Microsoft Defender for Cloud: How long do CIEM recommendations take to update? Can I trigger them?

Will Musgrave 0 Reputation points
2025-03-21T13:42:45.2033333+00:00

I'm using Microsoft Defender for Cloud for my Azure subscriptions and I have the Defender CSPM plan enabled.

Note that I have the following component listed with a status of On:

Insights into Cloud Infrastructure Entitlement Management (CIEM). CIEM is a way of ensuring that the identities and access rights of entities, such as users, groups, roles, or applications, are appropriate and secured in cloud environments. Permissions Management helps to understand the access permissions to cloud resources, such as virtual machines, storage, or databases, and risks associated with those permissions. The setup, data collection and the recommendations generation could take up to 24 hours.

I have a number of Azure recommendations related to "Permissions of inactive identities in your Azure subscription should be revoked" and "Azure overprovisioned identities should have only the necessary permissions" that I have tried to remediate. However, it indicates that they have been last changed a week ago. Should my recommendations be updated daily? Is there any way for me to trigger a manual update like I can do with an Azure policy on-demand evaluation via the Azure CLI?

I'm trying to tighten the feedback loop so that I can remediate things and see feedback as quickly as possible to make sure that I'm correcting my environments.

PS: Please add a tag for Microsoft Defender for Cloud to your Q&A section so I can more quickly identify the correct team.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.