Skip to content

docs(connectors): document Microsoft Defender device-group filtering - #15991

Merged
Maffooch merged 1 commit into
bugfixfrom
claude/sc-15105-defender-device-groups-docs
Sep 17, 2026
Merged

Maffooch merged 1 commit into
bugfixfrom
claude/sc-15105-defender-device-groups-docs

Conversation

@Maffooch

Copy link
Copy Markdown
Contributor

Description

Documentation-only update to the Microsoft Defender connector tool reference.

  • Clarifies that a Defender "device" is one individual onboarded machine (one finding per device / software version / CVE).
  • Documents importing in phases by device group: the new Device Groups allowlist on the connector, and the alternative of mapping only the discovered device-group Records you want.
  • Documents setting a minimum severity per device group via a per-record severity override.

No code changes.

Clarify that a Defender "device" is one individual machine (one finding
per device / software version / CVE), document the new Device Groups
allowlist for importing in phases (plus the record-mapping alternative),
and explain setting a minimum severity per device group via a per-record
severity override.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@Maffooch Maffooch added this to the 3.3.200 milestone Sep 16, 2026
@github-actions github-actions Bot added the docs label Sep 16, 2026
@Maffooch
Maffooch enabled auto-merge September 16, 2026 23:35
@Maffooch
Maffooch added this pull request to the merge queue Sep 17, 2026
Merged via the queue into bugfix with commit 80bdb56 Sep 17, 2026
31 checks passed
@Maffooch
Maffooch deleted the claude/sc-15105-defender-device-groups-docs branch September 17, 2026 04:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants