適用於:
- Microsoft Defender 全面偵測回應
建置於 Azure US Gov 環境中的適用於美國政府客戶的 Microsoft Defender,採用與 Azure 商業雲環境中的 Microsoft Defender 相同的基礎技術。
此方案適用於 GCC、GCC High 和 DoD 客戶,且此方案是以與商業版本相同的預防、偵測、調查和補救為依據。 不過,此方案在功能可用性方面有一些差異。
注意事項
如果你是使用 Defender for Cloud Apps、Defender for Endpoint 或 Defender for Identity in Commercial 的 GCC 客戶,你需要將這些服務轉移到他們的 GCC 版本,才能有資格使用 Microsoft Defender GCC。
授權需求
Microsoft Defender for US Government 客戶必須具備下列其中一種 Microsoft 大量授權方案:
桌面授權
| GCC | GCC High | DoD |
|---|---|---|
| Microsoft 365 GCC G5 | 適用於 GCC High 的 Microsoft 365 E5 | Microsoft 365 G5 DOD 專用 |
| Microsoft 365 G5 安全性 GCC | 適用於 GCC High 的 Microsoft 365 G5 安全性 | 適用於 DOD 的 Microsoft 365 G5 安全性 |
| Enterprise Mobility 和 Security G5 GCC | 適用於 GCC High 的 Enterprise Mobility + Security E5 | 適用於 DOD 的 Enterprise Mobility + Security E5 |
| Office 365 G5 GCC | 適用於 GCC High 的 Office 365 E5 | 適用於 DOD 的 Office 365 E5 |
| 適用於 Cloud Apps GCC 的Microsoft Defender | 適用於 GCC High 的 Microsoft Defender for Cloud Apps | 適用於 DOD 的 Microsoft Defender for Cloud Apps |
| 適用於端點的 Microsoft Defender - GCC | 適用於 GCC High 的適用於端點的 Microsoft Defender | 適用於 DOD 的適用於端點的 Microsoft Defender |
| 適用於身分識別的 Microsoft Defender - GCC | 適用於 GCC High 的 適用於身分識別的 Microsoft Defender | 適用於 DOD 的 適用於身分識別的 Microsoft Defender |
| 適用於 Office 365 的 Microsoft Defender 方案 2 GCC | 適用於 GCC High 的 適用於 Office 365 的 Microsoft Defender (方案 2) | 供 DOD 使用的適用於 Office 365 的 Microsoft Defender (方案 2) |
| Windows 10 企業版 E5 GCC | 適用於 GCC High 的 Windows 10 企業版 E5 | Windows 10 企業版 E5 適用於 DOD |
伺服器授權
| GCC | GCC High | DoD |
|---|---|---|
| 適用於端點的 Microsoft Defender 伺服器 GCC | 適用於 GCC High 的適用於端點的 Microsoft Defender 伺服器 | 適用於 DOD 的 適用於端點的 Microsoft Defender Server |
| 適用於伺服器的 Microsoft Defender | 適用於伺服器的 Microsoft Defender - 政府 | 適用於伺服器的 Microsoft Defender - 政府 |
入口網站 URL
以下是美國政府客戶的 Microsoft Defender 入口網站網址:
| 客戶類型 | 入口網站 URL |
|---|---|
| GCC | https://security.microsoft.com |
| GCC High | https://security.microsoft.us |
| DoD | https://security.apps.mil |
注意事項
如果您是 GCC 客戶,且正處於從適用於端點的 Microsoft Defender 商業版移動至 GCC,請使用 https://transition.security.microsoft.com 存取您的適用於端點的 Microsoft Defender 商業資料。
API
除了列在我們的 API 文件 中的公共 URL 之外,您必須使用下列 URI:
| 端點類型 | GCC | GCC High 與 DoD |
|---|---|---|
| 登入 | https://login.microsoftonline.com |
https://login.microsoftonline.us |
| Microsoft Defender 全面偵測回應 API | https://api-gcc.security.microsoft.us |
https://api-gov.security.microsoft.us |
與商業版功能對等
適用於美國政府客戶的 Microsoft Defender 與商業版產品並未完全對等。 雖然我們的目標是提供所有商業特色和功能給美國政府客戶,但我們想強調仍有部分功能還無法提供使用。
以下是已知的差距:
| 功能名稱 | GCC | GCC High | DoD |
|---|---|---|---|
| Microsoft 威脅專家 |
|
|
|
| 適用於 IoT 的 Microsoft Defender 企業 IoT 安全性 |
|
|
|
關於事件串流 API 表格的詳細列表,請參閱 Microsoft Defender 事件串流 API 支援的事件類型。
其他詳細資料
如需詳細資訊,請參閱個別工作負載 US Gov 頁面:
提示
想要深入了解? 請到我們的技術社群中與 Microsoft 安全性社群互動: Microsoft Defender 全面偵測回應技術社群。