Forum Discussion
Azure CIS policies with ADDS Joined VMs
Hi WHendrickson
Dismissing a CCEID changes the status of an item to "dismissed" and hides it from the dashboard.
If you still see it, please make sure your filter set to not display dismissed items:
- WHendricksonApr 12, 2021Copper Contributor
You are correct that they are hidden if dismissed however they are not removed from your secure score and regulatory compliance scores.
I'm looking at how to be exempt from these policies if I can't control them so they don't reflect negatively against our scores.
Thanks,
- StanislavBelovApr 12, 2021
Microsoft
In this case you can either disable certain rules (disabled findings won't be counted towards your secure score) or exempt the whole recommendation (not recommended):
https://docs.microsoft.com/en-us/azure/security-center/remediate-vulnerability-findings-vm?WT.mc_id=Portal-Microsoft_Azure_Security#disable-specific-findings-preview- WHendricksonApr 20, 2021Copper Contributor
These 2 CIS policies cannot be disabled like findings from a vulnerability assessment. Only way to remediate them is to disable the entire policy in Azure which is not the desired outcome. Microsoft either has to exclude them from ADDS joined VMs or allow users to set the restrictions from within Azure to satisfy them I believe.