1,498 questions with Microsoft Defender for Cloud-related tags
Defender 50 GB GA
Hi All, I was going through the document on https://learn.microsoft.com/en-us/azure/defender-for-cloud/introduction-malware-scanning The document talks about "up to 50 GB in preview" Can I know when will be the GA for this…
Unexpected Network Traffic Reaching VM Despite NSG Configuration in Azure
We are experiencing an issue where network traffic is reaching our Virtual Machine, even though our Network Security Group (NSG) is configured to block this traffic. For example, traffic on port 80 is being logged by UFW on the VM, despite the NSG rules…
How can I avoid an exchange service to fall into a restricted entity in Microsoft 365
I have a Microsoft 365 basic account. I am using an email from my account to send notifications and documents as attachments from an app that is located on an EC2 Amazon AWS. The problem I have is that the email account keeps falling under restricted…
Does the "Previously assigned" training completion status in Attack Simulator mean that the training has NOT been completed by the user?
I am using attack simulator to phish and assign training employees. I recently noticed a new status of completion of training following a click: "Previously assigned." Can you clarify what this Previously Assigned in the training completion…
Approve remediation pending action failed Request failed with status code 403
Receiving this error message when trying to approve pending action in Microsoft Defender. Please advise.
Need IOC's
Hi MSTeam, Can i have IOC's for the vulnerability "CVE-2024-21413" to hunt.
How do I remediate the Secure Score recommendation to enable automatic updates in office now that admin templates are deprecated in intune?
This information is incorrect: Go to the Devices-> Configuration profiles To update an existing policy: Click on the policy name in the list In the navigation bar, click on Properties Next to Configuration settings click on Edit Go to step…


Microsoft Defender for cloud
I'm trying to integrate defender CSPM advance , aws instance. I want to know is there any cost for data ingest from azure and egres from aws
DfC pre-scan possible (before pushing an image to a container)?
Is there a way to run a Defender for Containers like-scan before I push an image to a container? My team would like to verify that an image will pass DfC scans before pushing an image....
Inbound Port Rule resets everyday at 9:00am EST
Everyday at 9:02am EST within the Network Settings our Inbound Port Rules will reset automatically causing our remote users issues with remoting into the virtual machine. A 'Microsoft Defender for Cloud' rule will automatically appear at the top of the…
Not able to load recommendations in Secure Score
Hello, In the recommended actions tab after selecting a recommendation, it does not open, instead keeps loading. Screenshot 2025-02-18 172535.png
Azure Defender | Filter API by properties fields
Hi, I am trying to use this API to fetch detections: 'https://management.azure.com/subscriptions/<subscription_id>/providers/Microsoft.Security/alerts?api-version=2022-01-01&$filter=properties/startTimeUtc gt <datetime>' However, the…
Security and protection against ransomware/malware in Azure
We have VPN S2S connections from various locations. Plannign to deploy Azure Standard firewall. None of the VMs have public ips. We will be configuring azure sql managed instance with private endpoints and storage accounts with private links. Also will…
Microsoft Defender for Cloud Security Alerts are still open while link in Defender XDR is already resolved
Our team observed that there are open or active alerts in Microsoft Defender for Cloud while its corresponding incident in Defender XDR is already resolved. We assume that it is the corresponding alert in Defender XDR since when we click the link in…
Identifying OS Patches and Updates by Severity in Azure
Hello, How can I identify operating system patches or available OS updates on both Linux and Windows Azure VMs based on severity within the Azure Portal, Azure Update Manager, or Microsoft Defender for Cloud ? In Azure Update Manager, updates are…
How can I discover all necessary permissions to use a Azure Policy with least privileges
The Problem Hey I working for a project that will implement azure policies to secure the platform. We have to follow the policies of our customer. One of this policies is, to use always the concept of least privileges. If we take a look in the Policy…
Environment risk of All recommendations by risk enable
How to enable the environmental risk of All recommendations by risk. Now, it is showing zero in all risks.
How can I resolve the AuthorizationFailed error I’m encountering while connecting Microsoft Defender with Node.js?
Hello, I’m encountering this error while trying to connect Microsoft Defender with Node.js. Despite having both Reader and Security Reader roles assigned, the issue persists. I'm unsure of the root cause. Error Message: "The client '' with object ID…
How to remediate "Audit diagnostic setting for selected resource types"
Hi, Under regulatory compliance in defender, I have this recommendation "Audit diagnostic setting for selected resource types" which sounds very confusing. I have many resources under this recommendation, I opened some and enabled all type of…
"Cannot read properties of null (reading 'toString')" error in MS Defender for Cloud in Azure
Hi, When I want to open Regulatory Compliance blade in Microsoft Defender for Cloud, all of the sudden I started to get error message as below: Could you please assist?