STIGQter STIGQter: STIG Summary: Microsoft Defender for Endpoint Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 05 Jan 2026:

Microsoft Defender for Endpoint (MDE) must be connected to a central log server.

DISA Rule

SV-272889r1119412_rule

Vulnerability Number

V-272889

Group Title

SRG-APP-000515

Rule Version

MSDE-00-000450

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the MDE portal select Settings >> Microsoft Sentinel.
2. Under Workspaces connect a Sentinel Workspace.

Check Contents

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Microsoft Sentinel.
2. Under "Workspaces", verify a Sentinel Workspace has been assigned.

If a Sentinel Workspace has not been assigned, this is a finding.

If another documented and authorizing official (AO)-approved SIEM/Central Log Server is in use, this is not a finding.

Vulnerability Number

V-272889

Documentable

False

Rule Version

MSDE-00-000450

Severity Override Guidance

Access the MDE portal as a user with at least an MDE Administrator or equivalent role:

1. In the navigation pane, select Settings >> Microsoft Sentinel.
2. Under "Workspaces", verify a Sentinel Workspace has been assigned.

If a Sentinel Workspace has not been assigned, this is a finding.

If another documented and authorizing official (AO)-approved SIEM/Central Log Server is in use, this is not a finding.

Check Content Reference

M

Target Key

5693