1,403 questions with Microsoft Defender for Cloud-related tags

Sort by: Updated
0 answers

Attack Simulation Training recording "clicked message link" when reporting as junk mail

I've run my 2nd simulation training attack on my team but I was surprised to see that this one had more users showing as "clicked message link". Looking into it I can see that they have reporting the email as junk (not phishing) and when I…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-11-05T09:49:50.7933333+00:00
Chris 0 Reputation points
1 answer

Vulnerability Assessment and Penetration Test Report.

Hi Experts, One of our client is requesting a VAPT (Vulnerability Assessment and Penetration Testing) report from the cloud provider. Is it possible to obtain such a report from Microsoft, particularly after addressing any vulnerabilities? We are using…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-10-28T07:07:05.5133333+00:00
Veera 260 Reputation points
commented 2024-11-05T06:40:23.36+00:00
Givary-MSFT 32,991 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Incidents in Microsoft Sentinel Auto-Closing Without Automation Rules

I'm currently using Microsoft Sentinel and noticing that some incidents are automatically closing themselves, sometimes with the reason "resolved at source" or no comment at all. I've checked for any automation rules or playbooks that might be…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,151 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,053 questions
asked 2024-10-17T14:15:27.48+00:00
Hyago Santana Mariano 20 Reputation points
accepted 2024-11-04T19:55:29.14+00:00
Hyago Santana Mariano 20 Reputation points
1 answer One of the answers was accepted by the question author.

Defender for Servers or containers covers VMs on Containers?

We have a scenario wherein we are to have AKS clusters with containers. We would be running VMs on these containers. We wanted to understand if Defender for servers or Defender for containers or MDE covers these VMs from security standpoint at OS level,…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
44 questions
asked 2024-11-04T16:38:05.95+00:00
Rakesh Singh 210 Reputation points
accepted 2024-11-04T17:22:51.54+00:00
Rakesh Singh 210 Reputation points
1 answer One of the answers was accepted by the question author.

Identity Secure Score Regression without making any changes

Hello, Our Identity Secure Score in Entra ID has dropped from 79.98% to 50.36% without any changes made on our part. Using Microsoft Defender, we can view the Microsoft Secure Score, which is different from the Entra Identity Secure Score. However, we…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,053 questions
asked 2024-10-18T12:46:11.64+00:00
LM-5132 100 Reputation points
accepted 2024-11-04T15:58:13.3233333+00:00
LM-5132 100 Reputation points
2 answers

Tag name effect on Azure Defender for Cloud alerts

Hello! I am wondering if Tag names are case sensitive in case of Defender for Cloud sending alerts. For example if Defender for Cloud sends an alert based on the tag "Owner" would it also send notifications for: "Owner " …

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
912 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-10-28T09:19:39.9466667+00:00
Caroline CAH 20 Reputation points
answered 2024-11-04T13:58:33.11+00:00
Shikha Ghildiyal 0 Reputation points Microsoft Employee
1 answer

Defender recommendation issue

In Defender for cloud, I'm getting Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost recommendations, but in my Azure VM EncryptionAtHost enabled already, I have checked connection between VM and Azure monitor and also…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-09-11T15:35:44.4766667+00:00
Davit Grigoryan 11 Reputation points
commented 2024-11-04T12:30:44.3633333+00:00
Per Bendixen - Bixsoft 0 Reputation points
1 answer

MDE (WCF- Wild Card & FQDN is not there)

WCF, why there is no wildcard option or FQDN for allow and block list in WCF (MDE)

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-09-30T03:26:16.2333333+00:00
Sathish 0 Reputation points
answered 2024-11-04T10:58:33.08+00:00
Gautam 0 Reputation points Microsoft Employee
0 answers

Error when disabling "OpenSourceRelationalDatabases" plan in Defender for Cloud

I catch error when disabling "OpenSourceRelationalDatabases" plan in Defender for Cloud. "(AuthorizationFailed) Azure Security Center has no access to act on behalf of the subscription, please contact your tenant administrator Code:…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-09-27T17:01:38.25+00:00
Vitalii Liashuk 5 Reputation points
commented 2024-11-04T10:13:31.7633333+00:00
Gautam 0 Reputation points Microsoft Employee
0 answers

Disabling recommendations in Azure CSPM Preview

We are using Defender for Cloud with both the Microsoft cloud security benchmark and Azure CSPM (Preview) security policy standards. Where we have a use-case for disabling a recommendation in MCSB, I can easily do this as it is managed via Azure Policy…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-09-23T14:26:33.4166667+00:00
Dominic Schreiber 5 Reputation points
commented 2024-11-04T09:45:47.4833333+00:00
Gautam 0 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Insecure Azure storage SAS token

Hi, I am getting the recommendation "Insecure Azure storage SAS token" in Defender for the cloud. How to resolve it?

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,217 questions
Windows Server Storage
Windows Server Storage
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Storage: The hardware and software system used to retain data for subsequent retrieval.
653 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-11-04T05:16:24.4233333+00:00
Nudiya Anjum 20 Reputation points
accepted 2024-11-04T07:15:51.5933333+00:00
Nudiya Anjum 20 Reputation points
2 answers

Bulk Disable Defender Security Policies

Hi, We have circa 280 individual subscriptions which have the MS cloud security benchmark enabled, which we would like to remove from all. Is there a convenient powershell command or similar which would allow me remove this from all subs at…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-10-21T11:52:25.88+00:00
YogiBear 170 Reputation points
commented 2024-11-01T14:29:53.81+00:00
Stanislav Zhelyazkov 24,611 Reputation points MVP
2 answers

How to fully Uninstall/Clean-up Microsoft Defender Endpoint

Hello, We are having issues trying to use a migration tool to move our devices to another Microsoft tenant. It seems to be struggling gaining access and deleting a regkey that is link to a service for MDE. The tool is running and using the system…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,184 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
210 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
44 questions
asked 2024-06-27T13:23:57.6933333+00:00
Dan Beeney 0 Reputation points
edited the question 2024-11-01T11:16:59.36+00:00
simo-k 555 Reputation points
1 answer

Microsoft Defender is still showing a resolved recommendation.

Microsoft Defender for Cloud recommended to enable encryption at host in one of my Windows VM and I enabled encryption at host in that VM. But Microsoft Defender is still showing that recommendation. Can anyone answer why Defender is showing the resolved…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-10-21T12:15:53.5833333+00:00
Christeena Saji 20 Reputation points
commented 2024-11-01T06:08:57.5366667+00:00
Givary-MSFT 32,991 Reputation points Microsoft Employee
1 answer

Zero Day Defender For Endpoint and M365 and Cloud Apps and Entra

Threatlocker can learn and block zero day malware. Darktrace is constantly learning about new threats. How does Microsoft’s tools compare with the above 2 solutions in regards to using AI to relearn and detect beyond simply hash lookups. for: Edr Dlp …

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-10-18T19:27:38.1433333+00:00
David Broggy 5,821 Reputation points MVP
commented 2024-11-01T05:54:47.93+00:00
Givary-MSFT 32,991 Reputation points Microsoft Employee
1 answer

Both full and quick scans are out of 7 days

I would like to know why it shows as Both full and quick scans are out of 7 days? Already verified the below. Defender for Cloud enabled on your Azure account. You must have either of the following plans enabled on Defender for Cloud enabled on your…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-10-11T14:50:04.51+00:00
Raj 0 Reputation points
commented 2024-11-01T04:22:43.4466667+00:00
Givary-MSFT 32,991 Reputation points Microsoft Employee
1 answer

Enterprise Microsoft Defender Exclusion Files and Folder Path Audit Activity

Hi Community Members, Does anyone know where would be the events to locate for Defender files and folder paths and file exclusions performed by Admins? Its an enterprise Defender solution and not home. Many Thanks.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-10-31T11:02:01.5333333+00:00
joomla3597 35 Reputation points
answered 2024-10-31T17:13:43.22+00:00
James Hamil 25,006 Reputation points Microsoft Employee
0 answers

Azure MDC - FIPS detection false positive ?

Hi, I've been working on hardening my servers for a few weeks now and there is a finding called "Windows Server must be configured to use FIPS-compliant algorithms for encryption, hashing, and signing. (STE)" that I do not manage to…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-09-20T13:38:25.54+00:00
Dufour, Francois 46 Reputation points
commented 2024-10-31T13:49:09.72+00:00
Dufour, Francois 46 Reputation points
0 answers

OpenSSL Vulnerability Shown on Microsoft Defender for Cloud Dashboard - OneDrive affected app

An OpenSSL vulnerability has been flagged on one of our devices by Microsoft Defender for Cloud. The vulnerability has listed two dll files as the main culprits (both installed via OneDrive): libcrypto-3-x64.dll libssl-3-x64.dll The OneDrive version…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-10-31T12:38:50.5166667+00:00
Eric Wasike 0 Reputation points
edited the question 2024-10-31T12:44:38.2133333+00:00
Eric Wasike 0 Reputation points
1 answer One of the answers was accepted by the question author.

Defender Cloud for Azure HCI

Hello, Can we use defender cloud to protect our onprem VM guest if we use Azure Stack HCI?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,403 questions
asked 2024-10-31T04:19:01.5933333+00:00
Handian Sudianto 5,121 Reputation points
accepted 2024-10-31T07:22:48.6+00:00
Handian Sudianto 5,121 Reputation points