Compartir a través de


Adaptive Application Controls - List

Obtiene una lista de grupos de máquinas de control de aplicaciones para la suscripción.

GET https://management.azure.com/subscriptions/{subscriptionId}/providers/Microsoft.Security/applicationWhitelistings?api-version=2020-01-01
GET https://management.azure.com/subscriptions/{subscriptionId}/providers/Microsoft.Security/applicationWhitelistings?api-version=2020-01-01&includePathRecommendations={includePathRecommendations}&summary={summary}

Parámetros de identificador URI

Nombre En Requerido Tipo Description
subscriptionId
path True

string

Identificador de suscripción de Azure

Regex pattern: ^[0-9A-Fa-f]{8}-([0-9A-Fa-f]{4}-){3}[0-9A-Fa-f]{12}$

api-version
query True

string

Versión de API para la operación

includePathRecommendations
query

boolean

Incluir las reglas de directiva

summary
query

boolean

Devolver la salida en un formulario resumido

Respuestas

Nombre Tipo Description
200 OK

AdaptiveApplicationControlGroups

Aceptar

Other Status Codes

CloudError

Respuesta de error que describe el motivo del error de la operación.

Seguridad

azure_auth

Flujo OAuth2 de Azure Active Directory

Type: oauth2
Flow: implicit
Authorization URL: https://login.microsoftonline.com/common/oauth2/authorize

Scopes

Nombre Description
user_impersonation suplantación de su cuenta de usuario

Ejemplos

Gets a list of application control groups of machines for the subscription

Sample Request

GET https://management.azure.com/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/applicationWhitelistings?api-version=2020-01-01&includePathRecommendations=True&summary=False

Sample Response

{
  "value": [
    {
      "id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/locations/centralus/applicationWhitelistings/AMIT-VA",
      "name": "AMIT-VA",
      "type": "Microsoft.Security/applicationWhitelistings",
      "location": "centralus",
      "properties": {
        "recommendationStatus": "Recommended",
        "enforcementMode": "Audit",
        "protectionMode": {
          "exe": "Audit",
          "msi": "Audit",
          "script": "None"
        },
        "vmRecommendations": [
          {
            "configurationStatus": "Configured",
            "resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/erelh-dsc/providers/microsoft.compute/virtualmachines/erelh-14011",
            "recommendationAction": "Recommended",
            "enforcementSupport": "Supported"
          },
          {
            "configurationStatus": "Configured",
            "resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/amit-va/providers/microsoft.compute/virtualmachines/ream-test",
            "recommendationAction": "Recommended",
            "enforcementSupport": "Supported"
          },
          {
            "configurationStatus": "Configured",
            "resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/v-arrikl-scheduledapps/providers/microsoft.compute/virtualmachines/v-arrikl-14060",
            "recommendationAction": "Recommended",
            "enforcementSupport": "Supported"
          }
        ],
        "pathRecommendations": [
          {
            "path": "C:\\Windows\\SoftwareDistribution\\Download\\Install\\Windows-KB890830-x64-V5.53-delta.exe",
            "type": "File",
            "common": true,
            "action": "Remove",
            "usernames": [
              {
                "username": "LOCAL SYSTEM",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-5-18"
            ],
            "fileType": "Exe",
            "configurationStatus": "NoStatus"
          },
          {
            "path": "C:\\WindowsAzure\\GuestAgent_2.7.1198.822\\CollectGuestLogs.exe",
            "type": "File",
            "common": true,
            "action": "Remove",
            "usernames": [
              {
                "username": "LOCAL SYSTEM",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-5-18"
            ],
            "fileType": "Exe",
            "configurationStatus": "NoStatus"
          },
          {
            "path": "C:\\Windows\\System32\\wbem\\WmiPrvSE.exe",
            "type": "PublisherSignature",
            "publisherInfo": {
              "publisherName": "O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US",
              "productName": "*",
              "binaryName": "*",
              "version": "0.0.0.0"
            },
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "Everyone",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-5-18",
              "S-1-1-0"
            ],
            "fileType": "Exe",
            "configurationStatus": "Configured"
          },
          {
            "path": "%OSDRIVE%\\WINDOWSAZURE\\SECAGENT\\WASECAGENTPROV.EXE",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "Everyone",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Exe",
            "configurationStatus": "Configured"
          }
        ],
        "configurationStatus": "Configured",
        "issues": [],
        "sourceSystem": "Azure_AppLocker"
      }
    },
    {
      "id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/locations/centralus/applicationWhitelistings/ERELGROUP1",
      "name": "ERELGROUP1",
      "type": "Microsoft.Security/applicationWhitelistings",
      "location": "centralus",
      "properties": {
        "recommendationStatus": "Recommended",
        "enforcementMode": "Audit",
        "protectionMode": {
          "exe": "Audit",
          "msi": "None",
          "script": "None"
        },
        "vmRecommendations": [
          {
            "configurationStatus": "Configured",
            "resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/erelh-stable/providers/microsoft.compute/virtualmachines/erelh-16090",
            "recommendationAction": "Recommended",
            "enforcementSupport": "NotSupported"
          }
        ],
        "pathRecommendations": [
          {
            "path": "[Exe] O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\\*\\*\\0.0.0.0",
            "type": "PublisherSignature",
            "publisherInfo": {
              "publisherName": "O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US",
              "productName": "*",
              "binaryName": "*",
              "version": "0.0.0.0"
            },
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "Everyone",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Exe",
            "configurationStatus": "Configured"
          }
        ],
        "configurationStatus": "Configured",
        "issues": [],
        "sourceSystem": "Azure_AppLocker"
      }
    },
    {
      "id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/locations/centralus/applicationWhitelistings/GROUP1",
      "name": "GROUP1",
      "type": "Microsoft.Security/applicationWhitelistings",
      "location": "centralus",
      "properties": {
        "recommendationStatus": "Recommended",
        "enforcementMode": "Audit",
        "protectionMode": {
          "exe": "Audit",
          "msi": "None",
          "script": "None"
        },
        "vmRecommendations": [
          {
            "configurationStatus": "Configured",
            "resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/talk-va/providers/microsoft.compute/virtualmachines/tal-win-vm",
            "recommendationAction": "Recommended",
            "enforcementSupport": "Supported"
          },
          {
            "configurationStatus": "Configured",
            "resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/talk-va/providers/microsoft.compute/virtualmachines/tal-win-vm-jit",
            "recommendationAction": "Recommended",
            "enforcementSupport": "Supported"
          },
          {
            "configurationStatus": "Configured",
            "resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/myresourcegroup/providers/microsoft.compute/virtualmachines/myvmweb",
            "recommendationAction": "Recommended",
            "enforcementSupport": "Supported"
          },
          {
            "configurationStatus": "Configured",
            "resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/v-arrikl-scheduledapps/providers/microsoft.compute/virtualmachines/v-arrikl-14061",
            "recommendationAction": "Recommended",
            "enforcementSupport": "Supported"
          }
        ],
        "pathRecommendations": [
          {
            "path": "[Exe] O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US\\*\\*\\0.0.0.0",
            "type": "PublisherSignature",
            "publisherInfo": {
              "publisherName": "O=MICROSOFT CORPORATION, L=REDMOND, S=WASHINGTON, C=US",
              "productName": "*",
              "binaryName": "*",
              "version": "0.0.0.0"
            },
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "Everyone",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Exe",
            "configurationStatus": "Configured"
          },
          {
            "path": "%OSDRIVE%\\WINDOWSAZURE\\SECAGENT\\WASECAGENTPROV.EXE",
            "type": "ProductSignature",
            "publisherInfo": {
              "publisherName": "CN=MICROSOFT AZURE DEPENDENCY CODE SIGN",
              "productName": "MICROSOFT® COREXT",
              "binaryName": "*",
              "version": "0.0.0.0"
            },
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "NT AUTHORITY\\SYSTEM",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Exe",
            "configurationStatus": "Configured"
          },
          {
            "path": "%PROGRAMFILES%\\RAPID7\\INSIGHT AGENT\\COMPONENTS\\INSIGHT_AGENT\\2.6.7.9\\GET_PROXY.EXE",
            "type": "PublisherSignature",
            "publisherInfo": {
              "publisherName": "O=RAPID7 LLC, L=BOSTON, S=MASSACHUSETTS, C=US",
              "productName": "*",
              "binaryName": "*",
              "version": "0.0.0.0"
            },
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "NT AUTHORITY\\SYSTEM",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Exe",
            "configurationStatus": "Configured"
          },
          {
            "path": "%PROGRAMFILES%\\GOOGLE\\CHROME\\APPLICATION\\CHROME.EXE",
            "type": "ProductSignature",
            "publisherInfo": {
              "publisherName": "O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US",
              "productName": "GOOGLE CHROME",
              "binaryName": "*",
              "version": "0.0.0.0"
            },
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "NT AUTHORITY\\SYSTEM",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Exe",
            "configurationStatus": "Configured"
          },
          {
            "path": "O=GOOGLE INC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US\\GOOGLE UPDATE\\*\\0.0.0.0",
            "type": "ProductSignature",
            "publisherInfo": {
              "publisherName": "O=GOOGLE INC, L=MOUNTAIN VIEW, S=CALIFORNIA, C=US",
              "productName": "GOOGLE UPDATE",
              "binaryName": "*",
              "version": "0.0.0.0"
            },
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "NT AUTHORITY\\SYSTEM",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Exe",
            "configurationStatus": "Configured"
          }
        ],
        "configurationStatus": "Configured",
        "issues": [],
        "sourceSystem": "Azure_AppLocker"
      }
    },
    {
      "id": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/providers/Microsoft.Security/locations/westeurope/applicationWhitelistings/GROUP1",
      "name": "GROUP1",
      "type": "Microsoft.Security/applicationWhitelistings",
      "location": "westeurope",
      "properties": {
        "recommendationStatus": "Recommended",
        "enforcementMode": "Audit",
        "protectionMode": {
          "executable": "Audit"
        },
        "vmRecommendations": [
          {
            "configurationStatus": "Configured",
            "resourceId": "/subscriptions/20ff7fc3-e762-44dd-bd96-b71116dcdc23/resourcegroups/nic-no-pip/providers/microsoft.compute/virtualmachines/nic-no-pip-vm",
            "recommendationAction": "Recommended",
            "enforcementSupport": "Unknown"
          }
        ],
        "pathRecommendations": [
          {
            "path": "/sbin/init",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/sbin/upstart-udev-bridge",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/lib/systemd/systemd-udevd",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/sbin/upstart-socket-bridge",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/sbin/dhclient",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/bin/python3.4",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/sbin/upstart-file-bridge",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/bin/dbus-daemon",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "messagebus",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/lib/systemd/systemd-logind",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/sbin/getty",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/sbin/atd",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/sbin/cron",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/sbin/acpid",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/sbin/sshd",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/lib/linux-lts-xenial-tools-4.4.0-103/hv_vss_daemon",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/lib/linux-lts-xenial-tools-4.4.0-103/hv_kvp_daemon",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/sbin/nscd",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "unscd",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/sbin/ntpd",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "ntp",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/opt/microsoft/auoms/bin/auomscollect",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/opt/omi/bin/omiserver",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/opt/omi/bin/omiengine",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "omi",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/opt/omi/bin/omiagent",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/sbin/rsyslogd",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "syslog",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/bin/python2.7",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              },
              {
                "username": "omsagent",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/opt/microsoft/omsagent/ruby/bin/ruby",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "omsagent",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/opt/microsoft/auoms/bin/auoms",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/bin/dash",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "omsagent",
                "recommendationAction": "Recommended"
              },
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/bin/sleep",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "omsagent",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/opt/dsc/bin/dsc_host",
            "type": "File",
            "common": false,
            "action": "Recommended",
            "usernames": [
              {
                "username": "omsagent",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/bin/sudo",
            "type": "File",
            "common": false,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/bin/bash",
            "type": "File",
            "common": false,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/bin/apt-get",
            "type": "File",
            "common": false,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/lib/apt/methods/http",
            "type": "File",
            "common": false,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/lib/apt/methods/gpgv",
            "type": "File",
            "common": false,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/lib/apt/methods/copy",
            "type": "File",
            "common": false,
            "action": "Recommended",
            "usernames": [
              {
                "username": "root",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/usr/bin/pgrep",
            "type": "File",
            "common": true,
            "action": "Recommended",
            "usernames": [
              {
                "username": "omsagent",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          },
          {
            "path": "/opt/microsoft/omsconfig/bin/omsconsistencyinvoker",
            "type": "File",
            "common": false,
            "action": "Recommended",
            "usernames": [
              {
                "username": "omsagent",
                "recommendationAction": "Recommended"
              }
            ],
            "userSids": [
              "S-1-1-0"
            ],
            "fileType": "Executable",
            "configurationStatus": "Configured"
          }
        ],
        "configurationStatus": "Configured",
        "issues": [
          {
            "issue": "ExecutableViolationsAudited",
            "numberOfVms": 1
          }
        ],
        "sourceSystem": "Azure_AuditD"
      }
    }
  ]
}

Definiciones

Nombre Description
AdaptiveApplicationControlGroup
AdaptiveApplicationControlGroups

Representa una lista de grupos de máquinas virtuales o servidores y un conjunto de reglas recomendados por Microsoft Defender para que se permita la nube.

AdaptiveApplicationControlIssue

Una alerta que las máquinas de un grupo pueden tener

AdaptiveApplicationControlIssueSummary

Representa un resumen de las alertas del grupo de máquinas.

CloudError

Respuesta de error común para todas las API de Azure Resource Manager para devolver los detalles de error de las operaciones con errores. (Esto también sigue el formato de respuesta de error de OData).

CloudErrorBody

Detalle del error.

ConfigurationStatus

Estado de configuración del grupo o regla de máquinas

EnforcementMode

El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas

EnforcementSupport

La compatibilidad de la máquina con la característica Aplicar

ErrorAdditionalInfo

Información adicional sobre el error de administración de recursos.

FileType

Tipo del archivo (para archivos linux: se usa ejecutable)

PathRecommendation

Representa una ruta de acceso que se recomienda permitir y sus propiedades.

ProtectionMode

Modo de protección de los tipos de colección o archivo. Exe/Msi/Script se usan para Windows, el ejecutable se usa para Linux.

PublisherInfo

Representa la información del publicador de un proceso o regla.

RecommendationAction

Acción de recomendación de la máquina o regla

RecommendationStatus

El estado de recomendación inicial del grupo de máquinas o la máquina

RecommendationType

Tipo de la regla que se va a permitir

SourceSystem

El tipo de origen del grupo de máquinas

UserRecommendation

Representa un usuario que se recomienda permitir para una regla determinada.

VmRecommendation

Representa una máquina que forma parte de un grupo de máquinas.

AdaptiveApplicationControlGroup

Nombre Tipo Description
id

string

Id. de recurso

location

string

Ubicación donde se almacena el recurso

name

string

Nombre del recurso

properties.configurationStatus

ConfigurationStatus

Estado de configuración del grupo o regla de máquinas

properties.enforcementMode

EnforcementMode

El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas

properties.issues

AdaptiveApplicationControlIssueSummary[]

Representa un resumen de las alertas del grupo de máquinas.

properties.pathRecommendations

PathRecommendation[]

Representa una ruta de acceso que se recomienda permitir y sus propiedades.

properties.protectionMode

ProtectionMode

Modo de protección de los tipos de colección o archivo. Exe/Msi/Script se usan para Windows, el ejecutable se usa para Linux.

properties.recommendationStatus

RecommendationStatus

El estado de recomendación inicial del grupo de máquinas o la máquina

properties.sourceSystem

SourceSystem

El tipo de origen del grupo de máquinas

properties.vmRecommendations

VmRecommendation[]

Representa una máquina que forma parte de un grupo de máquinas.

type

string

Tipo de recurso

AdaptiveApplicationControlGroups

Representa una lista de grupos de máquinas virtuales o servidores y un conjunto de reglas recomendados por Microsoft Defender para que se permita la nube.

Nombre Tipo Description
value

AdaptiveApplicationControlGroup[]

AdaptiveApplicationControlIssue

Una alerta que las máquinas de un grupo pueden tener

Nombre Tipo Description
ExecutableViolationsAudited

string

MsiAndScriptViolationsAudited

string

MsiAndScriptViolationsBlocked

string

RulesViolatedManually

string

ViolationsAudited

string

ViolationsBlocked

string

AdaptiveApplicationControlIssueSummary

Representa un resumen de las alertas del grupo de máquinas.

Nombre Tipo Description
issue

AdaptiveApplicationControlIssue

Una alerta que las máquinas de un grupo pueden tener

numberOfVms

number

Número de máquinas del grupo que tienen esta alerta

CloudError

Respuesta de error común para todas las API de Azure Resource Manager para devolver los detalles de error de las operaciones con errores. (Esto también sigue el formato de respuesta de error de OData).

Nombre Tipo Description
error.additionalInfo

ErrorAdditionalInfo[]

Información adicional del error.

error.code

string

Código de error.

error.details

CloudErrorBody[]

Los detalles del error.

error.message

string

El mensaje de error.

error.target

string

Destino del error.

CloudErrorBody

Detalle del error.

Nombre Tipo Description
additionalInfo

ErrorAdditionalInfo[]

Información adicional del error.

code

string

Código de error.

details

CloudErrorBody[]

Los detalles del error.

message

string

El mensaje de error.

target

string

Destino del error.

ConfigurationStatus

Estado de configuración del grupo o regla de máquinas

Nombre Tipo Description
Configured

string

Failed

string

InProgress

string

NoStatus

string

NotConfigured

string

EnforcementMode

El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas

Nombre Tipo Description
Audit

string

Enforce

string

None

string

EnforcementSupport

La compatibilidad de la máquina con la característica Aplicar

Nombre Tipo Description
NotSupported

string

Supported

string

Unknown

string

ErrorAdditionalInfo

Información adicional sobre el error de administración de recursos.

Nombre Tipo Description
info

object

Información adicional.

type

string

Tipo de información adicional.

FileType

Tipo del archivo (para archivos linux: se usa ejecutable)

Nombre Tipo Description
Dll

string

Exe

string

Executable

string

Msi

string

Script

string

Unknown

string

PathRecommendation

Representa una ruta de acceso que se recomienda permitir y sus propiedades.

Nombre Tipo Description
action

RecommendationAction

Acción de recomendación de la máquina o regla

common

boolean

Si la aplicación se ejecuta normalmente en el equipo

configurationStatus

ConfigurationStatus

Estado de configuración del grupo o regla de máquinas

fileType

FileType

Tipo del archivo (para archivos linux: se usa ejecutable)

path

string

Ruta de acceso completa del archivo o un identificador de la aplicación

publisherInfo

PublisherInfo

Representa la información del publicador de un proceso o regla.

type

RecommendationType

Tipo de la regla que se va a permitir

userSids

string[]

Un identificador de seguridad

usernames

UserRecommendation[]

Representa un usuario que se recomienda permitir para una regla determinada.

ProtectionMode

Modo de protección de los tipos de colección o archivo. Exe/Msi/Script se usan para Windows, el ejecutable se usa para Linux.

Nombre Tipo Description
exe

EnforcementMode

El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas

executable

EnforcementMode

El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas

msi

EnforcementMode

El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas

script

EnforcementMode

El modo de cumplimiento y protección de directivas de control de aplicaciones del grupo de máquinas

PublisherInfo

Representa la información del publicador de un proceso o regla.

Nombre Tipo Description
binaryName

string

Campo "OriginalName" tomado del recurso de versión del archivo

productName

string

Nombre del producto tomado del recurso de versión del archivo

publisherName

string

Campo Asunto del certificado x.509 usado para firmar el código, con los siguientes campos: O = Organización, L = Localidad, S = Estado o Provincia y C = País

version

string

La versión del archivo binario tomada del recurso de versión del archivo

RecommendationAction

Acción de recomendación de la máquina o regla

Nombre Tipo Description
Add

string

Recommended

string

Remove

string

RecommendationStatus

El estado de recomendación inicial del grupo de máquinas o la máquina

Nombre Tipo Description
NoStatus

string

NotAvailable

string

NotRecommended

string

Recommended

string

RecommendationType

Tipo de la regla que se va a permitir

Nombre Tipo Description
BinarySignature

string

File

string

FileHash

string

ProductSignature

string

PublisherSignature

string

VersionAndAboveSignature

string

SourceSystem

El tipo de origen del grupo de máquinas

Nombre Tipo Description
Azure_AppLocker

string

Azure_AuditD

string

NonAzure_AppLocker

string

NonAzure_AuditD

string

None

string

UserRecommendation

Representa un usuario que se recomienda permitir para una regla determinada.

Nombre Tipo Description
recommendationAction

RecommendationAction

Acción de recomendación de la máquina o regla

username

string

Representa un usuario que se recomienda permitir para una regla determinada.

VmRecommendation

Representa una máquina que forma parte de un grupo de máquinas.

Nombre Tipo Description
configurationStatus

ConfigurationStatus

Estado de configuración del grupo o regla de máquinas

enforcementSupport

EnforcementSupport

La compatibilidad de la máquina con la característica Aplicar

recommendationAction

RecommendationAction

Acción de recomendación de la máquina o regla

resourceId

string

El identificador de recurso completo de la máquina