1,468 questions with Microsoft Defender for Cloud-related tags

Sort by: Updated
0 answers

Issue with Web Content Filtering – Indicators Not Working

Hello, I'm trying to set up site blocking using Web Content Filtering. After enabling all the necessary components in Advanced Features in security center: Web Content Filtering And configuring the following components in the system (via…

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,504 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
457 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,446 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
22 questions
asked 2025-01-18T01:27:17.23+00:00
Mountain Pond 1,481 Reputation points
edited the question 2025-01-19T09:37:20.8533333+00:00
Mountain Pond 1,481 Reputation points
1 answer

MS List for supported OS by Azure Defender for Server

We have Defender for Cloud enabled in our tenant with ARC onboarded servers; unfortunately supported OS aren't always clear between ARC and Azure Defender for Servers. Below articles checked: -ARC supported OS :…

Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
465 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2025-01-17T11:05:12.05+00:00
Hajer FATHALLAH 0 Reputation points
answered 2025-01-17T18:15:47.0233333+00:00
Jeff Pigott 160 Reputation points Microsoft Employee
1 answer

Microsoft XDR (Defender) - DeviceEvents - ShellLinkCreateFileEvent

Hi everyone, I've been trying to create a hunting query in the Defender portal to identify when a malicious .lnk file is created. I noticed that an interesting event to detect and analyze this is "DeviceEvents --> ShellLinkCreateFileEvent",…

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,977 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,885 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2024-12-19T18:02:05.2466667+00:00
viri4to 10 Reputation points
commented 2025-01-17T13:22:07.49+00:00
viri4to 10 Reputation points
2 answers

Can't Find OAuth Apps in Microsoft Defender Cloud Dropdown

Hello, I am looking to Remediate risky OAuth apps via Microsoft Defender. I am trying to follow this help article https://learn.microsoft.com/en-us/defender-cloud-apps/app-permission-policy but I do not have the same dropdown selection options as what is…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2025-01-08T21:49:21.09+00:00
NDS 082206 20 Reputation points
commented 2025-01-16T08:29:47.9333333+00:00
Navya 14,385 Reputation points Microsoft Vendor
1 answer

is it possible to collect windows log with windows defender for endpoint

Hello, We plan to install windows defender for endpoint at all computer workstations. The question is whether it is possible to collect Windows log (not only antivirus, but also system, applications, DLP) with windows defender for endpoint Thanks for…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2025-01-14T14:12:32.89+00:00
TomVanDerPo 0 Reputation points
answered 2025-01-16T08:12:10.3633333+00:00
Givary-MSFT 34,891 Reputation points Microsoft Employee
1 answer

Microsoft Defender for Cloud | Regulatory compliance shows error

I open the tab Regulatory compliance of Microsoft Defender for Cloud https://portal.azure.com/?quickstart=True#view/Microsoft_Azure_Security/SecurityMenuBlade/~/22 But the page only shows an error: Cannot read properties of null (reading 'toString')

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2025-01-13T15:48:09.6666667+00:00
mare 0 Reputation points
answered 2025-01-15T22:26:37.8166667+00:00
James Hamil 26,881 Reputation points Microsoft Employee
1 answer

Can I use Kusto Explorer on the Advanced hunting data from Defender portal?

Hello, Is it possible to use Kusto Explorer to run KQL queries on the data available on the Defender portal (Advanced Hunting section)? If not, will it be possible in the future ? Best Regards

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
22 questions
asked 2025-01-13T16:57:31.3+00:00
Romain PRACCA 6 Reputation points
commented 2025-01-15T14:35:33.0833333+00:00
Givary-MSFT 34,891 Reputation points Microsoft Employee
0 answers

Phishing attack simulation payload editor is extremely broken

We are using the attack simulation training module in Defender for Office. So we have used the solution to run phishing exercises the past year. I now wanted to change our custom positive reinforcement notification. It seems the editor…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
233 questions
asked 2025-01-14T12:22:45.53+00:00
Emil Gertsen Grønkjær 0 Reputation points
edited the question 2025-01-15T11:10:35.8666667+00:00
VarunTha 11,080 Reputation points Microsoft Vendor
1 answer One of the answers was accepted by the question author.

Do you know if Azure has an equivalent to Jira’s Asset Management System?

Jira have good Asset Management System. Does Azure have equivalent to Jira Asset Management System ?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2025-01-15T05:38:57.7233333+00:00
ritari 20 Reputation points
accepted 2025-01-15T10:41:32.87+00:00
ritari 20 Reputation points
0 answers

Defender for Cloud updated CIS Compliance Standard

I would like to ask if the Defender for Cloud product group knows when the updated CIS Azure Foundations Benchmark will become available as a regulatory compliance standard in Defender for Cloud.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2024-12-23T23:05:21.8+00:00
Josue Gonzalez 90 Reputation points
commented 2025-01-13T23:10:21.3966667+00:00
Josue Gonzalez 90 Reputation points
2 answers

Attack simulator training payloads CSS not applying for an ethical phishing campaign

Dears, I'm having an issue with DefenderATP cloud security platform (security.microsoft.com) and attack simulation payload creation. When creating email or login pages, CSS is not being applied to the html. On offline index.html file the content shows…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2025-01-10T10:56:54.2133333+00:00
Albert Garangou 0 Reputation points
answered 2025-01-13T18:28:03.5666667+00:00
Raja Pothuraju 11,170 Reputation points Microsoft Vendor
0 answers

Issues with "Pending Actions" in Microsoft Defender XDR Despite Full Remediation Setting

When an email is soft deleted (both manually and under automation), this action awaits approval in the action center. This doesn't happen for every soft delete. Some occur without needing approval. Upon checking the configurations, I see that full…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2025-01-13T16:01:17.06+00:00
Zeynep 0 Reputation points
edited the question 2025-01-13T17:07:37.03+00:00
Rakesh Gurram 11,300 Reputation points Microsoft Vendor
1 answer One of the answers was accepted by the question author.

Defender for Cloud - Disabled accounts with read and write permissions on Azure resources should be removed - removing permissions from accounts automatically

Hello, To complete recommendation from DfC "Disabled accounts with read and write permissions on Azure resources should be removed", I'd like to set autoschedule to remove permissions assigned to disabled accounts, which sign-ins aren't logged…

Azure Automation
Azure Automation
An Azure service that is used to automate, configure, and install updates across hybrid environments.
1,291 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,899 questions
asked 2025-01-08T13:11:15.56+00:00
SS97 40 Reputation points
accepted 2025-01-13T06:29:15.04+00:00
SS97 40 Reputation points
1 answer

Logic App Workflow Automation Not Triggering for Security Alerts

I have set up a Logic App to trigger workflow automation for security alerts on Microsoft Defender. However, it is not triggering automatically, even after simulating security alerts on the storage account. I can trigger the alerts manually, and I…

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,327 questions
Azure Logic Apps
Azure Logic Apps
An Azure service that automates the access and use of data across clouds without writing code.
3,313 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2025-01-05T21:52:46.64+00:00
Mike Ter 0 Reputation points
answered 2025-01-10T07:49:46.2466667+00:00
Shireesha Eeraboina (Quadrant Resource LLC) 660 Reputation points Microsoft Vendor
1 answer

AxiosError: Request failed with status code 400

Hi, When we are trying to raise our secure score we encountered this problem: Something went wrong We have encountered an error loading this page, please try again later: AxiosError: Request failed with status code 400 Can someone explain why its having…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
164 questions
asked 2024-12-16T22:13:47.3766667+00:00
Lyle 95 Reputation points
edited the question 2025-01-10T07:32:14.73+00:00
Raja Pothuraju 11,170 Reputation points Microsoft Vendor
0 answers

API to get Microsoft Defender Campaigns

Is there a way to get the Campaigns data inside the Microsoft Defender Portal using an API?

Microsoft 365
Microsoft 365
Formerly Office 365, is a line of subscription services offered by Microsoft which adds to and includes the Microsoft Office product line.
5,504 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
233 questions
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps
A Microsoft cloud access security broker that enables customers to control the access and use of software as a service apps in their organization.
164 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
22 questions
asked 2025-01-06T10:36:01.8966667+00:00
Hashem Barakat 0 Reputation points
commented 2025-01-10T05:43:28.29+00:00
Hashem Barakat 0 Reputation points
1 answer

Is it possible to automatically email reports for incomplete Attack Simulator training?

Hey everyone, I’m currently managing security training for my organization and using the Attack Simulator feature in Microsoft 365. I was wondering: Is there a way to automate reports for users who haven’t completed their assigned training and have those…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2024-12-11T14:43:26.54+00:00
Daniel Ideho 0 Reputation points
commented 2025-01-09T15:13:24.22+00:00
Daniel Ideho 0 Reputation points
0 answers

How to Calculate Identity SecureScore via Graph API?

Hello i try to get the SecureScore values via Graph API. I can request the main Score value. But i have problems to calculate the Scores for Identity/Data/Device and Apps. i know that i have to calculate the Current points for each type. That's works…

Microsoft Graph
Microsoft Graph
A Microsoft programmability model that exposes REST APIs and client libraries to access data on Microsoft 365 services.
12,798 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2025-01-09T11:49:21.9+00:00
Bader, Andreas 0 Reputation points
2 answers

Does MS Defender provides security features (like vulnerability scanning and Intrusion prevention etc) can be configure for Azure Cloud service (extended support) CS-ES.

Defender documentation shows The vulenerability scan is limited to VM as supported destinations only. Also the Defender inventory list does not shows any CS-ES instances protected by it.

Azure Cloud Services
Azure Cloud Services
An Azure platform as a service offer that is used to deploy web and cloud applications.
705 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2024-12-13T13:37:57.6933333+00:00
AzureGladiator 0 Reputation points
commented 2025-01-08T22:09:26.73+00:00
AzureGladiator 0 Reputation points
0 answers

OpenSSL Vulnerability Shown on Microsoft Defender for Cloud Dashboard - OneDrive affected app

An OpenSSL vulnerability has been flagged on one of our devices by Microsoft Defender for Cloud. The vulnerability has listed two dll files as the main culprits (both installed via OneDrive): libcrypto-3-x64.dll libssl-3-x64.dll The OneDrive version…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,468 questions
asked 2024-10-31T12:38:50.5166667+00:00
Eric Wasike 55 Reputation points
commented 2025-01-08T15:44:32.1866667+00:00
SM 0 Reputation points