1,203 questions with Microsoft Defender for Cloud-related tags

Sort by: Updated
0 answers

Exception Handling for Defender & Third-Party EDR Conflict

Hello. We are currently operating Microsoft Defender for Cloud (MDC). We aim to comply with one of MDC's recommendations, 'EDR solution should be installed on Virtual Machines.' While Windows machines have Microsoft Defender for Endpoint (MDE) installed…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,196 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-05-10T07:52:07.5633333+00:00
용현 정 20 Reputation points
0 answers

How to set Microsoft Defender (Security Center) settings via the Azure.ResourceManager SDK

We have the following code that enables Microsoft Defender for Cloud for an Azure subscription using the Azure.ResourceManager C# SDK. However, when we view the settings for Defender in the Azure portal, a couple of items aren't turned on that we would…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-05-09T16:46:23.4766667+00:00
Jason Looney 0 Reputation points
0 answers

Microsoft Defender for Cloud

Hello, Please guide me, why microsoft defender for cloud service has taking the charges for every month even though I not using the any of the Azure services. What is procedure to refund the unusage services and how to stop/delete it to avoid the…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-05-09T07:04:05.83+00:00
Hafiz 0 Reputation points
1 answer

Can I create a PowerAutomate flow to offboard devices in Defender for Endpoint?

I would like to create a friendly interface for users to offboard devices in Defender for Endpoint, so they won't have to run this process manually. Is this possible?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-05-08T15:04:07.6433333+00:00
Mohammed Ibrahim 0 Reputation points
answered 2024-05-08T19:42:01.3633333+00:00
James Hamil 22,086 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Defender for Endpoint Policies

Hello If a workstation or server is onboarded to defender for endpoint and no security policies have been pushed to the endpoint, what are the default settings or configuration that defender uses? does it stay dormant until policies are pushed? Thanks

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
345 questions
asked 2024-05-01T18:52:24.1+00:00
berketjune2012 371 Reputation points
accepted 2024-05-08T18:43:42.43+00:00
berketjune2012 371 Reputation points
2 answers

Integrating Microsoft Sentinel with Microsoft Defender XDR

I am trying to Integrate microsoft sentinel and defender XDR. So here are the steps I have done so far. Log analytics created, Sentinel attached to the workspace enabled the defender connector . after enabling the connector , I have enabled…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-04-29T08:54:17.4333333+00:00
Anand Rao Nednur 0 Reputation points
commented 2024-05-08T08:12:41.3266667+00:00
Anand Rao Nednur 0 Reputation points
1 answer One of the answers was accepted by the question author.

Microsoft Vulnerability Manager Security Recommendations - Python

Microsoft Vulnerability Manager Security Recommendations is advising to Update Python as it is currently version 3.7.7.0 however, when installing Python latest version (3.12.30) from https://www.python.org/downloads/ it is still reporting on Microsoft…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-05-01T10:08:51.46+00:00
Jack Fields 45 Reputation points
accepted 2024-05-08T07:35:54.4533333+00:00
Jack Fields 45 Reputation points
0 answers

I am receiving this notification from the Defender "Insecure SSH private key"

I am receiving this notification from the Defender "Insecure SSH private key" Defender for Servers found a plaintext SSH private key that is part of a pair. It is important to secure the private key to avoid its misuse or leakage. But on the…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-03-14T08:28:38.85+00:00
Pradeep Khantwal 30 Reputation points
commented 2024-05-07T11:21:54.5333333+00:00
IgorViunov 0 Reputation points
1 answer

Regulatory compliance reports not accurately affecting security

I have some regulatory compliance reports still showing unhealthy resources 3 days after the problem as been remediated. Any idea why this could be happening?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-05-02T01:56:01.4533333+00:00
DG001 346 Reputation points Microsoft Employee
edited an answer 2024-05-06T21:52:13.51+00:00
James Hamil 22,086 Reputation points Microsoft Employee
1 answer

How Defender ATP works on IOS ?

Hello everyone, I am currently a student and intern in cybersecurity, and I am curious about how Defender operates on mobile devices, particularly on iOS (after deployed with Intune). I have been trying to find a flow chart that outlines the workings of…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
Microsoft Intune iOS
Microsoft Intune iOS
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.iOS: An Apple mobile operating system.
189 questions
asked 2024-05-02T12:23:41.01+00:00
Loïc 40 Reputation points
answered 2024-05-06T07:16:35.6366667+00:00
Givary-MSFT 28,486 Reputation points Microsoft Employee
2 answers

Defender I use GPO Can Switch Config policy On Defender Mange by MDE device configuration management ?

Now plan deploy MDE my PC joins local AD which makes it difficult to manage policy through GPO. Is this possible? If I want to use Switch Gpo policy through Device configuration management MDE?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
3,874 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
14 questions
asked 2024-04-25T09:12:13.4166667+00:00
TECHIT SRIWICHAI 160 Reputation points
commented 2024-05-06T05:42:00.36+00:00
Akhilesh 5,090 Reputation points Microsoft Vendor
7 answers

OpenSSL vulnerabilities showing in Defender Dashboard

We have multiple devices showing up with OpenSSL vulnerabilities. It is detecting two dll files that it is flagging. Which they are libssl-3-x64.dll and libcrypto-3-x64.dll. It is flagging this for multiple different applications through out multiple…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
155 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
104 questions
asked 2023-09-22T20:14:57.2433333+00:00
Jeff Thorne 40 Reputation points
edited an answer 2024-05-04T10:02:05.8366667+00:00
Erik Moreau 406 Reputation points MVP
1 answer

Can Defender for Endpoint policies and features on Azure Stack HCI hosts be managed by MDE or SCCM?

I am curious whether MDE or SCCM can be used to manage Defender for Endpoint policies and features on Azure Stack HCI hosts. Also, does Azure Stack support the use of ASR rules via Defender for Endpoint? Will enabling ASR impact the functioning of Azure…

Azure Stack HCI
Azure Stack HCI
A hyperconverged infrastructure operating system delivered as an Azure service that provides security, performance, and feature updates.
273 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-04-16T14:22:45.8666667+00:00
Jamie Childs 21 Reputation points
commented 2024-05-02T09:12:01.1266667+00:00
Jamie Childs 21 Reputation points
1 answer

Disable Microsoft Defender for Cloud for select virtual machines in Azure

I have several VMs running Windows 10/11 and Ubuntu in my Azure vnet and I really don't need them included in Microsoft Defender for Cloud. I've done some searching and apparently there is no way to select which VMs are included in the service, it's an…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,196 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-05-02T01:43:52.0066667+00:00
Paul Nerie 266 Reputation points
commented 2024-05-02T06:20:40.0033333+00:00
Paul Nerie 266 Reputation points
4 answers

Windows Defender SenseNdr.exe Application Crashing Events

Faulting application name: SenseNdr.exe, version: 2.3.1.0, time stamp: 0x7484efee Faulting module name: SenseNdr.exe, version: 2.3.1.0, time stamp: 0x7484efee Exception code: 0xc0000409 Fault offset: 0x000000000071f9c1 Faulting process id:…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2023-08-02T16:59:39.43+00:00
Vrindavan Patange 130 Reputation points
commented 2024-05-01T22:25:29.8633333+00:00
Glenn Turner 10 Reputation points
1 answer One of the answers was accepted by the question author.

Choosing between Defender for Endpoint and Defender for Server for servers with no internet connectivity

We are planning to migrate from Symantec® Endpoint Security to Microsoft, specifically looking for EDR and XDR features for our On Prem servers that have no connectivity to the internet. Should we use Defender for Endpoint or Defender for Servers? We are…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-04-23T07:49:38.81+00:00
milo last 20 Reputation points
accepted 2024-04-30T13:28:13.99+00:00
milo last 20 Reputation points
0 answers

FIM in defender not showing file changes for newly created file after 3 days also.

Team, I have enabled FIM on one of the Resource Group it has created one default Log Analytics Workspace, DCR rule. We executed a script that will create test file on all VM's in /etc and C:\windows\system32 directory. But those changes are not yet…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-04-30T06:15:50.83+00:00
Disha Bodade 65 Reputation points
edited the question 2024-04-30T07:43:48.3433333+00:00
VarunTha 3,615 Reputation points Microsoft Vendor
1 answer

What is best way to keep up to date employer's devices?

I'm looking for a solution with minimum administrator effort for keeping up to date on all employer's devices. In the organization, I have about 50 devices that they onboarded to Defender for Cloud's portal. All devices showing on Microsoft Defender…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,406 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
14 questions
asked 2024-04-03T00:01:57.0166667+00:00
Mohsen Akhavan 936 Reputation points
commented 2024-04-30T06:51:41.01+00:00
Crystal-MSFT 43,721 Reputation points Microsoft Vendor
1 answer One of the answers was accepted by the question author.

Is there a way to enable Defender for Servers in Azure by resource group within a subscription?

Working on deploying Defender for Cloud and wanting to enable Defender for Servers in Azure on a subscription but don't want all servers within the subscription to have it enabled just yet. Would prefer to target servers in specific resource groups…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-04-26T14:45:09.53+00:00
Adrienne Gotwalt 20 Reputation points
edited the question 2024-04-29T05:25:43.6866667+00:00
OMMI NAVEEN KUMAR 195 Reputation points Microsoft Vendor
1 answer

How To Remediate Azure Secure Score Recommendations

Hello, I have this is security recommendation showing in Defender for Cloud, "Azure Machine Learning Computes should have local authentication methods disabled", the remediation steps given is to toggle "Enable SSH access" off. I…

Azure Machine Learning
Azure Machine Learning
An Azure machine learning service for building and deploying models.
2,579 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,203 questions
asked 2024-03-01T02:36:26.8366667+00:00
Andy Lau Pik Hui 60 Reputation points
answered 2024-04-26T01:30:20.87+00:00
Andy Lau Pik Hui 60 Reputation points