Best Practice for deallocated VM's

Microsoft

What is the best practice for handling this situation.
If a machine is set to deallocated as it is not currently needed, you'll have bunch of high severity alerts sitting in your dashboard that are just extra noise, is it not possible not suppress alerts for temporarily.

In addition, it seem that if a deallocated machine that was scoped for auto provisioning of Defender for Server is turned on, the Auto provisioning does not happen, is this normal behaviour and what's the best way to handle the security gap this creates apart from monitoring and manually redeploying Defender for server whenever a deallocated machine goes online again?  

0 Replies