86,766 questions with Microsoft Security-related tags

Sort by: Updated
0 answers

URGENT – Sole Global Administrator locked out – MFA reset / Tenant Recovery required

I am the sole Global Administrator of my Microsoft 365 Business tenant bibous.onmicrosoft.com. My administrator account is ******@bibous.onmicrosoft.com. I know my username and password, but I cannot complete MFA because my Microsoft Authenticator…

Microsoft Security | Microsoft Authenticator
asked 2026-09-15T10:03:24.2+00:00
Matheo 0 Reputation points
0 answers

Account has been hacked, we do not recognize recovery adress and hacker inserted 2 factors verification

My husband has registered Microsoft account via Gmail. It has been hacked and we are unable to access it anymore. The hacker inserted some recovery email which we do not recognize and activated 2 factors verification. Is there any chance to recover it?…

Microsoft Security | Microsoft Authenticator
asked 2026-09-15T09:38:10.63+00:00
Ivana Aleksic 0 Reputation points
1 answer

MDC Vulnerability Assessment Findings Workbook Not Displaying Vulnerabilities While Findings Are Visible Under VM Recommendations

Hello, We are facing an issue in Microsoft Defender for Cloud (MDC) regarding the "Vulnerability Assessment Findings" workbook. The workbook is not displaying any vulnerability findings and appears to be empty. However, when we navigate to a…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2026-08-12T12:00:15.76+00:00
Ekta Jitendra Singh 0 Reputation points
answered 2026-09-15T09:25:45.0566667+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
1 answer

Microsoft Defender for Cloud Secure Score Not Updating Despite Recommendations Showing Completed

Issue Summary We are observing an inconsistency in Microsoft Defender for Cloud Secure Score calculations. Multiple recommendations are showing a status of "Completed"; however, the overall Secure Score is not improving as expected. In…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2026-08-18T11:08:19.1066667+00:00
Sumanth Myakala 10 Reputation points Microsoft External Staff
answered 2026-09-15T09:24:17.4133333+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
1 answer

StorageDataScanner remains after Defender for Storage malware scanning is disabled — what is the supported cleanup?

Context I ran a bounded, resource-level Defender for Storage malware-scanning experiment against one Development/PoC Storage account in France Central. The account allows selected networks rather than unrestricted public access. No Production environment…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2026-08-23T12:58:31.5133333+00:00
Mr. Who 0 Reputation points
answered 2026-09-15T09:23:57.1766667+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
1 answer

Microsoft Sentinel is enabled on Sentinel-Lab-Workspace, but Defender portal does not expose Microsoft Sentinel

Microsoft Sentinel is enabled on Sentinel-Lab-Workspace, but the Defender portal does not expose Microsoft Sentinel or the Connect workspace option. The direct Sentinel settings URL returns “You don’t have permission.” The administrator has Global…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2026-08-22T21:11:44.5933333+00:00
meherzad javed 5 Reputation points
answered 2026-09-15T09:22:23.5733333+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
1 answer

Azure Workbook

Hi i have an issue i am enountering. I am tryingto have different ysplit panels in azure but i cant. I used he render qquery but it is like ignore when running. Here is my query let SHO_CPU = Perf | where Computer in (dynamic([{WVDHosts}])) | where…

Microsoft Security | Microsoft Sentinel
asked 2026-08-28T09:32:49.8266667+00:00
edited an answer 2026-09-15T09:18:49.8133333+00:00
1 answer

Vulnerability assessment / Missing findings for images running on AKS clusters

Running-container vulnerability assessment stopped producing findings for all of our AKS clusters between the afternoon of Wednesday 08/12 and Thursday 08/13. Registry (container image) vulnerability assessment continues to work normally, but the…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2026-08-17T18:55:27.88+00:00
Mat Thomas 6 Reputation points
answered 2026-09-15T09:15:01.7433333+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
1 answer

Microsoft Sentinel: Loading Data Issues in Defender Portal — Ongoing Investigation

Problem description I am experiencing issues accessing Microsoft Sentinel features through the Defender portal. Since September 3, 2026, all Sentinel features such as Content Hub, Analytics, Automation, Logs, and Hunting immediately redirect back to the…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2026-09-04T01:26:00.0266667+00:00
kristich-5860 5 Reputation points
answered 2026-09-15T09:13:59.3566667+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
0 answers

Defender for Endpoint - RBAC group filter not working on export APIs

Hi team, We're ingesting vulnerability/asset data from Defender for Endpoint for a single tenant segmented into multiple RBAC device groups (one group per business unit). We're attempting to filter by RBAC group ID/name, but the assessment export APIs…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2026-09-02T17:54:57.63+00:00
Berlin Russel 0 Reputation points
1 answer

Defender for Cloud: Exemptions Not Persisting After Deletion — Reappear After Some Time

I need this escalated to a human engineer with product knowledge of Microsoft Defender for Cloud and the Security Resource Provider specifically. The case summary I received does not reflect the diagnostic work already carried out, and I do not want…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2026-09-10T10:54:14.96+00:00
Andy Gibson - Admin 0 Reputation points
answered 2026-09-15T09:10:51.2766667+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
0 answers

Defender for Storage emits Microsoft.Security.MalwareScanningResult with undocumented dataVersion: "1.1"

We are implementing Microsoft Defender for Storage on-upload malware scanning with scan results delivered through Event Grid to an Entra-authenticated webhook. The integration is working through authentication: genuine…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2026-09-03T16:57:30.1833333+00:00
Stuart McAllister 0 Reputation points
commented 2026-09-15T09:08:32.7466667+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
1 answer

Is it possible to provision identities to multiple on-prem apps with one SCIM agent?

Let's assume the scenario, where organization has 5 instances of the same app installed in the kubernetes cluster, each for different department. The Identities are provisioned from Entra ID Apps dedicated to each on-prem aplication instance thru…

Microsoft Security | Microsoft Entra | Microsoft Entra ID
asked 2026-09-15T07:17:35.1133333+00:00
Jacek Guzek 0 Reputation points
answered 2026-09-15T09:05:01.1833333+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
1 answer

Governance relationships can't co-exist with pre-configured GDAP admin relationship

I operate for an MSSP, we are CSP as well. Below is our setup - We have GDAP setup for our clients to support their 365 services. We have Azure lighthouse to centrally manage their subscriptions. Microsoft announced last year that Sentinel is going…

Microsoft Security | Microsoft Sentinel
asked 2026-08-13T09:19:57.15+00:00
Khanna, Keshav 20 Reputation points
answered 2026-09-15T09:03:10.4166667+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
1 answer

Defender Unified RBAC also shows “Failed to load workspace data.”

I have a Microsoft Sentinel workspace connected to Defender XDR as Primary, but Advanced Hunting does not show any Sentinel workspace tables in Schema. workspace('<WorkspaceID>').<Table> is unavailable, while Azure Portal Sentinel/Log…

Microsoft Security | Microsoft Sentinel
asked 2026-09-10T15:18:51.77+00:00
Abdulrhman Abbad 0 Reputation points
answered 2026-09-15T09:01:02.1166667+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
1 answer

Sentinel: Creating Alerts for Windows Update Compliance in GCC Environment — No Data Ingestion

Problem description I am trying to create an alert in Microsoft Sentinel for Windows Update compliance below 90%, but no data is being ingested into Sentinel despite enabling Windows Update for Business reports over a week ago. Environment Microsoft…

Microsoft Security | Microsoft Sentinel
asked 2026-09-11T18:15:32.3266667+00:00
Adam Ring JIT 0 Reputation points
answered 2026-09-15T08:59:31.8833333+00:00
Konstantinos Lianos 905 Reputation points Student Ambassador
2 answers

My account was hacked and compromised. Please help!

Just 2 days ago my microsoft account was hacked. I suddenly recieved an email on microsoft saying that my security information has been changed. I clicked on review and it took me to a page where I input my microsoft email but when I put it in, it said…

Microsoft Security | Microsoft Authenticator
asked 2026-02-13T09:56:08.4666667+00:00
Allen Minami 5 Reputation points
commented 2026-09-15T07:45:54.3966667+00:00
Kion Miklósi-Yuan 0 Reputation points
0 answers

Sole global admin locked out by MFA (Authenticator on a lost device, no backup methods) - requesting tenant recovery

I am the sole global administrator of my Microsoft 365 tenant and I can no longer sign in. I would like to be pointed to the correct admin account recovery path. What happened: I replaced my phone. The old device is gone, so nothing could be transferred.…

Microsoft Security | Microsoft Entra | Microsoft Entra ID
asked 2026-09-15T07:44:29.7666667+00:00
1 answer One of the answers was accepted by the question author.

Azure Portal Displays Blank Page When Accessing Provisioning Module in AWS SSO Enterprise Application

We are experiencing an issue in the Azure Portal where the Provisioning module within the AWS SSO Enterprise Application fails to load. When navigating to: Azure Portal → Enterprise Applications → AWS SSO → Provisioning …the portal returns a blank page…

Microsoft Security | Microsoft Entra | Microsoft Entra ID
asked 2026-02-02T11:33:34.4133333+00:00
commented 2026-09-15T07:08:10.4033333+00:00
Anant Bhat 0 Reputation points
0 answers

AADSTS500207 "The account type can't be used for the resource you're trying to access" — Credential Management API, External ID (CIAM) tenant

Goal: I'm setting up Passkey (FIDO2) support for customer sign-in on a Power Pages portal, using Microsoft Entra External ID (CIAM) as the identity provider. Current authentication is email + password as the primary method, with email one-time passcode…

Microsoft Security | Microsoft Entra | Microsoft Entra External ID
asked 2026-09-15T03:46:19.2433333+00:00
Ella Oducado 0 Reputation points