best practices
13 TopicsMicrosoft Azure Defender for Cloud Regulatory Compliance
Could you configure Microsoft Defender to monitor regulatory compliance by resource group (default) instead of by subscription level? Is this possible? All documentation on this points out that it's by subscription level (default) and management group. You can set default policy, edit/create custom initiatives, and enable/disable regulations/standard on settings.Solved2.4KViews0likes3CommentsMissing scan data on Endpoint protection should be installed on virtual machine scale sets
Hi everyone, I have enabled Defender for Cloud on one of our Azure Subscriptions as we are looking to test it's capabilities to report on Defender for Windows. I'm looking at the metric "Endpoint protection should be installed on virtual machine scale sets" however all of my VMSS instances are "Missing Scan Data". If I look at the scale sets on the Inventory page of Defender for Cloud I can see the Monitoring Agent is Installed and Defender for Cloud is On. Is there anything else I need to do to start scanning? How can I tell why these VMSS's are not being scanned.Using Lighthouse to monitor MDC
This Cross-tenant management experiences - Azure Lighthouse | Microsoft Learn states that "the entire subscription must be delegated to the managing tenant; Microsoft Defender for Cloud scenarios are not supported with delegated resource groups" does this mean that every subscription monitored by MDC must be delegated to the managed service provider? Also what happens if MDC is monitoring another cloud? how does this affect the service provider?1.6KViews0likes1CommentDefender and Plans
Hi What is considered before enabling the various Microsoft Defender plans? - enable all by resources type or enable the specific ones? (what your subscription contains) There are no cost if you e.g. enable the 'Containers plan' and you don't have any Containers deployed in the Subscription? What happens on the subscription level when enabling the containers plan?1.3KViews0likes2CommentsCentralize remediation for defender reccomendations
Hi, I have a question. Can I apply the remediation of Microsoft defender reccomendation one time for all subscription that I have? For example I want to resolve MFA reccomendation for all subscription (15) but apply the remediation one time. (I‘’m referring to all the reccomendation that not provide quick fix button). DeployIfNotExist can help me? Or blueprint? Thanks915Views0likes1Commentassign default initiative not showing
Hi Trying to Creating default initiative, but its not showing under default (after several hours) When Assigning there's this notification: Creating initiative assignment succeeded Creating initiative assignment 'Azure Security Benchmark' in 'sub1' was successful. Please note that the assignment takes around 30 minutes to take effect.720Views0likes0CommentsE2E Bootstrap Solution for Malicious File Scanning Using Microsoft Defender for Storage in Azure
The following blog post elucidates one of the architectural patterns that can be employed for efficiently monitoring the malware scan status while utilizing Microsoft Defender for storage malware scanning. Read the full blog here: Malicious File Scanning Using Microsoft Defender for Storage in Azure646Views0likes0Comments