1,250 questions with Microsoft Defender for Cloud-related tags

Sort by: Updated
5 answers

Impossible to enable Defender for Storage Malware scanning

I would like to enable Azure Defender Malware scanning on my (StorageV2) Storage Account. I upgraded my subscription's MS Defender for Cloud plan. However, any attempt on enabling Malware scanning or Sensitive data discovery fails. While enabling on…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,853 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2023-05-16T15:33:43.44+00:00
PP 20 Reputation points
commented 2024-06-06T13:29:42.0933333+00:00
Eric Buist 0 Reputation points Microsoft Employee
0 answers

How to get the impacted asset (user or client) when fetching alerts (v2) from Defender using API?

Hello, I followed this documentation to list alerts from Defender https://learn.microsoft.com/en-us/graph/api/security-list-alerts_v2?view=graph-rest-beta&tabs=http While I am getting the output, it is very different from when I fetch the alerts…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
11,188 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
172 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
118 questions
asked 2024-05-30T13:30:38.1333333+00:00
Rawad BASSIL 0 Reputation points
edited the question 2024-06-06T06:12:59.9466667+00:00
Rakesh Gurram 5,070 Reputation points Microsoft Vendor
1 answer

Defender for cloud not enable some of the subscription

Hi, We have added 23 subscriptions to a single management group and enabled Defender for cloud at the management group level, and assigned NIST 00-53. However, only 2 of the 23 subscriptions are showing the Defender state as "OFF".…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-30T02:20:43.16+00:00
Joseph, Christopher 0 Reputation points
commented 2024-06-06T05:02:17.71+00:00
Akshay-MSFT 17,486 Reputation points Microsoft Employee
2 answers

how do I use Azure Policy to enable 'Agentless scanning for machines (preview)' setting for Defender for CSPM

I cant seem to find a policy that enables the 'Agentless scanning for machines (preview)' setting in Defender for Cloud. How do i do it then?

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
819 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2023-03-15T20:25:57.67+00:00
Nadia Hansen 0 Reputation points
answered 2024-06-05T20:40:09.77+00:00
SteveJ22LK90 0 Reputation points
1 answer One of the answers was accepted by the question author.

Microsoft Defender for Cloud

Hi Team, I am receiving alerts which says the Backup Failure for my Virtual machines, I am not able to fix the issue could you please check and do the needful. This was the Recommended actions suggest by not not able to understand this. Please grant…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,956 questions
Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,444 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-02-16T07:02:49.7133333+00:00
Pradeep Khantwal 50 Reputation points
accepted 2024-06-05T09:35:46.33+00:00
Pradeep Khantwal 50 Reputation points
1 answer

Can I create a PowerAutomate flow to offboard devices in Defender for Endpoint?

I would like to create a friendly interface for users to offboard devices in Defender for Endpoint, so they won't have to run this process manually. Is this possible?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-08T15:04:07.6433333+00:00
Mohammed Ibrahim 0 Reputation points
commented 2024-06-04T20:53:09.0566667+00:00
James Hamil 22,891 Reputation points Microsoft Employee
1 answer

How to block SAM, LSA dump through Microsoft Defender for Endpoint

Hello, I am trying to see if the EDR Microsoft Defender for Endpoint or other solutions from Microsoft offer options to block the following hive dump SAM, LSA and optionaly DPAPI. I am aware that suspicious dumps are detected but is there a possibility…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-31T14:25:17.97+00:00
Pierre 0 Reputation points
commented 2024-06-04T09:59:01.52+00:00
Pierre 0 Reputation points
1 answer One of the answers was accepted by the question author.

ServiceNow integration with Defender for Cloud

What permissions are required in SerivceNow for the ServiceNow integration with Defender for Cloud user? The doc does not seem to indicate what permissions are required for the ServiceNow service account in…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-21T00:08:36.3933333+00:00
DG001 386 Reputation points Microsoft Employee
accepted 2024-06-04T02:31:46.19+00:00
DG001 386 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Exception Handling for Defender & Third-Party EDR Conflict

Hello. We are currently operating Microsoft Defender for Cloud (MDC). We aim to comply with one of MDC's recommendations, 'EDR solution should be installed on Virtual Machines.' While Windows machines have Microsoft Defender for Endpoint (MDE) installed…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
26 questions
asked 2024-05-12T23:46:36.76+00:00
용현 정 40 Reputation points
accepted 2024-06-03T23:53:30.83+00:00
용현 정 40 Reputation points
1 answer One of the answers was accepted by the question author.

Microsoft Defender for Containers in AKS-HCI - pricing questions

Hello, I added a new AKS-HCI kubernetes cluster on premises to arc, and enabled defender for containers and installed the extensions in the cluster. but billing has still been 0 since 1 month. can you explain why. given that it is stated that billing…

Azure Stack HCI
Azure Stack HCI
A hyperconverged infrastructure operating system delivered as an Azure service that provides security, performance, and feature updates.
296 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-31T13:09:57.42+00:00
Chelligue Hamza 45 Reputation points
accepted 2024-06-03T08:41:13.4+00:00
Chelligue Hamza 45 Reputation points
2 answers

How to notify security team members of assigned alerts/incidents in Microsoft Defender

Is there a way to send email notifications to someone when we assign an alert or incident specifically to them in Microsoft Defender? We already have email notifications set up for new alerts, but we're wondering if there is a way to notify team members…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-29T19:10:08.59+00:00
Fraley, David 0 Reputation points
answered 2024-06-03T06:39:04.6066667+00:00
Sandeep G-MSFT 15,816 Reputation points Microsoft Employee
1 answer

What's the exact definition of 'Timegenerated' in an Azure Resource Graph query output for Container Image Vulnerabilities?

When we run a query to find vulnerabilities in Container Images, there's a 'timegenerated' column in the query output. I've tried to find this documented somewhere, but can't, I've only found a document for Azure Monitor. Does this mean it's the last…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
2,956 questions
Azure Container Registry
Azure Container Registry
An Azure service that provides a registry of Docker and Open Container Initiative images.
419 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-30T14:45:02.8466667+00:00
LaBombard, Lory 41 Reputation points
commented 2024-05-31T16:30:54.6166667+00:00
Lory Labombard 0 Reputation points Microsoft Employee
1 answer

Azure - Microsoft Defender for Cloud - I can't download security recommendations to a CSV. I could for nearly 90 days straight and can download all others.

Hi, I can't download security recommendations to a csv file from: Microsoft Defender for Cloud | Recommendations from either the: Secure score recommendations or All recommendations tabs in Azure. I was able to do so yesterday and nearly every day since…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2022-05-31T13:57:58.173+00:00
John M. Kimball 1 Reputation point
commented 2024-05-31T12:52:55.9+00:00
Miller, Stephen 0 Reputation points
0 answers

Microsoft defender is alerting for vulnerable version of nuget package in Azure Function's ".azurefunctions/function.deps.json" file"

Hi Champs, I'm facing a typical problem with my function app and MS defender for cloud. Defender is raising issues for my deployed function(written in c#) as: Even after installing latest nuget package, "function.deps.json" file is not…

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
4,542 questions
Azure
Azure
A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.
1,070 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-30T05:26:36.4033333+00:00
Pratim Das, Partha C 306 Reputation points
edited the question 2024-05-31T01:04:10.4133333+00:00
Pratim Das, Partha C 306 Reputation points
1 answer

If Defender for Blob doesn't scan a file (no tags) is there anything we can do to force it to look again?

We have a system that scans all files uploaded to blob on upload. However, we've noticed that occassionally some files just never get scanned (i.e. never get the tags against them). In the documents it does say this can happen if the file throughput is…

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
2,570 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-29T14:02:34.32+00:00
Ed Russell 0 Reputation points
commented 2024-05-30T13:59:47+00:00
Ed Russell 0 Reputation points
1 answer

How to stop ATP clicking links in Phishing simulation emails

I have logged in to Microsoft Defender for O365 and configured the Phishing Simulation tab under Email & collaboration > Policies & rules > Threat policies > Advanced delivery. But something ATP wise is still clicking the links in my…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
4,186 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-14T10:05:54.43+00:00
DOdmin 0 Reputation points
commented 2024-05-30T05:16:58.9166667+00:00
Akshay-MSFT 17,486 Reputation points Microsoft Employee
1 answer

Standard Recommendations with Source "Defender for Cloud"

Recommendations under Compliance Standards (e.g. Azure CSPM (Preview) Standard) are tagged with source field as "Policy" or "Defender for Cloud". whats the difference between recommendations that are sourced from policy vs defender…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-23T20:55:59.75+00:00
Tropo Bridge 0 Reputation points
edited a comment 2024-05-29T14:03:09.0466667+00:00
Tropo Bridge 0 Reputation points
1 answer

Enable Defender For Storage malware scanning using ARM template.

I have this resource definition: //Defender For Storage { "type": "Microsoft.Security/DefenderForStorageSettings", "apiVersion": "2022-12-01-preview", "name":…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-29T10:34:05.5533333+00:00
Denys Bielov 25 Reputation points
commented 2024-05-29T12:05:22.0166667+00:00
Anushka 320 Reputation points
3 answers One of the answers was accepted by the question author.

Error durin on-upload malware scan activation for storage account

I created Event Grid topic and want to assign it to Microsoft Defender report pipeline. When I enable on-upload scan for my storage account and select my topic, I get Plan enablement partially succeeded. Could not enable on-upload malware scanning:…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
2,853 questions
Azure Event Grid
Azure Event Grid
An Azure event routing service designed for high availability, consistent performance, and dynamic scale.
339 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-21T16:29:33.4633333+00:00
Denys Bielov 25 Reputation points
answered 2024-05-29T10:30:08.2266667+00:00
Denys Bielov 25 Reputation points
1 answer

How to set Microsoft Defender (Security Center) settings via the Azure.ResourceManager SDK

We have the following code that enables Microsoft Defender for Cloud for an Azure subscription using the Azure.ResourceManager C# SDK. However, when we view the settings for Defender in the Azure portal, a couple of items aren't turned on that we would…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2024-05-09T16:46:23.4766667+00:00
Jason Looney 0 Reputation points
answered 2024-05-28T12:58:11.2766667+00:00
Andrew Blumhardt 9,831 Reputation points Microsoft Employee