1,250 questions with Microsoft Defender for Cloud-related tags

Sort by: Updated
2 answers

How to acquire security information in Azure Defender using REST API?

I'm using REST API to acquire security information of resources in Security Center -> Azure Defender. I learned that Azure Defender can be installed both in azure and third party resources. Can I use single API to acquire: Alert Count by…

Azure API Management
Azure API Management
An Azure service that provides a hybrid, multi-cloud management platform for APIs.
1,912 questions
Azure Cost Management
Azure Cost Management
A Microsoft offering that enables tracking of cloud usage and expenditures for Azure and other cloud providers.
2,286 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-11-12T09:18:03.557+00:00
wisdom_MTT 1 Reputation point
commented 2020-11-26T00:09:43.72+00:00
James Hamil 22,981 Reputation points Microsoft Employee
0 answers

Explanation- Parameter : Enabling NIST SP 800-53 R4 compliance standards.

Explanation- Parameter : Enabling NIST SP 800-53 R4 compliance standards. Below Parameters needs some explanation - List of users excluded from Windows VM Administrators groupWhat to mention if there are no users in exclusion, as this section is…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-11-25T09:40:09.57+00:00
Vikram Kolekar 1 Reputation point
commented 2020-11-25T23:38:08.907+00:00
JamesTran-MSFT 36,531 Reputation points Microsoft Employee
1 answer

Securing Single Web App.

I currently have a single Web App and Durable Functions, 2 VMs and 1 Azure SQL Database and 1 Cosmos DB. I wanted to know what is the best approach to secure the Web App. I have read WAF, or WAF with Application Gateway or Front Door. I would need…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
622 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,277 questions
asked 2020-11-22T11:51:38.713+00:00
Kman 41 Reputation points
commented 2020-11-23T20:39:34.313+00:00
ajkuma 24,396 Reputation points Microsoft Employee
0 answers

Is it possible to acquire overview of my resources in Security Center -> Inventory using REST API?

I'm using REST API to acquire security overview information of vms and other resources in Security Center -> Inventory. I'd like to know: How many VMs is unmonitored Healthy, unhealthy, and not applicable Overview on resources:…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-11-11T09:53:14.9+00:00
wisdom_MTT 1 Reputation point
commented 2020-11-12T01:01:03.833+00:00
wisdom_MTT 1 Reputation point
1 answer One of the answers was accepted by the question author.

Policy & Compliance

Hello, We have setup security centre for 4 of our subscriptions. For industry & regulatory standards, by default we have PCI and etc enabled. I wanted to enable PI (Personally Identifiable) data, AML data policy as part of the regulatory…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-11-05T12:53:22.98+00:00
Prasenna Kannan 436 Reputation points
commented 2020-11-09T23:34:15.133+00:00
Prasenna Kannan 436 Reputation points
2 answers One of the answers was accepted by the question author.

Microsoft Antimalware Extension

Hi, since Windows Defender is not supported on Server 2012 R2 I'm looking for endpoint protection solutions to vms in Azure. I came a cross Microsoft Antimalware Extension for Windows which could solve my issues but have few questions about this service…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,479 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-07-30T07:15:13.577+00:00
Bombbe 1,616 Reputation points
answered 2020-11-06T11:31:31.84+00:00
Sudhakar Penki 96 Reputation points
1 answer One of the answers was accepted by the question author.

IAASAntimalware- Provisioning Failed

I am getting below error on installing MicroSoft AntiMalware Extension to Azure Virtual Machine. Error 1: System.InvalidOperationException: Cannot start service MSMPSvc on computer '.'. ---System.ComponentModel.Win32Exception: The service…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,479 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-11-06T07:22:45.97+00:00
Sudhakar Penki 96 Reputation points
accepted 2020-11-06T07:33:59.73+00:00
Sudhakar Penki 96 Reputation points
1 answer

Deploy ATP to Windows server 2016 1607

Hi all i folow this guide https://video2.skills-academy.com/en-us/mem/configmgr/protect/deploy-use/defender-advanced-threat-protection Download package, get key and ID, put to MECM and deploy to servers. We have SCOM 2019 UR2 on all servers. …

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-08-26T14:42:13+00:00
Belan Marek 51 Reputation points
answered 2020-11-03T16:09:46.067+00:00
SIMOS George 1 Reputation point
1 answer One of the answers was accepted by the question author.

Microsoft Graph Security API results

Hello, With the Graph Security API /alerts endpoint url, I receive alerts info but some fields are not filled in the response. As an example, in the screenshot there is no value for the field "privateIpAddress". Is there a reason why…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-10-02T11:27:41.413+00:00
Panayiotis Mousarris 21 Reputation points
accepted 2020-11-03T14:04:01.877+00:00
Panayiotis Mousarris 21 Reputation points
1 answer

Azure Security Center recommendations remediation tracker

Hello, Can we have an option on Azure Security Center recommendations to get the remediation tasks tracked as it is done on Defender Portal (Attached image for reference) This would be helpful where there are policies that needs to be applied to…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-10-27T15:50:15.48+00:00
Ambarish Haridathan 1 Reputation point
answered 2020-10-27T16:26:07.953+00:00
James Hamil 22,981 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Azure Pen Test

Hi, does Azure has available reports of its own Pen Test or Red Teaming test?

Azure DNS
Azure DNS
An Azure service that enables hosting Domain Name System (DNS) domains in Azure.
628 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,041 questions
asked 2020-10-26T21:40:37.367+00:00
Alessandra Pluchino 21 Reputation points
answered 2020-10-27T14:27:32.103+00:00
Alessandra Pluchino 21 Reputation points
1 answer

Microsoft Cloud application security discovery dillema

Hello, we want to use MCAS in our Azure environment. The problem I encountered is that when trying to enable the Discovery in our environment I cannot do it. We don't have any proxies or Firewall in place -> no logs can be exported and…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-10-22T08:18:27.707+00:00
Iustin Alexandru 1 Reputation point
commented 2020-10-26T15:11:42.547+00:00
Iustin Alexandru 1 Reputation point
10 answers

Intune - Devices reported as without ATP-sensor

So we activated Defender ATP within Intune and connected it with Microsoft Defender Security Center: I can see the devices at https://securitycenter.windows.com/machines But Intune reports them as devices without ATP-sensor: …

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-09-29T12:45:57.437+00:00
Chned 51 Reputation points
answered 2020-10-26T04:50:24.42+00:00
Crystal-MSFT 45,736 Reputation points Microsoft Vendor
1 answer One of the answers was accepted by the question author.

Microsoft Threat Model - Not able to add a new stensil to my template

I created a threat model with MSTM tool with some template taken. I need to add few new stensils to it. but I don't find a option to do the same! is that possible? Pls advise / let know a way. Thanks,

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-10-21T09:49:28.977+00:00
Akhilesh Kumar Gupta - ERS, HCL Tech 101 Reputation points
accepted 2020-10-24T03:07:05.557+00:00
Akhilesh Kumar Gupta - ERS, HCL Tech 101 Reputation points
2 answers

Azure SecurityCenter

Hello All, What is the advantages of integration(enabling) of Azure Security Center with Sentinel? What kind of rule we can enable on sentinel for Azure Security Center? Thank You Rohit

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,041 questions
asked 2020-07-21T16:19:44.817+00:00
Rohit 1 Reputation point
answered 2020-10-21T12:52:37.373+00:00
Jaehong Lee_sb339 1 Reputation point
0 answers

Azure ATP Sensor Proxy Authentication

All internet traffic in our org goes via a forward web proxy. It also has the capability to bypass SSL inspection should we need to. I have been looking at deploying the Azure ATP sensor to my domain controllers but security teams are uncomfortable with…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-10-18T13:58:35.11+00:00
shockoQA 126 Reputation points
commented 2020-10-20T23:42:19.497+00:00
JamesTran-MSFT 36,531 Reputation points Microsoft Employee
0 answers

VMs missing from Security Center inventory

Hi all I have enabled Security Center for my subscription but it did not list any of my VMs in the inventory. I have created new ones (Linux OS) since enabling Sec Center but it won't list these either. I feel I must be missing something. Does…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-10-19T16:43:08.15+00:00
Bill M 1 Reputation point
commented 2020-10-19T19:27:38.707+00:00
James Hamil 22,981 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Azure Security Assessment

Hi there, It is required to assess the Security (CSPM) for all our Azure PaaS & SaaS services across a number of Management Groups. Not just the security score. An in-depth Security Assessment to be carried out across:- Identity and…

Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
820 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-09-29T10:26:25.71+00:00
Raju Golla 41 Reputation points
accepted 2020-10-15T11:29:18.33+00:00
Raju Golla 41 Reputation points
1 answer One of the answers was accepted by the question author.

Azure Defender and specific App Services

I'm reading the documentation for Azure Defender (https://video2.skills-academy.com/en-gb/azure/security-center/azure-defender) and this suggests that the only way to enable Azure Defender for App Service is through enabling for the subscription which would…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
asked 2020-10-14T11:03:07.927+00:00
Rob Nicholls 21 Reputation points
commented 2020-10-15T09:26:48.81+00:00
Rob Nicholls 21 Reputation points
1 answer

How to notify admin and suspend user if user downloads large amount of files in 20 minutes?

Helo, I require to notify admin and suspend user if user downloads large amount of files in 20 minutes. which security policy can be considered? an activity policy/DLP policy/File Policy/an alert policy ? Thanks,

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,367 questions
asked 2020-10-15T05:19:24.06+00:00
Dave Wi 11 Reputation points
answered 2020-10-15T06:59:21.917+00:00
Vasil Michev 99,431 Reputation points MVP