Microsoft Defender for Cloud: How long do CIEM recommendations take to update? Can I trigger them?
I'm using Microsoft Defender for Cloud for my Azure subscriptions and I have the Defender CSPM plan enabled.
Note that I have the following component listed with a status of On:
Insights into Cloud Infrastructure Entitlement Management (CIEM). CIEM is a way of ensuring that the identities and access rights of entities, such as users, groups, roles, or applications, are appropriate and secured in cloud environments. Permissions Management helps to understand the access permissions to cloud resources, such as virtual machines, storage, or databases, and risks associated with those permissions. The setup, data collection and the recommendations generation could take up to 24 hours.
I have a number of Azure recommendations related to "Permissions of inactive identities in your Azure subscription should be revoked" and "Azure overprovisioned identities should have only the necessary permissions" that I have tried to remediate. However, it indicates that they have been last changed a week ago. Should my recommendations be updated daily? Is there any way for me to trigger a manual update like I can do with an Azure policy on-demand evaluation via the Azure CLI?
I'm trying to tighten the feedback loop so that I can remediate things and see feedback as quickly as possible to make sure that I'm correcting my environments.
PS: Please add a tag for Microsoft Defender for Cloud to your Q&A section so I can more quickly identify the correct team.