User Profile
YuriDiogenes
Joined 8 years ago
User Widgets
Recent Discussions
Re: Azure Defender Plan for DevOps(Preview) missing
Hello Jake, There is no Defender for DevOps plan to enable yet, as we are still in public preview. The Defender for DevOps configuration for now starts to happen when you create a connector. See the steps from the lab https://github.com/Azure/Microsoft-Defender-for-Cloud/blob/main/Labs/Modules/Module%2014-Config%20Azure%20ADO%20in%20DfD.md670Views0likes0CommentsRe: Best Practices for Compliance Score
Last month we released the Workflow Automation for Regulatory Compliance. More info at https://docs.microsoft.com/en-us/azure/security-center/release-notes#workflow-automations-can-be-triggered-by-changes-to-regulatory-compliance-assessments-in-preview Regarding the webinar, thanks for the suggestion.996Views0likes0CommentsRe: Secure score evaluation in companies in the sector
Hello Elias01 - the ASC Secure Score doesn't take in consideration the industry verticals. The score is purely calculated based on the aggregation of security recommendations into security controls, and these recommendations are specifically for the workloads that are available in the subscription.2.4KViews0likes0CommentsRe: Security Center Recommendations
SecureDuck it depends on the type of recommendation. For example, "no recommendation" in the UI for JIT VM could be caused by: Missing NSG - The just-in-time solution requires an NSG to be in place. Classic VM - Security Center just-in-time VM access currently supports only VMs deployed through Azure Resource Manager. A classic deployment is not supported by the just-in-time solution. Other - A VM is in this category if the just-in-time solution is turned off in the security policy of the subscription or the resource group, or if the VM is missing a public IP and doesn't have an NSG in place. Check the recommendation and review the documentation for the potential reasons that an item show as not recommended: https://docs.microsoft.com/en-us/azure/security-center/1.7KViews0likes0CommentsRe: How to implement os recommendations
LA1976 GPO is the recommended way to implement these settings. Regarding this statement "why not be able to download the json from the portal to have it converted to DSC or GPO" <== this capability is not currently available. We are revisiting this UI, and we should bring some changes to the way these recommendations can be implemented. I don't have a ETA to share, but changes are coming to this experience. Thanks for sharing your feedback!1.2KViews0likes0CommentsRe: How to collect Security Data and generate a report from an Azure Subscription to check compliance
palchak enable Azure Security Center in your subscription, upgrade it to Standard tier (upgrade is free for 30 days) and wait for ASC to scan the resources available in the subscription and generate the security recommendations. Here a quick tutorial on how to onboard ASC https://docs.microsoft.com/en-us/azure/security-center/security-center-get-started1.9KViews0likes0CommentsRe: Antimalware Hybrid Licensing
Stefan Schörling - got more details from the Antimalware PM: Microsoft antimalware service in Azure is not SCEP. It's Microsoft antimalware for Azure. SCEP is system center endpoint protection and the only way you get it / deploy it is via system center (not free).2.8KViews1like0CommentsRe: Antimalware Hybrid Licensing
Hello Stefan Schörling , sorry the delay. In summary (update now): Microsoft antimalware service in Azure is not SCEP. It's Microsoft antimalware for Azure. SCEP is system center endpoint protection and the only way you get it / deploy it is via system center.2.9KViews0likes3Comments
Recent Blog Articles
A Proactive Approach to Cloud Security Posture Management with Microsoft Defender for Cloud
Introduction In this blog, I discuss the importance of proactive security posture management, how security teams can be organized for security posture management, how roles and responsibilities can...16KViews5likes4CommentsMicrosoft Defender for Cloud PoC Series – Microsoft Defender for Resource Manager
Introduction In this blog, we guide you through conducting a Proof of Concept (PoC) for Microsoft Defender for Resource Manager, part of Microsoft Defender for Cloud. This service provides advanced...6.8KViews5likes1CommentAzure Network Security using Microsoft Defender for Cloud integration with Azure Firewall Manager
Written in collaboration with Mohit_Kumar (Senior PM CxE Azure Network Security Team) Current challenges Recent attacks are a great reminder that security hygiene should be your number one pr...9.4KViews4likes1CommentQuerying your Secure Score Across Multiple Subscriptions in Microsoft Defender for Cloud
Although the capability to query the Secure Score using API was already available and we already published some automations to leverage this capability, now you can also query your Secure Score using...7.6KViews5likes0Comments