1,578 questions with Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

What's "DC only" in Secure recommendation mean?

Hi everyone, When the secure score recommendation has these words "(DC only)", does it mean this only applies to VM that's part of a domain controller? An example of a recommendation: N4W7B6 Ensure 'Audit Distribution Group Management' is…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-08-02T03:00:14.8133333+00:00
Tan-9136 120 Reputation points
commented 2025-08-12T01:26:35.9666667+00:00
Tan-9136 120 Reputation points
0 answers

Enable Microsoft Defender for Cloud Only for Production Resources – Other Plans Should Remain Off

Hello, I'm managing a subscription under Azure subscription 1 and I want to enable Microsoft Defender for Cloud ONLY for production resources (resource group: yell-production-resources). All other environments (dev, qa, staging, etc.) should remain…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-07-31T21:00:18.3866667+00:00
Christopher Cheetham 0 Reputation points
commented 2025-08-11T18:10:48.2666667+00:00
Raja Pothuraju 29,245 Reputation points Microsoft External Staff Moderator
1 answer One of the answers was accepted by the question author.

Is the ppc64le Architecture is supported by MDATP?

I am currently using SUSE Linux Enterprise 15.2 with a ppc64le (PowerPC 64-bit Little Endian) system architecture. While attempting to install Microsoft Defender for Endpoint (MDATP), I encountered the following error: No provider of 'mdatp' found. Could…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-08-04T12:40:40.3333333+00:00
chirag darji 156 Reputation points
commented 2025-08-11T08:14:48.5533333+00:00
chirag darji 156 Reputation points
1 answer

Defender for Cloud - "Machines should have vulnerability findings resolved" Stopped Populating

I perform weekly reviews of Microsoft Defender for Cloud's "Recommendations" and have noticed that in the past several weeks, we have not had any findings under the item "Machines should have vulnerability findings resolved". There…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-08-05T18:04:31.8433333+00:00
Cusimano, Joey 80 Reputation points
edited a comment 2025-08-08T14:11:00.26+00:00
Catherine Kyalo 2,100 Reputation points Microsoft Employee
2 answers

Defender for cloud scans aren't running for windows servers

images.pdf Using defender for cloud to scan for package and other vulnerabilities on our Azure VM (see environment settings in attached screenshot). Our VMs are only on when in use (about 8 hours a day). All VM's have the recommendation "machines…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-07-08T23:03:03.8333333+00:00
Nishant R V (Perimatics) 0 Reputation points
answered 2025-08-08T13:33:49.8466667+00:00
Catherine Kyalo 2,100 Reputation points Microsoft Employee
1 answer

Logic App Workflow Automation Not Triggering for Security Alerts

I have set up a Logic App to trigger workflow automation for security alerts on Microsoft Defender. However, it is not triggering automatically, even after simulating security alerts on the storage account. I can trigger the alerts manually, and I…

Azure Storage
Azure Storage
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,591 questions
Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
3,589 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-01-05T21:52:46.64+00:00
Mike Ter 15 Reputation points
commented 2025-08-07T10:17:28.5566667+00:00
jaseruk 0 Reputation points
1 answer

Need to offboard the Windows Defender from Windows Servers

hello all, In our organization we have a S1 agent installed on the Windows servers running on Azure, therefore I need to uninstall the Microsoft defender completely from the servers, but even after remove the role for Windows Defender the services…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Windows for business | Windows Server | User experience | Other
asked 2025-01-28T07:43:17.5966667+00:00
agarwal utkarsh (Contractor) 0 Reputation points
edited an answer 2025-08-07T07:30:44.9+00:00
VarunTha 14,860 Reputation points Microsoft External Staff Moderator
1 answer

Microsoft Defender for Cloud Plan for Azure Servers

Hi, currently we have the basic Foundational CSPM MS Defender for Cloud plan enabled and also Defender CSPM. We would like to enable the Cloud Workload Protection (CWP) plan 2 for our Azure servers that costs around $15/Server/month. We have around 50…

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,712 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-07-19T15:01:45.25+00:00
Ghulam Abbas 211 Reputation points
answered 2025-08-07T07:19:28.55+00:00
Catherine Kyalo 2,100 Reputation points Microsoft Employee
1 answer

Issues with MS Defender for Cloud Alerts Not Appearing on Security Portal

Experiencing an issue where alerts generated in Microsoft Defender for Cloud on portal.azure.com are not visible in the alerts section of the security.microsoft.com portal. Environment settings have been configured in Azure, all plans enabled for the…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-05-11T14:17:11.16+00:00
sparsh ladani 0 Reputation points
commented 2025-08-06T05:33:00.2333333+00:00
Jonathan Benjamin 0 Reputation points
1 answer One of the answers was accepted by the question author.

KQL using SecurityResources needs to return Last Scan time of the AZ SQL database not of the host

I have a KQL query attached that returns the ScanTime but it is not the scan time for the database. It appears to be the scan time for something else ( returns Aug 2 when the database UI shows 7/31). Q: How to change my KQL query to return the scan…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-08-04T16:22:41.4233333+00:00
Nguyen, Hoa 421 Reputation points
commented 2025-08-05T15:35:45.0533333+00:00
Nguyen, Hoa 421 Reputation points
2 answers

When ISO27001:2022 will be available for Defender regulatory compliance security framework

We have to add ISO270001:2022 framework in regulatory compliance in Defender for Cloud. However i am only able to see ISO27001:2013 Could you please confirm when 2022 will be available

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2023-08-07T03:03:19.2833333+00:00
Rakesh Kumar 15 Reputation points
commented 2025-08-05T11:45:57.5333333+00:00
Lucas Kuiper 5 Reputation points
2 answers One of the answers was accepted by the question author.

Inquiry About Security Score Standards in Microsoft Defender for Cloud

Hello, I am currently supporting the operation of Microsoft Defender for Cloud. I have a question regarding the security score in Microsoft Defender for Cloud. While I understand that a higher security score indicates a safer cloud environment, I…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-11-28T06:57:36.65+00:00
용현 정 105 Reputation points
edited a comment 2025-08-04T03:22:41.81+00:00
Pradeep M 9,785 Reputation points Microsoft External Staff Moderator
11 answers

OpenSSL vulnerabilities showing in Defender Dashboard

We have multiple devices showing up with OpenSSL vulnerabilities. It is detecting two dll files that it is flagging. Which they are libssl-3-x64.dll and libcrypto-3-x64.dll. It is flagging this for multiple different applications through out multiple…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
asked 2023-09-22T20:14:57.2433333+00:00
Jeff Thorne 65 Reputation points
edited an answer 2025-08-01T05:50:13.5066667+00:00
RNareddy 2,505 Reputation points Microsoft External Staff Moderator
1 answer

query to associate the department with an MDC recommendation

How can I update the following query to associate the department with each MDC recommendation? securityresources | where type == "microsoft.security/assessments" | extend source = trim(' ',…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-03-21T15:33:25.52+00:00
Yue Ma 40 Reputation points
edited a comment 2025-07-31T11:01:24.3966667+00:00
RNareddy 2,505 Reputation points Microsoft External Staff Moderator
3 answers

Understanding why full and quick scans are out of 7 days

Hi, We have been receiving security recommendations for our virtual machines, and one of the findings states that "Both full and quick scans are out of 7 days": EDR configuration issues should be resolved on virtual machines-> Findings->…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-06-06T12:05:36.9366667+00:00
Quattrocchi, Calogero 275 Reputation points
edited an answer 2025-08-02T07:30:36.5733333+00:00
VarunTha 14,860 Reputation points Microsoft External Staff Moderator
4 answers

Issue with Defender Recommendations - Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost.

HI i have 3 virtual machines in azure i have enabled one week back Encryption at host for all machines - Now am seeing - Recommendations - Virtual machines and virtual machine scale sets should have encryption at host enabled is now in healthy…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
9,207 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-06-15T08:00:35.97+00:00
Kuldeep Singh(OT) 75 Reputation points
edited an answer 2025-08-02T07:48:41.5666667+00:00
VarunTha 14,860 Reputation points Microsoft External Staff Moderator
1 answer

Security alerts email notifications

I have enabled Microsoft Defender for Cloud antimalware protection on a single storage account. Upon uploading an EICAR file I see security alerts with severity High are created, but I'm not getting any email notifications about them despite doing the…

Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
3,226 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-08-23T05:05:09.8566667+00:00
metalheart 411 Reputation points
edited a comment 2025-08-03T07:53:04.7566667+00:00
VarunTha 14,860 Reputation points Microsoft External Staff Moderator
2 answers

OpenSSL Vulnerability Shown on Microsoft Defender for Cloud Dashboard - OneDrive affected app

An OpenSSL vulnerability has been flagged on one of our devices by Microsoft Defender for Cloud. The vulnerability has listed two dll files as the main culprits (both installed via OneDrive): libcrypto-3-x64.dll libssl-3-x64.dll The OneDrive version…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2024-10-31T12:38:50.5166667+00:00
Eric Wasike 75 Reputation points
answered 2025-08-01T14:00:18.26+00:00
CyberSecTech 0 Reputation points
2 answers

Minimum permission/right to Assign owner to MS Defender issue

I want to create a 'custom' role with the minimum permissions/rights to enable the ability to ....... Assign owner and set due date by which recommendation should be implemented in MS Defender So i can assign an administrator with limited technical…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-07-22T09:59:17.1266667+00:00
Stratfull, Russ (EC) 0 Reputation points
edited an answer 2025-07-31T10:33:30.7966667+00:00
Stratfull, Russ (EC) 0 Reputation points
0 answers

Azure VM with high severity vulnerabilities allows lateral movement to

Hi, I have multiple virtual machines and I gave access to those machines to other resources like storage account, Azure KeY vault but in every morning I get "Azure VM with high severity vulnerabilities allows lateral movement to..." with…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-07-24T06:13:49.5066667+00:00
Bogdan Eremia 45 Reputation points
commented 2025-08-01T12:19:04.2833333+00:00
Raja Pothuraju 29,245 Reputation points Microsoft External Staff Moderator