# L1 Support SME - Microsoft Defender for Endpoint, MDCA & Purview

**Company:** [Unison Group](null/companies/deKpPhPMtQZga7XoPG1tSo.md)
**Location:** Kuala Lumpur, Malaysia
**Workplace:** on site
**Employment type:** Full-time
**Department:** Noresh

[Apply for this job](null/view/477a4426-8ba9-4878-8c66-2c53b8f8cc4f)

## Description

-   Provide L1 operational support for Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, and Microsoft Purview incidents, alerts, requests, and customer tickets.
-   Perform initial ticket intake, categorisation, prioritisation, user-impact assessment, and investigation based on available evidence and approved support guidance.
-   Investigate MDE alerts, incidents, device timelines, antivirus detections, device health, onboarding status, sensor health, and endpoint policy status.
-   Investigate MDCA alerts, user activities, connected applications, cloud-discovery information, activity policies, anomaly detections, and connector health.
-   Review Purview alerts and events related to Information Protection, sensitivity labels, Data Loss Prevention, Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.
-   Collect screenshots, diagnostic packages, logs, alert details, policy status, connector status, audit records, and validation outputs required for issue investigation.
-   Perform basic runbook-based troubleshooting and escalate unresolved or complex issues to L2, L3, platform SMEs, Microsoft Support, or relevant client teams.
-   Maintain clear ticket notes, investigation findings, supporting evidence, customer updates, escalation details, and closure information within agreed service levels.

## Requirements

-   Experience in L1 support, security operations, endpoint support, service desk coordination, or Microsoft 365 operational support.
-   Working knowledge of Microsoft Defender for Endpoint, Microsoft Defender for Cloud Apps, Microsoft Purview, and their respective management portals.
-   Ability to perform initial investigation of MDE incidents, alerts, device timelines, endpoint health, onboarding status, and policy deployment.
-   Ability to review MDCA alerts, activities, connected applications, policies, cloud-discovery information, and connector status.
-   Familiarity with Purview Information Protection, sensitivity labels, DLP, Endpoint DLP, Insider Risk Management, and Data Lifecycle Management.
-   Understanding of customer-ticket handling, alert triage, log collection, evidence documentation, escalation management, and issue lifecycle tracking.
-   Ability to follow approved runbooks, knowledge articles, support guides, and escalation procedures without making unauthorised production changes.
