I start using ENS Adaptive threat protection (ATP) 3 months ago. I like to make ATP more productive and useful by tapping on Threat Intelligence Exchange server and active response server. I have less than 200 users and look at the materials I read are applicable to big installation of 1000 or more.
What is best way to enhance the way ATP work? Appreciate any help. Thank you in advance.