[Index]

Model: device/mssecurity/Machine

Incidents

Full HTML Help

MICROSOFT

Overview

Automate provides support for Microsoft Defender for Endpoint, that addresses user devices (laptops, phones, tablets, PCs) and network devices (access points, routers, firewalls).

Note

Dashboards

The administrator interface provides dashboards for the view and management of data:

Dashboards:
Security Management - Defender for Endpoint Overview Security Management - Defender for Endpoint Actions
Dashboards:

To customize your dashboards:

Incident and Alert Actions

Incidents

Related device model: device/msgraphsecurity/Incident

Automate provides an Incidents list view showing such headings as the incident Status and Severity at a hierarchy (Located At), and allows for the examination of the Details of an incident, including for example the Incident Web URL at security.microsoft.com.

Alerts

Related device model: device/msgraphsecurity/Alerts

Automate provides an Alerts list view showing such headings as the incident Title, Status, Severity, Description and Device at a hierarchy (Located At), and allows for the Details of an instance to be viewed and managed.

Managing an alert

Administrators can manage the following alert properties:

Device Actions

View Devices

Related device model: device/mssecurity/Machine

Automate provides an View Devices list view showing such headings as the Last IP Address, Health Status, Exposure Level and Device at a hierarchy (Located At), and allows for the examination of the Details of a device.

Bulk Actions

Automate provides an interface to carry out bulk actions on devices. For Target Defender Devices, the Available and Selected transfer boxes are available to select devices accessible from a hierarchy to carry out operations in bulk:

Machine Action

The relation/MachineAction model is available to allow for the execution of Cancel action. (This action sends a request to device/mssecurity/MachineActionCancel.)

Related Topics

Model Details: device/mssecurity/Machine

Title Description Details
Machine ID machine identity
  • Field Name: id
  • Type: String
Computer DNS Name machine fully qualified name
  • Field Name: computerDnsName
  • Type: String
First Seen First date and time where the machine was observed by Microsoft Defender for Endpoint
  • Field Name: firstSeen
  • Type: String
  • Format: date-time
Last Seen Time and date of the last received full device report. A device typically sends a full report every 24 hours
  • Field Name: lastSeen
  • Type: String
  • Format: date-time
OS Platform Operating system platform
  • Field Name: osPlatform
  • Type: String
OS Version Operating system Version
  • Field Name: version
  • Type: String
OS Build Operating system build number
  • Field Name: osBuild
  • Type: ["Integer", "Null"]
Last IP Address Last IP on local NIC on the machine
  • Field Name: lastIpAddress
  • Type: String
Last External IP Address Last IP through which the machine accessed the internet
  • Field Name: lastExternalIpAddress
  • Type: String
Health Status machine health status
  • Field Name: healthStatus
  • Type: String
RBAC Group Name Machine group Name
  • Field Name: rbacGroupName
  • Type: String
RBAC Group ID Machine group ID
  • Field Name: rbacGroupId
  • Type: String
Risk Score Risk score as evaluated by Microsoft Defender for Endpoint
  • Field Name: riskScore
  • Type: ["String", "Null"]
AAD Device ID Microsoft Entra Device ID (when machine is Microsoft Entra joined)
  • Field Name: aadDeviceId
  • Type: ["String", "Null"]
Machine Tags Set of machine tags
  • Field Name: machineTags.[n]
  • Type: Array
Exposure Level Exposure level as evaluated by Microsoft Defender for Endpoint
  • Field Name: exposureLevel
  • Type: ["String", "Null"]
Device Value The value of the device
  • Field Name: deviceValue
  • Type: ["String", "Null"]
Onboarding Status Status of machine onboarding
  • Field Name: onboardingStatus
  • Type: String
OS Architecture Operating system architecture
  • Field Name: osArchitecture
  • Type: String
Managed By
  • Field Name: managedBy
  • Type: String
IP Addresses Set of IpAddress objects
  • Field Name: ipAddresses.[n]
  • Type: Array
IP Address
  • Field Name: ipAddresses.[n].ipAddress
  • Type: String
MAC Address
  • Field Name: ipAddresses.[n].macAddress
  • Type: ["String", "Null"]
Type
  • Field Name: ipAddresses.[n].type
  • Type: String
Operational Status
  • Field Name: ipAddresses.[n].operationalStatus
  • Type: String
VM Metadata
  • Field Name: vmMetadata
  • Type: Object
VM ID
  • Field Name: vmMetadata.vmId
  • Type: String
Cloud Provider
  • Field Name: vmMetadata.cloudProvider
  • Type: String
Resource ID
  • Field Name: vmMetadata.resourceId
  • Type: String
Subscription ID
  • Field Name: vmMetadata.subscriptionId
  • Type: String