L1 Support SME Microsoft Defender
The client is a multinational organization operating in a highly dynamic industry, with regional presence across multiple markets. The engagement involves managing complex account relationships, ensuring seamless program delivery, and coordinating with cross-functional teams to support ongoing business operations and strategic initiatives.
• Experience in L1 support, security operations, endpoint support, service desk coordination, or Microsoft 365 operational support.
• Working knowledge of Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, Microsoft Purview, and their respective management portals.
• Ability to perform initial investigation of MDE incidents, alerts, device timelines, endpoint health, onboarding status, and policy deployment.
• Ability to review MDCA alerts, activities, connected applications, policies, cloud-discovery information, and connector status.
• Familiarity with Purview Information Protection, sensitivity labels, DLP, Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.
• Understanding of customer-ticket handling, alert triage, log collection, evidence documentation, escalation management, and issue lifecycle tracking.
• Ability to follow approved runbooks, knowledge articles, support guides, and escalation procedures without making unauthorised production changes.
• Provide L1 operational support for Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and Microsoft Purview incidents, alerts, requests, and customer tickets.
• Perform initial ticket intake, categorisation, prioritisation, user-impact assessment, and investigation based on available evidence and approved support guidance.
• Investigate MDE alerts, incidents, device timelines, antivirus detections, device health, onboarding status, sensor health, and endpoint policy status.
• Investigate MDCA alerts, user activities, connected applications, cloud-discovery information, activity policies, anomaly detections, and connector health.
• Review Purview alerts and events related to Information Protection, sensitivity labels, Data Loss Prevention, Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.
• Collect screenshots, diagnostic packages, logs, alert details, policy status, connector status, audit records, and validation outputs required for issue investigation.
• Perform basic runbook-based troubleshooting and escalate unresolved or complex issues to L2, L3, platform SMEs, Microsoft Support, or relevant client teams.
• Maintain clear ticket notes, investigation findings, supporting evidence, customer updates, escalation details, and closure information within agreed service levels.
Ref: JN-092026-209402