1,194 questions with Microsoft Defender for Cloud-related tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

Is there a way to enable Defender for Servers in Azure by resource group within a subscription?

Working on deploying Defender for Cloud and wanting to enable Defender for Servers in Azure on a subscription but don't want all servers within the subscription to have it enabled just yet. Would prefer to target servers in specific resource groups…

Azure
Azure
A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.
944 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-26T14:45:09.53+00:00
Adrienne Gotwalt 0 Reputation points
accepted 2024-04-26T15:31:13.1966667+00:00
Adrienne Gotwalt 0 Reputation points
1 answer

Time Difference between Intune & defender console

Hello Expert, My query is that I checked and found that the time status on the device in Intune is showing something different, and in Defender it's showing something else. Why is that? Can you please suggest.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,336 questions
asked 2024-04-22T19:44:29.1266667+00:00
TechUST 416 Reputation points
commented 2024-04-26T06:21:06.58+00:00
ZhoumingDuan-MSFT 7,750 Reputation points Microsoft Vendor
0 answers

How To Remediate Azure Secure Score Recommendations

Hello, I have this is security recommendation showing in Defender for Cloud, "Azure Machine Learning Computes should have local authentication methods disabled", the remediation steps given is to toggle "Enable SSH access" off. I…

Azure Machine Learning
Azure Machine Learning
An Azure machine learning service for building and deploying models.
2,563 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-03-01T02:36:26.8366667+00:00
Andy Lau Pik Hui 60 Reputation points
commented 2024-04-26T01:30:20.87+00:00
Andy Lau Pik Hui 60 Reputation points
1 answer

Error when using Advanced Hunting

Hello, I have a customer that is getting the error below when using advanced hunting and is unable to search 'EmailEvents' and would like some insight on it?   Issue: When using the Advanced Hunting option, the object 'EmailEvents' returns: "Syntax…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-23T20:11:31.1466667+00:00
DG001 346 Reputation points Microsoft Employee
commented 2024-04-26T00:10:16.78+00:00
DG001 346 Reputation points Microsoft Employee
1 answer

Defender I use GPO Can Switch Config policy On Defender Mange by MDE device configuration management ?

Now plan deploy MDE my PC joins local AD which makes it difficult to manage policy through GPO. Is this possible? If I want to use Switch Gpo policy through Device configuration management MDE?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,787 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
11 questions
asked 2024-04-25T09:12:13.4166667+00:00
TECHIT SRIWICHAI 160 Reputation points
answered 2024-04-25T23:04:07.87+00:00
TECHIT SRIWICHAI 160 Reputation points
1 answer

Choosing between Defender for Endpoint and Defender for Server for servers with no internet connectivity

We are planning to migrate from Symantec® Endpoint Security to Microsoft, specifically looking for EDR and XDR features for our On Prem servers that have no connectivity to the internet. Should we use Defender for Endpoint or Defender for Servers? We are…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-23T07:49:38.81+00:00
milo last 0 Reputation points
answered 2024-04-25T20:12:46.3666667+00:00
James Hamil 21,696 Reputation points Microsoft Employee
5 answers

Defender 365 admin console - Disabled Connected to a custom indicator & Connected to a unsanctionned blocked app rules

I want to know how I can disable these two following alerts : Disabled Connected to a custom indicator Connected to an unsanctioned blocked app I didn't find these alerts on the Alerts Policy of XDR/EPP or Cloud apps. Since all the changed that…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
103 questions
asked 2024-03-21T14:28:41.46+00:00
Étienne Fiset 45 Reputation points
answered 2024-04-25T18:15:54.0566667+00:00
Étienne Fiset 45 Reputation points
0 answers

Logic App - Internal Server Error for HTTP request

Hello, I'm working on a logic app integration with Microsoft Defender for Vulnerability. I use HTTP request to authenticate with Microsoft Defender API. …

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,787 questions
Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,845 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-22T10:52:35.3133333+00:00
Hrabec Pavel 0 Reputation points
commented 2024-04-25T12:36:53.7633333+00:00
Hrabec Pavel 0 Reputation points
0 answers

Run a phishing simulation

No matter what type of simulation I am doing. They are not working.

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,787 questions
Not Monitored
Not Monitored
Tag not monitored by Microsoft.
36,001 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-15T18:48:10.51+00:00
Dennis Machado (Tek Experts) 0 Reputation points Microsoft Vendor
commented 2024-04-25T09:54:24.62+00:00
Pauline Mbabu 10 Reputation points Microsoft Employee
2 answers

Defender for Business onboarding endpoint

When running Microsoft Defender Endpoint onboarding for manual device onboarding, the error occurs: Error ID: 15, Error Level: 1. I have already carried out all the procedures in this answer:…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-22T23:49:47.3833333+00:00
answered 2024-04-25T06:52:45.3166667+00:00
Givary-MSFT 27,966 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Defender P2 Qualys Deprecation -> switch to MDE for MDVM

Qualys is being deprecated to be used together with Cloud Defender for Servers Plan 2. In the documentation I read that MDVM is part of MDE, either plan 1 or plan 2. Plan 1 has basic vulnerability scanning and p2 supplies addons to that basic…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-18T05:07:22.7233333+00:00
BartDecker-8243 175 Reputation points
answered 2024-04-25T06:17:07.11+00:00
BartDecker-8243 175 Reputation points
1 answer One of the answers was accepted by the question author.

Custom detection in MDE

I am trying to create Custom Detection in Microsoft Security Center where my query has multiple Join and summarize statements. Whenever I am running query its providing results but after saving in Custom Detection form and under its results section its…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,787 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,754 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-23T12:01:01.1433333+00:00
Ankush Kumar 35 Reputation points
accepted 2024-04-24T07:49:17.5166667+00:00
Ankush Kumar 35 Reputation points
2 answers

Snapshot not working for continues export of Defender for Cloud

Hi, I have setup a continues export for Defender for Cloud as described in the following documentation to export all possible data to a Log Analytics workspace using streaming updates and snapshot.…

Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
2,845 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-04T12:50:53.2666667+00:00
Bram 0 Reputation points
answered 2024-04-23T09:40:13.43+00:00
Bram 0 Reputation points
3 answers

Support for Microsoft Defender on on premise Active Directory domain controllers

hi - can you tell us if Microsoft supports or partially supports or does not support Microsoft Defender for Servers/Cloud going onto on premise domain controllers? If there are any special caveants please provide links

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-09T00:47:46.03+00:00
Tom Minchin 0 Reputation points
answered 2024-04-22T15:11:15.3733333+00:00
obi-wan 0 Reputation points
1 answer

Confused with Module 3 - Policy Management at https://github.com/Azure/Microsoft-Defender-for-Cloud/blob/main/Onboarding/Modules/3-Policy-Management.md#step-3---assign-and-customize-the-mdc-default-policy

Hi, I am reading the onboarding process and reached module 3 at https://github.com/Azure/Microsoft-Defender-for-Cloud/blob/main/Onboarding/Modules/3-Policy-Management.md#step-3---assign-and-customize-the-mdc-default-policy I have already activated all…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
793 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-03-29T17:09:12.1766667+00:00
Salam ELIAS 112 Reputation points
commented 2024-04-22T13:07:12.7933333+00:00
Monalla-MSFT 11,636 Reputation points
2 answers

Applying azure PCI DSS4 regulatory complaince policy for passwords

Hi, I am trying to assign PCI DSS4 Defender for cloud regulatory compliance policy for passwords - Audit Windows machines that allow re-use of the passwords after the specified number of unique passwords- where count is 24 Audit Windows machines that…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
793 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-16T20:23:01.5533333+00:00
Ishan Saxena 20 Reputation points
answered 2024-04-18T20:45:02.7166667+00:00
Marcin Policht 10,525 Reputation points MVP
7 answers

OpenSSL vulnerabilities showing in Defender Dashboard

We have multiple devices showing up with OpenSSL vulnerabilities. It is detecting two dll files that it is flagging. Which they are libssl-3-x64.dll and libcrypto-3-x64.dll. It is flagging this for multiple different applications through out multiple…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
149 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
103 questions
asked 2023-09-22T20:14:57.2433333+00:00
Jeff Thorne 40 Reputation points
answered 2024-04-18T14:51:14.6833333+00:00
Julio Soza 0 Reputation points
1 answer One of the answers was accepted by the question author.

Setting Defender for Server Pricing Plan per resource + disable MDE auto-provision

I have some question related Defender for server and the added ability to set the pricing plans on a resource level as well as outlined here:…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-15T14:25:42.88+00:00
BartDecker-8243 175 Reputation points
accepted 2024-04-18T05:02:11.6733333+00:00
BartDecker-8243 175 Reputation points
1 answer

Can Defender for Endpoint policies and features on Azure Stack HCI hosts be managed by MDE or SCCM?

I am curious whether MDE or SCCM can be used to manage Defender for Endpoint policies and features on Azure Stack HCI hosts. Also, does Azure Stack support the use of ASR rules via Defender for Endpoint? Will enabling ASR impact the functioning of Azure…

Azure Stack HCI
Azure Stack HCI
A hyperconverged infrastructure operating system delivered as an Azure service that provides security, performance, and feature updates.
265 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
asked 2024-04-16T14:22:45.8666667+00:00
Jamie Childs 21 Reputation points
answered 2024-04-18T01:16:36.9066667+00:00
vipullag-MSFT 24,111 Reputation points Microsoft Employee
1 answer

How to get the list of CIS benchmark available for each OS in defender?

Hi Team, We are currently using defender for cloud, where we need to understand the SCA capability of defender for each OS and what all CIS benchmarks does it covers for each os. Can we able to get the list of available Benchmarks for Windows, Linux and…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,194 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
149 questions
asked 2024-04-08T11:41:37.79+00:00
Jayaraman M 0 Reputation points
commented 2024-04-17T01:54:14.4233333+00:00
Akhilesh 4,775 Reputation points Microsoft Vendor