1,567 questions with Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud tags
the recommendation named “ Kubernetes clusters should disable automounting API credentials” does not provide the option to create an exemption.
the recommendation named “Kubernetes clusters should disable automounting API credentials” does not provide the option to create an exemption. How can we resolve this?
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
OpenSSL vulnerabilities in Defender for latest version Microsoft Products
My org has several OpenSSL vulnerabilities for OneDrive and Azure Disk Encryption. The CVEs are CVE-2024-4603, CVE-2024-4741, CVE-2024-5535, and Defender was said to fix inaccuracies with these last month (Sept. 2024).…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Resolving EDR Configuration Issues for Deleted Virtual Machines
Hi there, I am currently looking to improve secure score. One of the recommendation is to Enable Endpoint Protection which has a secondary recommendation as follows: "EDR configuration issues should be resolved on virtual machines". However,…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
False Positives on Attack Simulation Training - And how to cancel the training assigned to the user as a result of the false positive?
#1. Defender is reporting that users opened an attachment on an Attack Sumulation. Several users are claiming they did not open the attachment. We've been using Defender for a little over 2 years, and we used another tool prior for 5 years prior to…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
webhook enablement error
Hi, we have enabled to defender at blob storage level. We have assigned the eventgrid to capture the defender results in case of malware detection. We want to attach a webhook to eventgrid subscription to notify the malware errors in API. It throws error…
Azure Blob Storage
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
defender for cloud apps
HI team, need your help with the below. I am going through the documentation of defender for cloud app M365 and i found that in order to import and study the logs, we will need a firewall, proxy etcc and based on that we can discover the IT shadow…
Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Defender for cloud DevOps Security: Is it mandatory to have Github Advanced security enabled to find code vulnerabiltiy in azure devops repos
We are exploring the feature Microsoft Security DevOps and noticed there are no code vulnerability listed in the defender except Iac templates. As per the following table, is it a must have to enable Github Advanced Security to discover code or secret…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
What's the exact definition of 'Timegenerated' in an Azure Resource Graph query output for Container Image Vulnerabilities?
When we run a query to find vulnerabilities in Container Images, there's a 'timegenerated' column in the query output. I've tried to find this documented somewhere, but can't, I've only found a document for Azure Monitor. Does this mean it's the last…
Azure Monitor
Azure Container Registry
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
An unknown application will gain access to the user's mailbox on their behalf.
Hello, We use a third-party event analytics service in M365. This service has noticed suspicious activity. Some application with an IP address from the Microsoft stack gets access to employee mailboxes. The request is made on behalf of the employee to…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
I want to change Microsoft Defender for Cloud Plan2 to Plan1 for cost saving
I want to change Microsoft Defender for Cloud Plan2 to plan1. If changes from plan2 to plan1 what is any impacts on server. What should i do, i want to install Defender for Server on on-premises servers.
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
How to deactivate Microsoft Defender for Endpoint in Azure for a specific resource group?
Hello community, We are currently using Microsoft Defender for Servers – Plan 2 in Azure, which is active and enforced at the subscription level. We have a use case where we need to exclude or deactivate Defender for Endpoint (MDE) for a specific…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Azure DevOps org doesn't get linked into Defender for Cloud via devops connector ( yes - i've followed all instructions + troubleshooting steps)
Hi, It seems that I've run into the issue where the Azure DevOps org doesn't get linked back into the Defender for Cloud: i checked all the pre-requisites on both sides of the setup - Azure DevOps and Defender for Cloud both apps show the correct…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Azure Defender for Storage - RPC Method Call Failure and CloudException
Issue Description: When enabling Defender for Storage settings, specifically "on-upload malware scanning" and "sensitive data discovery," I receive the following errors: CloudException: "Plan enablement partially succeeded.…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud


How to deploy Microsoft Defender for a storage account with bicep
I'm trying to use bicep to enable Microsoft Defender for Cloud for a storage account in Azure. However, the defender is enabled but the "On-upload malware scanning" is not enabled even though I set the property to "true" in the bicep…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
How to verify Microsoft Defender for DNS feature
How to validate Microsoft Defender for DNS feature on virtual machines ? Tried to validate as described here: https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/validating-microsoft-defender-for-dns-alerts/2227845 But I am not getting…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
how to prevent Microsoft Defender for Cloud from being redeployed automatically after disabling plan
We have another antivirus installed and tried to disable Microsoft Defender on Azure VMs but it keeps getting redployed automatically. We turned off the defender plan yet still it comes back.
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
A Microsoft Azure IP has suspicious activity reported on Defender for Cloud
Details about the situation include an Azure SQL Server database with a firewall allowing only three IPs and the option "Allow Azure services and resources to access this server" checked. An alert was received from Defender for Cloud indicating…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
How to fix vulnerability on Azure containe registry
Dear team We use Azure container apps which pull images from Azure container registry. Microsoft defender for cloud detect some vulnerabilities, for example ID = CVE-2024-56406 Package type = OS. Status: Unhealthy Vendor: Debian Installed version:…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Azure Container Apps
Issues with MS Defender for Cloud Alerts Not Appearing on Security Portal
Experiencing an issue where alerts generated in Microsoft Defender for Cloud on portal.azure.com are not visible in the alerts section of the security.microsoft.com portal. Environment settings have been configured in Azure, all plans enabled for the…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Tenant mismatch issue in Defender
Good Afternoon, We have an issue with Defender in servers onboarded with Azure Arc, the onboarded status is onboarded, antivirus is active, but the MDE Enrollment status is "Tenant mismatch". This happens only in some servers, others its MDE…