1,564 questions with Microsoft Defender for Cloud-related tags
how to install windows defender
how do i install windoes defender on my PC and delet norton anti virus program
Microsoft Defender for Cloud
Defender for Endpoint Vulnerability Management Browser Extensions not populating
We recently turned on Defender Vulnerability Management add-on and applied the licenses to our users, but the add-on does not seem to be working properly. It's been 10 days that we have enabled the add-on but so far, only a few devices and a few…
Microsoft Defender for Cloud
Azure VM with high severity vulnerabilities allows lateral movement to Critical Azure storage account with sensitive data
We're getting these alerts: Microsoft Defender for Cloud found potential attack path in your environment Azure VM with high severity vulnerabilities allows lateral movement to Critical Azure storage account with sensitive data "An Azure virtual…
Microsoft Defender for Cloud
The cloud defender recommendations are not showing for storage accounts
We have enabled Cloud Defender at the subscription level, however there are some resources in these that are not being covered correctly. One example: the storage account recommendations are not showing up. There are definitely some recommendations that…
Microsoft Defender for Cloud
Logs of MS defender for cloud for ACR
Hi All, We're trying to check logs for defender for cloud, specifically for acr image scans. Had a ticket raised to find out and the technical team does not seem to have access too which is very strange. We have thousands of images being scanned every…
Microsoft Defender for Cloud
I'm receiving defender alerts for a VM that I have removed
Im receiving microsoft defender alerts for a VM that I removed from my portal. I have deleted all resources related to that VM, but our system administrator keeps getting security alerts for malicious connectivity attempts to that removed VM. I can't…
Microsoft Defender for Cloud
the recommendation named “ Kubernetes clusters should disable automounting API credentials” does not provide the option to create an exemption.
the recommendation named “Kubernetes clusters should disable automounting API credentials” does not provide the option to create an exemption. How can we resolve this?
Microsoft Defender for Cloud
OpenSSL vulnerabilities in Defender for latest version Microsoft Products
My org has several OpenSSL vulnerabilities for OneDrive and Azure Disk Encryption. The CVEs are CVE-2024-4603, CVE-2024-4741, CVE-2024-5535, and Defender was said to fix inaccuracies with these last month (Sept. 2024).…
Microsoft Defender for Cloud
Resolving EDR Configuration Issues for Deleted Virtual Machines
Hi there, I am currently looking to improve secure score. One of the recommendation is to Enable Endpoint Protection which has a secondary recommendation as follows: "EDR configuration issues should be resolved on virtual machines". However,…
Microsoft Defender for Cloud
Defender Log to Event Hub is not been stream
I’ve configured Continuous Export to Event Hub, but no messages appear to be streaming. What steps should I take to troubleshoot this issue?
Microsoft Defender for Cloud
False Positives on Attack Simulation Training - And how to cancel the training assigned to the user as a result of the false positive?
#1. Defender is reporting that users opened an attachment on an Attack Sumulation. Several users are claiming they did not open the attachment. We've been using Defender for a little over 2 years, and we used another tool prior for 5 years prior to…
Microsoft Defender for Cloud
Defender for Cloud indicates false an unhealthy resource
After switching Microsoft Defender for Cloud to Express configuration, one of the resources in my subscription is persistently flagged as unhealthy. However, when I drill into the resource in the Defender portal: The Findings tab is empty, showing no…
Microsoft Defender for Cloud
webhook enablement error
Hi, we have enabled to defender at blob storage level. We have assigned the eventgrid to capture the defender results in case of malware detection. We want to attach a webhook to eventgrid subscription to notify the malware errors in API. It throws error…
Azure Blob Storage
Microsoft Defender for Cloud
defender for cloud apps
HI team, need your help with the below. I am going through the documentation of defender for cloud app M365 and i found that in order to import and study the logs, we will need a firewall, proxy etcc and based on that we can discover the IT shadow…
Microsoft 365
Windows 10 Security
Microsoft Defender for Cloud
OpenSSL Vulnerability Shown on Microsoft Defender for Cloud Dashboard - OneDrive affected app
An OpenSSL vulnerability has been flagged on one of our devices by Microsoft Defender for Cloud. The vulnerability has listed two dll files as the main culprits (both installed via OneDrive): libcrypto-3-x64.dll libssl-3-x64.dll The OneDrive version…
Microsoft Defender for Cloud
Defender for cloud DevOps Security: Is it mandatory to have Github Advanced security enabled to find code vulnerabiltiy in azure devops repos
We are exploring the feature Microsoft Security DevOps and noticed there are no code vulnerability listed in the defender except Iac templates. As per the following table, is it a must have to enable Github Advanced Security to discover code or secret…
Microsoft Defender for Cloud
What's the exact definition of 'Timegenerated' in an Azure Resource Graph query output for Container Image Vulnerabilities?
When we run a query to find vulnerabilities in Container Images, there's a 'timegenerated' column in the query output. I've tried to find this documented somewhere, but can't, I've only found a document for Azure Monitor. Does this mean it's the last…
Azure Monitor
Azure Container Registry
Microsoft Defender for Cloud
An unknown application will gain access to the user's mailbox on their behalf.
Hello, We use a third-party event analytics service in M365. This service has noticed suspicious activity. Some application with an IP address from the Microsoft stack gets access to employee mailboxes. The request is made on behalf of the employee to…
Microsoft Defender for Cloud
I want to change Microsoft Defender for Cloud Plan2 to Plan1 for cost saving
I want to change Microsoft Defender for Cloud Plan2 to plan1. If changes from plan2 to plan1 what is any impacts on server. What should i do, i want to install Defender for Server on on-premises servers.
Microsoft Defender for Cloud
How to deactivate Microsoft Defender for Endpoint in Azure for a specific resource group?
Hello community, We are currently using Microsoft Defender for Servers – Plan 2 in Azure, which is active and enforced at the subscription level. We have a use case where we need to exclude or deactivate Defender for Endpoint (MDE) for a specific…