1,578 questions with Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud tags
What's "DC only" in Secure recommendation mean?
Hi everyone, When the secure score recommendation has these words "(DC only)", does it mean this only applies to VM that's part of a domain controller? An example of a recommendation: N4W7B6 Ensure 'Audit Distribution Group Management' is…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Enable Microsoft Defender for Cloud Only for Production Resources – Other Plans Should Remain Off
Hello, I'm managing a subscription under Azure subscription 1 and I want to enable Microsoft Defender for Cloud ONLY for production resources (resource group: yell-production-resources). All other environments (dev, qa, staging, etc.) should remain…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud

Is the ppc64le Architecture is supported by MDATP?
I am currently using SUSE Linux Enterprise 15.2 with a ppc64le (PowerPC 64-bit Little Endian) system architecture. While attempting to install Microsoft Defender for Endpoint (MDATP), I encountered the following error: No provider of 'mdatp' found. Could…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Defender for Cloud - "Machines should have vulnerability findings resolved" Stopped Populating
I perform weekly reviews of Microsoft Defender for Cloud's "Recommendations" and have noticed that in the past several weeks, we have not had any findings under the item "Machines should have vulnerability findings resolved". There…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Defender for cloud scans aren't running for windows servers
images.pdf Using defender for cloud to scan for package and other vulnerabilities on our Azure VM (see environment settings in attached screenshot). Our VMs are only on when in use (about 8 hours a day). All VM's have the recommendation "machines…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Logic App Workflow Automation Not Triggering for Security Alerts
I have set up a Logic App to trigger workflow automation for security alerts on Microsoft Defender. However, it is not triggering automatically, even after simulating security alerts on the storage account. I can trigger the alerts manually, and I…
Azure Storage
Azure Logic Apps
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Need to offboard the Windows Defender from Windows Servers
hello all, In our organization we have a S1 agent installed on the Windows servers running on Azure, therefore I need to uninstall the Microsoft defender completely from the servers, but even after remove the role for Windows Defender the services…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Windows for business | Windows Server | User experience | Other
Microsoft Defender for Cloud Plan for Azure Servers
Hi, currently we have the basic Foundational CSPM MS Defender for Cloud plan enabled and also Defender CSPM. We would like to enable the Cloud Workload Protection (CWP) plan 2 for our Azure servers that costs around $15/Server/month. We have around 50…
Azure Monitor
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Issues with MS Defender for Cloud Alerts Not Appearing on Security Portal
Experiencing an issue where alerts generated in Microsoft Defender for Cloud on portal.azure.com are not visible in the alerts section of the security.microsoft.com portal. Environment settings have been configured in Azure, all plans enabled for the…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
KQL using SecurityResources needs to return Last Scan time of the AZ SQL database not of the host
I have a KQL query attached that returns the ScanTime but it is not the scan time for the database. It appears to be the scan time for something else ( returns Aug 2 when the database UI shows 7/31). Q: How to change my KQL query to return the scan…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
When ISO27001:2022 will be available for Defender regulatory compliance security framework
We have to add ISO270001:2022 framework in regulatory compliance in Defender for Cloud. However i am only able to see ISO27001:2013 Could you please confirm when 2022 will be available
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Inquiry About Security Score Standards in Microsoft Defender for Cloud
Hello, I am currently supporting the operation of Microsoft Defender for Cloud. I have a question regarding the security score in Microsoft Defender for Cloud. While I understand that a higher security score indicates a safer cloud environment, I…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
OpenSSL vulnerabilities showing in Defender Dashboard
We have multiple devices showing up with OpenSSL vulnerabilities. It is detecting two dll files that it is flagging. Which they are libssl-3-x64.dll and libcrypto-3-x64.dll. It is flagging this for multiple different applications through out multiple…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Microsoft Security | Microsoft Defender | Microsoft Defender for Identity
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud Apps
query to associate the department with an MDC recommendation
How can I update the following query to associate the department with each MDC recommendation? securityresources | where type == "microsoft.security/assessments" | extend source = trim(' ',…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Understanding why full and quick scans are out of 7 days
Hi, We have been receiving security recommendations for our virtual machines, and one of the findings states that "Both full and quick scans are out of 7 days": EDR configuration issues should be resolved on virtual machines-> Findings->…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Issue with Defender Recommendations - Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost.
HI i have 3 virtual machines in azure i have enabled one week back Encryption at host for all machines - Now am seeing - Recommendations - Virtual machines and virtual machine scale sets should have encryption at host enabled is now in healthy…
Azure Virtual Machines
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Security alerts email notifications
I have enabled Microsoft Defender for Cloud antimalware protection on a single storage account. Upon uploading an EICAR file I see security alerts with severity High are created, but I'm not getting any email notifications about them despite doing the…
Azure Blob Storage
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
OpenSSL Vulnerability Shown on Microsoft Defender for Cloud Dashboard - OneDrive affected app
An OpenSSL vulnerability has been flagged on one of our devices by Microsoft Defender for Cloud. The vulnerability has listed two dll files as the main culprits (both installed via OneDrive): libcrypto-3-x64.dll libssl-3-x64.dll The OneDrive version…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Minimum permission/right to Assign owner to MS Defender issue
I want to create a 'custom' role with the minimum permissions/rights to enable the ability to ....... Assign owner and set due date by which recommendation should be implemented in MS Defender So i can assign an administrator with limited technical…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Azure VM with high severity vulnerabilities allows lateral movement to
Hi, I have multiple virtual machines and I gave access to those machines to other resources like storage account, Azure KeY vault but in every morning I get "Azure VM with high severity vulnerabilities allows lateral movement to..." with…
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
