1,567 questions with Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

the recommendation named “ Kubernetes clusters should disable automounting API credentials” does not provide the option to create an exemption.

the recommendation named “Kubernetes clusters should disable automounting API credentials” does not provide the option to create an exemption. How can we resolve this?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-06-13T14:51:56.5766667+00:00
Brynel Peter Libera (CONVERGYS CORPORATION) 100 Reputation points Microsoft External Staff
commented 2025-06-17T16:18:03.54+00:00
Brynel Peter Libera (CONVERGYS CORPORATION) 100 Reputation points Microsoft External Staff
3 answers

OpenSSL vulnerabilities in Defender for latest version Microsoft Products

My org has several OpenSSL vulnerabilities for OneDrive and Azure Disk Encryption. The CVEs are CVE-2024-4603, CVE-2024-4741, CVE-2024-5535, and Defender was said to fix inaccuracies with these last month (Sept. 2024).…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-10-15T20:07:36.4466667+00:00
Zach Hyman 130 Reputation points
commented 2025-06-17T08:25:37.1466667+00:00
Paul Brears 0 Reputation points
2 answers One of the answers was accepted by the question author.

Resolving EDR Configuration Issues for Deleted Virtual Machines

Hi there, I am currently looking to improve secure score. One of the recommendation is to Enable Endpoint Protection which has a secondary recommendation as follows: "EDR configuration issues should be resolved on virtual machines". However,…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-06-02T18:02:31.23+00:00
A Dahal 20 Reputation points
accepted 2025-06-16T16:05:02.2866667+00:00
A Dahal 20 Reputation points
1 answer

False Positives on Attack Simulation Training - And how to cancel the training assigned to the user as a result of the false positive?

#1. Defender is reporting that users opened an attachment on an Attack Sumulation. Several users are claiming they did not open the attachment. We've been using Defender for a little over 2 years, and we used another tool prior for 5 years prior to…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-07-26T15:35:44.8933333+00:00
Jason 10 Reputation points
commented 2025-06-13T15:32:07.0566667+00:00
Chris 0 Reputation points
2 answers

webhook enablement error

Hi, we have enabled to defender at blob storage level. We have assigned the eventgrid to capture the defender results in case of malware detection. We want to attach a webhook to eventgrid subscription to notify the malware errors in API. It throws error…

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
3,212 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-07-26T04:54:37.5533333+00:00
Gupta, Garima 20 Reputation points
commented 2025-06-11T09:43:24.3966667+00:00
AARON Anthony (OPR) 0 Reputation points
2 answers

defender for cloud apps

HI team, need your help with the below. I am going through the documentation of defender for cloud app M365 and i found that in order to import and study the logs, we will need a firewall, proxy etcc and based on that we can discover the IT shadow…

Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2023-01-13T06:43:23.7266667+00:00
eg1995 1,156 Reputation points
commented 2025-06-11T03:27:14.7733333+00:00
GPGK 0 Reputation points
1 answer One of the answers was accepted by the question author.

Defender for cloud DevOps Security: Is it mandatory to have Github Advanced security enabled to find code vulnerabiltiy in azure devops repos

We are exploring the feature Microsoft Security DevOps and noticed there are no code vulnerability listed in the defender except Iac templates. As per the following table, is it a must have to enable Github Advanced Security to discover code or secret…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-06-09T20:55:10.2+00:00
ahd 210 Reputation points
accepted 2025-06-10T13:26:56.5733333+00:00
ahd 210 Reputation points
2 answers

What's the exact definition of 'Timegenerated' in an Azure Resource Graph query output for Container Image Vulnerabilities?

When we run a query to find vulnerabilities in Container Images, there's a 'timegenerated' column in the query output. I've tried to find this documented somewhere, but can't, I've only found a document for Azure Monitor. Does this mean it's the last…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,674 questions
Azure Container Registry
Azure Container Registry
An Azure service that provides a registry of Docker and Open Container Initiative images.
511 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-05-30T14:45:02.8466667+00:00
LaBombard, Lory 41 Reputation points
answered 2025-06-09T13:26:52.7966667+00:00
Jeff LoSpinoso 0 Reputation points
1 answer One of the answers was accepted by the question author.

An unknown application will gain access to the user's mailbox on their behalf.

Hello, We use a third-party event analytics service in M365. This service has noticed suspicious activity. Some application with an IP address from the Microsoft stack gets access to employee mailboxes. The request is made on behalf of the employee to…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-06-06T17:25:56.09+00:00
Denys Pasternak 40 Reputation points
commented 2025-06-09T11:19:42.2566667+00:00
Denys Pasternak 40 Reputation points
1 answer

I want to change Microsoft Defender for Cloud Plan2 to Plan1 for cost saving

I want to change Microsoft Defender for Cloud Plan2 to plan1. If changes from plan2 to plan1 what is any impacts on server. What should i do, i want to install Defender for Server on on-premises servers.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-06-04T08:20:22.03+00:00
Zaw Myo Win 0 Reputation points
commented 2025-06-09T07:45:43.68+00:00
Gabriel-N 2,995 Reputation points Microsoft External Staff Moderator
1 answer

How to deactivate Microsoft Defender for Endpoint in Azure for a specific resource group?

Hello community, We are currently using Microsoft Defender for Servers – Plan 2 in Azure, which is active and enforced at the subscription level. We have a use case where we need to exclude or deactivate Defender for Endpoint (MDE) for a specific…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-04-30T15:16:33.4266667+00:00
Hotak, Mustafa 0 Reputation points
answered 2025-06-05T11:57:05.5133333+00:00
Catherine Kyalo 2,090 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Azure DevOps org doesn't get linked into Defender for Cloud via devops connector ( yes - i've followed all instructions + troubleshooting steps)

Hi, It seems that I've run into the issue where the Azure DevOps org doesn't get linked back into the Defender for Cloud: i checked all the pre-requisites on both sides of the setup - Azure DevOps and Defender for Cloud both apps show the correct…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-06-04T19:24:28.4266667+00:00
Mihai 20 Reputation points
accepted 2025-06-04T20:40:11.69+00:00
Mihai 20 Reputation points
1 answer

Azure Defender for Storage - RPC Method Call Failure and CloudException

Issue Description: When enabling Defender for Storage settings, specifically "on-upload malware scanning" and "sensitive data discovery," I receive the following errors: CloudException: "Plan enablement partially succeeded.…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-05-31T05:46:21.8866667+00:00
Iacono, Vito 6 Reputation points
commented 2025-06-04T14:22:54.9133333+00:00
Jose Benjamin Solis Nolasco 3,511 Reputation points
1 answer One of the answers was accepted by the question author.

How to deploy Microsoft Defender for a storage account with bicep

I'm trying to use bicep to enable Microsoft Defender for Cloud for a storage account in Azure. However, the defender is enabled but the "On-upload malware scanning" is not enabled even though I set the property to "true" in the bicep…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-04-03T13:26:14.27+00:00
Christopher Solum-Faeste 30 Reputation points
edited a comment 2025-06-04T09:04:33.87+00:00
Trent Richardson 0 Reputation points
1 answer

How to verify Microsoft Defender for DNS feature

How to validate Microsoft Defender for DNS feature on virtual machines ? Tried to validate as described here: https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/validating-microsoft-defender-for-dns-alerts/2227845 But I am not getting…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-05-22T23:49:29.76+00:00
Igor Chulkov 0 Reputation points
commented 2025-06-04T05:44:06.17+00:00
Catherine Kyalo 2,090 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

how to prevent Microsoft Defender for Cloud from being redeployed automatically after disabling plan

We have another antivirus installed and tried to disable Microsoft Defender on Azure VMs but it keeps getting redployed automatically. We turned off the defender plan yet still it comes back.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-05-23T18:41:40.7033333+00:00
Fencecore Azure Admin 20 Reputation points
accepted 2025-06-03T12:52:48.3033333+00:00
Fencecore Azure Admin 20 Reputation points
1 answer One of the answers was accepted by the question author.

A Microsoft Azure IP has suspicious activity reported on Defender for Cloud

Details about the situation include an Azure SQL Server database with a firewall allowing only three IPs and the option "Allow Azure services and resources to access this server" checked. An alert was received from Defender for Cloud indicating…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-05-29T15:54:35.7566667+00:00
Luis Alberto Oviedo Conrado 20 Reputation points
accepted 2025-05-30T17:22:24.3166667+00:00
Luis Alberto Oviedo Conrado 20 Reputation points
1 answer

How to fix vulnerability on Azure containe registry

Dear team We use Azure container apps which pull images from Azure container registry. Microsoft defender for cloud detect some vulnerabilities, for example ID = CVE-2024-56406 Package type = OS. Status: Unhealthy Vendor: Debian Installed version:…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Azure Container Apps
Azure Container Apps
An Azure service that provides a general-purpose, serverless container platform.
710 questions
asked 2025-05-28T04:59:43.3766667+00:00
Van Huy Tuyen 20 Reputation points
commented 2025-05-29T11:48:18.77+00:00
Khadeer Ali 5,990 Reputation points Microsoft External Staff Moderator
1 answer

Issues with MS Defender for Cloud Alerts Not Appearing on Security Portal

Experiencing an issue where alerts generated in Microsoft Defender for Cloud on portal.azure.com are not visible in the alerts section of the security.microsoft.com portal. Environment settings have been configured in Azure, all plans enabled for the…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-05-11T14:17:11.16+00:00
sparsh ladani 0 Reputation points
commented 2025-05-28T09:46:32.7466667+00:00
SrideviM 5,725 Reputation points Microsoft External Staff Moderator
1 answer One of the answers was accepted by the question author.

Tenant mismatch issue in Defender

Good Afternoon, We have an issue with Defender in servers onboarded with Azure Arc, the onboarded status is onboarded, antivirus is active, but the MDE Enrollment status is "Tenant mismatch". This happens only in some servers, others its MDE…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-05-27T10:06:24.45+00:00
Alejandro Miranda 60 Reputation points
accepted 2025-05-27T10:26:30.9933333+00:00
Alejandro Miranda 60 Reputation points