendar year or at the end of your subscription term, whichever comes first.
+[Ask Defender Experts](experts-on-demand.md) is intended to provide a better understanding of complex threats affecting your organization. It focuses on products included in Microsoft Defender XDR (Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, and Defender for Identity). [See sample questions you can ask Defender Experts](experts-on-demand.md#sample-questions-you-can-ask-from-defender-experts).
+
+Defender Experts for Hunting customers are assigned 10 Ask Defender Experts credits, which you can use to submit questions, at the start of each calendar quarter. Unused credits from the current quarter roll up to the next one. You can use up to 20 credits only per quarter. All unused credits expire by the end of the calendar year or at the end of your subscription term, whichever comes first.
[Learn more about Microsoft's commercial licensing terms](https://www.microsoft.com/licensing/terms/productoffering/Microsoft365/MCA)
-### Access requirements
+## Access requirements
-Anyone from your organization can complete the customer interest form for Microsoft Defender Experts for Hunting service, however, you need to work with your Commercial Executive to transact the SKU. You might need certain roles and permissions to fully access the service capabilities. Refer to [Custom roles in role-based access control for Microsoft Defender XDR](custom-roles.md) for details.
+Anyone from your organization can [apply for the Defender Experts for Hunting service](#apply-for-microsoft-defender-experts-for-hunting-service). However, you need to work with your Commercial Executive to transact the SKU.
-## Understand the service's availability and data access requirements
+You might need certain roles and permissions to fully access the service capabilities. Refer to [Custom roles in role-based access control for Microsoft Defender XDR](custom-roles.md) for details.
+
+## Service availability and data protection
Defender Experts for Hunting is a managed threat hunting service that proactively hunts for threats across endpoints, email, identity, and cloud apps. To carry out hunting on your behalf, Microsoft experts need access to your Microsoft Defender XDR advanced hunting data. Enrolling in this service means you're granting permission to Microsoft experts to access the said data.
@@ -77,7 +92,7 @@ The following sections enumerate additional information about the service's data
All data used for hunting from existing Defender services will continue to reside in the customer's original Microsoft Defender XDR service storage location. [Learn more](/microsoft-365/enterprise/o365-data-locations)
-Defender Experts for Hunting operational data, such as case tickets and analyst notes, are generated and stored in a Microsoft data center in the US region for the length of the service, irrespective of the Microsoft Defender XDR service storage location. Data generated for the reporting dashboard is stored in customer's Microsoft Defender XDR service storage location. Reporting data and operational data will be retained for a grace period of no more than 90 days after a customer's subscription expires. If the customer terminates their subscription, data will be deleted within 30 days.
+Defender Experts for Hunting operational data, such as case tickets and analyst notes, are generated and stored in a Microsoft data center in the US region for US customers and in the European Union for EU customers, for the length of the service, irrespective of the Microsoft Defender XDR service storage location. Data generated for the reporting dashboard is stored in customer's Microsoft Defender XDR service storage location. Reporting data and operational data will be retained for a grace period of no more than 90 days after a customer's subscription expires. If the customer terminates their subscription, data will be deleted within 30 days.
Microsoft experts hunt over [advanced hunting logs](advanced-hunting-schema-tables.md) in Microsoft Defender XDR advanced hunting tables. The data in these tables depend on the set of Defender services the customer is enabled for (for example, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, and Microsoft Entra ID). Experts also use a large set of internal threat intelligence data to inform their hunting and automation.
@@ -93,15 +108,16 @@ This service is available worldwide for customers in our commercial public cloud
This service is currently delivered in English language only.
-## Apply for Microsoft Defender Experts for Hunting service
+## Apply for Microsoft Defender Experts for Hunting service
-If you haven't done so yet, you can complete the customer interest form for Defender Experts for Hunting:
+You can apply for the Defender Experts for Hunting by performing the following steps:
-1. Complete the [customer interest form](https://aka.ms/DEX4HuntingCustomerInterestForm). Anyone from your company can apply, but if you're accepted, you need to work with your Commercial Executive to transact the SKU.
-2. Enter your name, company name, and company email ID.
-3. Select **Submit**. Someone from our sales team will reach out within five business days.
+1. Complete the [customer interest form](https://aka.ms/DEX4HuntingCustomerInterestForm).
+2. Enter your name, company name, and company email ID.
+3. Select **Submit**. Someone from our sales team will reach out within five business days.
### Next step
- [Start using Defender Experts for Hunting](onboarding-defender-experts-for-hunting.md)
+
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]
diff --git a/defender-xdr/faq-defender-experts-hunting.md b/defender-xdr/faq-defender-experts-hunting.md
new file mode 100644
index 0000000000..5b5104d7d0
--- /dev/null
+++ b/defender-xdr/faq-defender-experts-hunting.md
@@ -0,0 +1,55 @@
+---
+title: FAQs related to Microsoft Defender Experts for Hunting service
+ms.reviewer:
+description: Frequently asked questions related to the Microsoft Defender Experts for hunting service
+ms.service: defender-experts-for-hunting
+ms.author: vpattnaik
+author: vpattnai
+ms.localizationpriority: medium
+manager: dansimp
+audience: ITPro
+ms.collection:
+ - m365-security
+ - tier1
+ - essentials-get-started
+ms.topic: conceptual
+ms.custom:
+- cx-ti
+- cx-ean
+search.appverid: met150
+ms.date: 01/12/2025
+---
+
+# General information on Microsoft Defender Experts for Hunting service
+
+**Applies to:**
+
+- [Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md)
+- [Microsoft Defender XDR](microsoft-365-defender.md)
+
+The following section lists down questions your security operations center (SOC) team might have about the Microsoft Defender Experts for Hunting service:
+
+| Questions | Answers |
+|---------|---------|
+| **What is the Microsoft Defender Experts for Hunting service?** | [Microsoft Defender Experts for Hunting](defender-experts-for-hunting.md) provides a proactive threat hunting service to identify threats in advance.
[Microsoft Defender Experts for XDR](dex-xdr-overview.md) also includes the proactive threat hunting offered by Defender Experts for Hunting.|
+|**Does Defender Experts for Hunting use or require Microsoft Sentinel or a security information and event management (SIEM) platform?**| No. This service doesn't use any non-Microsoft data ingested either through Microsoft Sentinel or any other SIEM platform.|
+|**What products does Defender Experts for Hunting operate on?**| Defender Experts for Hunting relies on event signals from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, Microsoft Entra ID protection, and Microsoft Defender for Identity. It also relies on proprietary Microsoft Threat Intelligence sources. Any event definitions not authored by Microsoft Defender products, such as third-party events or detections, fall outside the scope of this service.|
+|**What is the role of Defender Experts for Hunting in the context of a purple team (red team and blue team coordinated work stream) exercise?**| Defender Experts for Hunting is part of the blue team in a purple team exercise. It complements your internal hunting team by enhancing their capabilities rather than replacing them.|
+|**What actions can your experts take during a hunting investigation that results in a Defender Experts Notification?**| During threat hunting investigations, our analysts refrain from taking direct actions on customer assets. Instead, they provide detailed information, including a threat summary and hunting queries that show the timeline of events for the identified attack, and remediation action recommendations. Defender Experts Notifications provide guidance on how you can review and address the novel threat.|
+|**What types of incidents can your experts investigate?**| The Defender Experts for Hunting service specializes in addressing the evolving threat landscape, bridging industry knowledge gaps, and recommending the most effective ways to identify these threats. Our experts don't prioritize well-established threats that Microsoft Defender products address adequately. However, when a well-known tactic is employed to generate a novel attack, our experts identify both the novel and existing attack tactics diligently. [Learn more about novel attacks in our in the Microsoft Security Experts Blog](https://techcommunity.microsoft.com/tag/Defender%20Experts%20for%20Hunting?nodeId=board%3AMicrosoftSecurityExperts)|
+|**Can your experts help me improve my security posture?**| The scope of the posture change recommendation is limited to the scope of a Defender Experts Notification and is limited to preventing the attack identified in the context of the notification.|
+|**Can Defender Experts for Hunting help with an active compromise or vulnerability?**| No, Defender Experts currently don't provide incident response services.|
+|**How can my organization participate in the Defender Experts for Hunting service?**| Reach out to your Microsoft representative to express your interest in Defender Experts for Hunting.|
+|**Does Defender Experts for Hunting cover cloud servers that have Microsoft Defender for Endpoint deployed on them?**| Defender Experts for Hunting covers servers—whether on premises or on a hyperscale cloud service provider—that have Microsoft Defender for Endpoint deployed on them with a Microsoft Defender for Endpoint for Servers license. For Defender Experts coverage, a server is considered as a user seat for billing. The service doesn't cover Microsoft Defender for Cloud. [Learn more about specific hardware and software requirements](/defender-endpoint/minimum-requirements)|
+|**Once I see a Defender Experts Notification, if I have questions, how do I communicate with the Defender Experts for Hunting team?**| The **Ask Defender Experts** option in the Microsoft Defender portal delivers swift and accurate responses to all your threat-hunting questions. However, this service is limited to questions related specifically to Defender Experts for Hunting. [Learn more about Ask Defender Experts](experts-on-demand.md)|
+|**What kinds of inquiries could I submit in Ask Defender Experts?**| Ask Defender Experts is intended to provide a better understanding of complex threats affecting your organization. It focuses on products included in Microsoft Defender XDR (Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, and Defender for Identity). It doesn't answer inquiries related to custom detections in the above products (that is, non-Defender XDR and third-party cybersecurity products), bugs in your product experience in the Defender portal, and those related to security incident response services. [See some sample questions you can ask our Defender Experts](experts-on-demand.md#sample-questions-you-can-ask-from-defender-experts)|
+|**What certifications does the Defender Experts for Hunting service have?**| Defender Experts for Hunting is certified for [HIPAA and ISO](/compliance/regulatory/offering-hipaa-hitech).|
+|**How is customer data protected?**| For more information about Microsoft's commitment in valuing and protecting your data, see [Data collection, usage, and retention](before-you-begin-defender-experts.md#data-collection-usage-and-retention). You can also visit the [Trust Center](https://www.microsoft.com/en-us/trust-center/product-overview) then scroll down to **Additional products and services** > **Managed Security Services** > [**Microsoft Defender Experts**](https://aka.ms/trustcenter-defenderexperts).|
+|**Does the hunting service offer real-time threat remediation with boots on ground?**| No, the hunting service doesn't cover real-time threat remediation.
Despite this, Microsoft provides professional on-site service through our [Microsoft Incident Response team](https://www.microsoft.com/en-us/security/business/microsoft-incident-response?msockid=2c408e0b54cc68301f9a9b55554869f3). This service requires a separate contract. We prioritize customer needs and have a swift turnaround time. Contact your Customer Service Account Manager for further assistance.|
+|**Is there a graph API that can fetch Defender Experts Notifications content?**| Yes. For more information, see [Access incident notifications using Graph API](access-den-graph-api.md).|
+
+### See also
+- [Before you begin using Defender Experts for Hunting](before-you-begin-defender-experts.md)
+- [Start using Defender Experts for Hunting](onboarding-defender-experts-for-hunting.md)
+
+[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]
\ No newline at end of file