L1 Support SME Microsoft Defender


Copy Linklink

The client is a multinational organization operating in a highly dynamic industry, with regional presence across multiple markets. The engagement involves managing complex account relationships, ensuring seamless program delivery, and coordinating with cross-functional teams to support ongoing business operations and strategic initiatives.

• Experience in L1 support, security operations, endpoint support, service desk coordination, or Microsoft 365 operational support.

• Working knowledge of Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, Microsoft Purview, and their respective management portals.

• Ability to perform initial investigation of MDE incidents, alerts, device timelines, endpoint health, onboarding status, and policy deployment.

• Ability to review MDCA alerts, activities, connected applications, policies, cloud-discovery information, and connector status.

• Familiarity with Purview Information Protection, sensitivity labels, DLP, Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.

• Understanding of customer-ticket handling, alert triage, log collection, evidence documentation, escalation management, and issue lifecycle tracking.

• Ability to follow approved runbooks, knowledge articles, support guides, and escalation procedures without making unauthorised production changes.

• Provide L1 operational support for Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and Microsoft Purview incidents, alerts, requests, and customer tickets.

• Perform initial ticket intake, categorisation, prioritisation, user-impact assessment, and investigation based on available evidence and approved support guidance.

• Investigate MDE alerts, incidents, device timelines, antivirus detections, device health, onboarding status, sensor health, and endpoint policy status.

• Investigate MDCA alerts, user activities, connected applications, cloud-discovery information, activity policies, anomaly detections, and connector health.

• Review Purview alerts and events related to Information Protection, sensitivity labels, Data Loss Prevention, Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.

• Collect screenshots, diagnostic packages, logs, alert details, policy status, connector status, audit records, and validation outputs required for issue investigation.

• Perform basic runbook-based troubleshooting and escalate unresolved or complex issues to L2, L3, platform SMEs, Microsoft Support, or relevant client teams.

• Maintain clear ticket notes, investigation findings, supporting evidence, customer updates, escalation details, and closure information within agreed service levels.


Ref: JN-092026-209402