
According to the technical post, Microsoft began rolling out case management, workbooks and natural-language playbook generation to eligible customers’ Defender portals on Sept. 23, with no additional configuration required.
The included data covers Defender for Endpoint, Office 365, Identity, Cloud Apps and Cloud, plus Microsoft Entra ID Protection logs and Azure and Office 365 activity logs. Retention is 30 days during the preview, rising to 90 days on Nov. 15, the post added.
Everything else costs
Anything beyond that requires an ISOC workspace, which needs an Azure subscription, according to Microsoft’s product documentation. The workspace unlocks more than 500 data connectors, user and entity behavior analytics (UEBA), CI/CD repositories and threat intelligence.
This story originally appeared on Computerworld
