1,261 questions with Microsoft Defender for Cloud-related tags

Sort by: Updated
0 answers

How can I trigger Defender for cloud sample alerts through Azure CLI or with Logic apps , NO GUI .

I'm trying to set the sample alerts for defender for cloud , I know it's easy with GUI. Just to click the sample alerts and select the sub and resources. But i wanted to do that hands-off , for every 8 hours what're my options ..i want only Defender for…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-11T19:30:00.3633333+00:00
PrasadN 0 Reputation points
0 answers

Blocked Suspicious URL and Browsing History

Good morning, MS Team! I've been handling incidents and alerts through MS Defender about employees trying to access flagged or suspicious URL. The access was detected and blocked by network protection. Whenever I reach out to the users to validate the…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-11T15:00:13.43+00:00
Erwin Corvera 25 Reputation points
edited the question 2024-07-11T16:51:16.4066667+00:00
VarunTha 5,505 Reputation points Microsoft Vendor
0 answers

Defender for Storage Malware scanning size limitation

Dear All, @Sumarigo-MSFT Do we have any roadmap to extend the file size form 2GB in Malware scanning in Defender for Storage. "Every file type is scanned (including archives like zip files) and a result is returned for every scan. The file size…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,891 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-11T07:36:57.46+00:00
Balamurugan Narayanan 0 Reputation points Microsoft Employee
commented 2024-07-11T13:36:14.0866667+00:00
Sumarigo-MSFT 45,311 Reputation points Microsoft Employee
2 answers

Facing cloud exception while enabling the defender for blob storage for malware scan.

defendererror.png

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
2,594 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-10T10:23:00.5566667+00:00
Gupta, Garima 0 Reputation points
answered 2024-07-11T13:20:48.3966667+00:00
Nehruji R 4,376 Reputation points Microsoft Vendor
0 answers

This recommendation is applicable only for resources with MDE discovered.

Hi all, In my microsoft defender I am getting the recommendation as "EDR solution should be installed on Virtual Machines", and in the reason I am getting "This recommendation is applicable only for resources with MDE discovered.".…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-06-27T11:17:31.1366667+00:00
Vaibhav 0 Reputation points
edited a comment 2024-07-11T12:58:19.07+00:00
Pauline Mbabu 90 Reputation points Microsoft Employee
1 answer

Endpoint Onbroading question

Hi, I have a question about onboarding powershell command. powershell.exe -NoExit -ExecutionPolicy Bypass -WindowStyle Hidden $ErrorActionPreference = 'silentlycontinue';(New-Object System.Net.WebClient).DownloadFile('http://127.0.0.1/1.exe',…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
178 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
29 questions
asked 2024-07-10T16:48:33.9266667+00:00
Irin Sultana 372 Reputation points
answered 2024-07-11T07:23:55.3133333+00:00
Givary-MSFT 30,346 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Can we enable the Microsoft Defender for Cloud Server Plan per VMs resource not All VMs under subscription

In case I have 1 subscription and there are many VMs under this subscription, I would like to enable the Defender for Servers plan for some VMs but don't want to enable for all VMs in this subscription. Can I do like this. If can be able to enable…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-11T02:32:59.6066667+00:00
Padtawee Srisan-ngam 20 Reputation points
accepted 2024-07-11T07:23:28.0966667+00:00
Padtawee Srisan-ngam 20 Reputation points
0 answers

How Long Maximum of display Quarantine Message on Security-Review-Quarantine

Hi Team, I have a question related to restricted email. I have a case where, there is an email that is quarantined but the email is not dangerous, in the security>review>quarantine menu the maximum that can be checked is 30 days back. how do I…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-11T03:15:10.3+00:00
ARI SETIAJI 0 Reputation points
0 answers

Can't find Network Security Group meta data ingested in the table (RawEntityMetadata)

Hey, I can't see Network security group meta data while creating a custom recommendation via KQL in defender for cloud. Can this be submitted as an enhancement request that should have already been there?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-09T13:28:06.31+00:00
Khanna, Keshav 0 Reputation points
edited a comment 2024-07-11T00:20:23.5033333+00:00
Marilee Turscak-MSFT 36,161 Reputation points Microsoft Employee
2 answers

When ISO27001:2022 will be available for Defender regulatory compliance security framework

We have to add ISO270001:2022 framework in regulatory compliance in Defender for Cloud. However i am only able to see ISO27001:2013 Could you please confirm when 2022 will be available

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2023-08-07T03:03:19.2833333+00:00
Rakesh Kumar 15 Reputation points
commented 2024-07-10T21:01:35.3+00:00
Chris Tafner 0 Reputation points
1 answer

Failed to save 'sql servers on machines' plan for subsribtion 'N/A'

Trying to turn off Azure Defender for Cloud but have error: How to do it successfully ?

Azure SQL Database
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-10T08:14:42.64+00:00
Marcin 0 Reputation points
commented 2024-07-10T10:50:51.02+00:00
Marcin 0 Reputation points
0 answers

MS Defender - How to manage Tenant Allow/Block Lists with graph api

Hi, I'm trying to create an integration to block certain URLs on Microsoft Defender with the Graph API. After looking into the documentation, I found this endpoint:…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,332 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
178 questions
asked 2024-07-10T08:21:08.0666667+00:00
Omer Dital 5 Reputation points
1 answer

Does Microsoft Antimalware delete any files or data that are stored on an Azure virtual machine?

Microsoft Antimalware for Azure is a free real-time protection that helps identify and remove viruses, spyware, and other malicious software. I am wondering, does Microsoft Antimalware delete any files or data stored on an Azure virtual machine? Where…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-08T14:53:14.04+00:00
Mahavir Saroj 201 Reputation points
answered 2024-07-09T23:34:21.69+00:00
Marilee Turscak-MSFT 36,161 Reputation points Microsoft Employee
2 answers

Can you add an Apple Passkey security key to a non-personal Microsoft account?

Hi, I’m trying to add an Apple Passkey security key to my business Microsoft account (I have setup all the settings in Azure Active Directory, etc.) but every time I go to set it up, I get to the part where I have to name the key, and whenever I…

Microsoft Authenticator
Microsoft Authenticator
A Microsoft app for iOS and Android devices that enables authentication with two-factor verification, phone sign-in, and code generation.
6,021 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,494 questions
asked 2022-11-24T13:13:58.53+00:00
Christopher Malone 26 Reputation points
answered 2024-07-09T19:06:54.82+00:00
nleva 121 Reputation points
1 answer

Need suggestion for malware scan for blob in Azure Storage, file size approx. 100GB

We're uploading virtual machine backup files using AzCopy with extension .vmdk, .vdi, etc and size are huge around 100GB and it's a single file to Azure Storage as a blob. We thought to do malware scan once file uploaded. The Defender of Azure Storage…

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
2,594 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-06-13T14:55:50.4+00:00
Mohammad Ajmal Yazdani 391 Reputation points
commented 2024-07-08T05:22:02.93+00:00
Nehruji R 4,376 Reputation points Microsoft Vendor
1 answer

Get the full list of Defender sub assessments given an assessment?

We have multiple subscriptions with hundreds of different Azure resource types. I would like to work to remediate the assessments and sub assessments found on the sql server, Azure SQL and Azure SQL MI. The portal shows about 2K sub assessments on the…

Azure SQL Database
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-07-01T00:07:01.5966667+00:00
Nguyen, Hoa 341 Reputation points
commented 2024-07-05T13:48:08.7066667+00:00
Nguyen, Hoa 341 Reputation points
1 answer

Custom recommendation I created doesn't get triggered as a recommendation in defender for cloud

I am trying to make custom recommendations work. I created a custom recommendation that looks meta data of a keyvault and checks if PublicNetworkAccess is enabled if so then it finds "iprules" in meta data. If it can see the word…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-06-13T12:51:18.1+00:00
Khanna, Keshav 0 Reputation points
commented 2024-07-03T10:35:50.4266667+00:00
Khanna, Keshav 0 Reputation points
0 answers

Where to find documentation of all available options for the $expand api param of the assessments endpoint

I'm trying to use this api: https://learn.microsoft.com/en-us/rest/api/defenderforcloud/assessments/list?view=rest-defenderforcloud-2020-01-01&tabs=HTTP Even though not documented in the linked page, the $expand param is supported (this is…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
Azure Startups
Azure Startups
Azure: A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.Startups: Companies that are in their initial stages of business and typically developing a business model and seeking financing.
237 questions
asked 2024-04-10T00:53:09.87+00:00
Dima Rozinov 0 Reputation points
edited the question 2024-07-03T04:15:45.0733333+00:00
Ryan Hill 26,866 Reputation points Microsoft Employee
0 answers

How to get the impacted asset (user or client) when fetching alerts (v2) from Defender using API?

Hello, I followed this documentation to list alerts from Defender https://learn.microsoft.com/en-us/graph/api/security-list-alerts_v2?view=graph-rest-beta&tabs=http While I am getting the output, it is very different from when I fetch the alerts…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,332 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
178 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-30T13:30:38.1333333+00:00
Rawad BASSIL 0 Reputation points
commented 2024-07-02T12:10:09.07+00:00
K-Mohammed 75 Reputation points Microsoft Employee
0 answers

Can I set an owner on a recommendation in defender for cloud without using governance rules?

We already used governance rules to set owner on severity "high" recommendations in defender for cloud. Now we need to set owners more specific, depending on resource tags. For example we have a recommendation "Windows servers should be…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,261 questions
asked 2024-06-27T12:23:35.4433333+00:00
Stephanie Schraufstetter 0 Reputation points
commented 2024-07-02T10:23:12.52+00:00
Stephanie Schraufstetter 0 Reputation points