1,468 questions with Microsoft Defender for Cloud-related tags
Issue with Web Content Filtering – Indicators Not Working
Hello, I'm trying to set up site blocking using Web Content Filtering. After enabling all the necessary components in Advanced Features in security center: Web Content Filtering And configuring the following components in the system (via…
MS List for supported OS by Azure Defender for Server
We have Defender for Cloud enabled in our tenant with ARC onboarded servers; unfortunately supported OS aren't always clear between ARC and Azure Defender for Servers. Below articles checked: -ARC supported OS :…
Microsoft XDR (Defender) - DeviceEvents - ShellLinkCreateFileEvent
Hi everyone, I've been trying to create a hunting query in the Defender portal to identify when a malicious .lnk file is created. I noticed that an interesting event to detect and analyze this is "DeviceEvents --> ShellLinkCreateFileEvent",…
Can't Find OAuth Apps in Microsoft Defender Cloud Dropdown
Hello, I am looking to Remediate risky OAuth apps via Microsoft Defender. I am trying to follow this help article https://learn.microsoft.com/en-us/defender-cloud-apps/app-permission-policy but I do not have the same dropdown selection options as what is…
is it possible to collect windows log with windows defender for endpoint
Hello, We plan to install windows defender for endpoint at all computer workstations. The question is whether it is possible to collect Windows log (not only antivirus, but also system, applications, DLP) with windows defender for endpoint Thanks for…
Microsoft Defender for Cloud | Regulatory compliance shows error
I open the tab Regulatory compliance of Microsoft Defender for Cloud https://portal.azure.com/?quickstart=True#view/Microsoft_Azure_Security/SecurityMenuBlade/~/22 But the page only shows an error: Cannot read properties of null (reading 'toString')
Can I use Kusto Explorer on the Advanced hunting data from Defender portal?
Hello, Is it possible to use Kusto Explorer to run KQL queries on the data available on the Defender portal (Advanced Hunting section)? If not, will it be possible in the future ? Best Regards
Phishing attack simulation payload editor is extremely broken
We are using the attack simulation training module in Defender for Office. So we have used the solution to run phishing exercises the past year. I now wanted to change our custom positive reinforcement notification. It seems the editor…
Do you know if Azure has an equivalent to Jira’s Asset Management System?
Jira have good Asset Management System. Does Azure have equivalent to Jira Asset Management System ?
Defender for Cloud updated CIS Compliance Standard
I would like to ask if the Defender for Cloud product group knows when the updated CIS Azure Foundations Benchmark will become available as a regulatory compliance standard in Defender for Cloud.
Attack simulator training payloads CSS not applying for an ethical phishing campaign
Dears, I'm having an issue with DefenderATP cloud security platform (security.microsoft.com) and attack simulation payload creation. When creating email or login pages, CSS is not being applied to the html. On offline index.html file the content shows…
Issues with "Pending Actions" in Microsoft Defender XDR Despite Full Remediation Setting
When an email is soft deleted (both manually and under automation), this action awaits approval in the action center. This doesn't happen for every soft delete. Some occur without needing approval. Upon checking the configurations, I see that full…
Defender for Cloud - Disabled accounts with read and write permissions on Azure resources should be removed - removing permissions from accounts automatically
Hello, To complete recommendation from DfC "Disabled accounts with read and write permissions on Azure resources should be removed", I'd like to set autoschedule to remove permissions assigned to disabled accounts, which sign-ins aren't logged…
Logic App Workflow Automation Not Triggering for Security Alerts
I have set up a Logic App to trigger workflow automation for security alerts on Microsoft Defender. However, it is not triggering automatically, even after simulating security alerts on the storage account. I can trigger the alerts manually, and I…
AxiosError: Request failed with status code 400
Hi, When we are trying to raise our secure score we encountered this problem: Something went wrong We have encountered an error loading this page, please try again later: AxiosError: Request failed with status code 400 Can someone explain why its having…
API to get Microsoft Defender Campaigns
Is there a way to get the Campaigns data inside the Microsoft Defender Portal using an API?
Is it possible to automatically email reports for incomplete Attack Simulator training?
Hey everyone, I’m currently managing security training for my organization and using the Attack Simulator feature in Microsoft 365. I was wondering: Is there a way to automate reports for users who haven’t completed their assigned training and have those…
How to Calculate Identity SecureScore via Graph API?
Hello i try to get the SecureScore values via Graph API. I can request the main Score value. But i have problems to calculate the Scores for Identity/Data/Device and Apps. i know that i have to calculate the Current points for each type. That's works…
Does MS Defender provides security features (like vulnerability scanning and Intrusion prevention etc) can be configure for Azure Cloud service (extended support) CS-ES.
Defender documentation shows The vulenerability scan is limited to VM as supported destinations only. Also the Defender inventory list does not shows any CS-ES instances protected by it.
OpenSSL Vulnerability Shown on Microsoft Defender for Cloud Dashboard - OneDrive affected app
An OpenSSL vulnerability has been flagged on one of our devices by Microsoft Defender for Cloud. The vulnerability has listed two dll files as the main culprits (both installed via OneDrive): libcrypto-3-x64.dll libssl-3-x64.dll The OneDrive version…