1,476 questions with Microsoft Defender for Cloud-related tags
In MS Defender for Cloud how to exclude a single VM from the monitoring
I have a virtual appliance from MDR provider AlerLogic. MS Defender generates alerts for the VM because it does vulnerability scanning and uses some tools that make Defender unhappy. This is the normal behavior of the Virtual Appliance. Is there any way…
Set 'Account lockout threshold' to 1-10 invalid login attempts Problems
Hi All, We are struggling to resolve tickets on our azure defender Security recommendations when they reference greyed out options in the "Group Policy" , for example : Account Lockout Duration *( greyed out ) we cannot set the limit from 0-10…
Need to add defender alert notification for an email address through powershell as we have multiple subscriptions.
Hi, We want to add Microsoft defender notification through powershell as we have multiple subscriptions on diff tenants. Either by powershell or partner centre powershell . Attaching screenshot - Already read the article -…
MDE managed devices
Hi! It is possible to manage Windows Servers with Defender for Endpoint and Intune. After setup, the Windows Server device appears in Intune. But can Devices > Configuration > Policies be deployed to it, or only policies under the Endpoint…
Environment risk of All recommendations by risk enable
How to enable the environmental risk of All recommendations by risk. Now, it is showing zero in all risks.
Defender for Cloud - Vulnerabilities Extensions
Hi All, I have enabled New Microsoft Vulnerability Management from Environment settings - Under Subscription - Under server plan. We have Plan 2 license. But i don't see any extension getting installed under server VMs. Please suggest on how to confirm…
Defender for Databases plan selection
Are SQL managed instances covered under the "Defender for SQL servers on machines" or under the "Defender for Azure SQL" plan?
We received reports from our users that our URL is unsafe, but they are safe.
Hi there, I am trying to contact Microsoft Defender support, but I am experiencing difficulties getting in contact with anyone. I am writing regarding false positive alerts that our users are receiving from Microsoft Defender concerning our legitimate…
Need to offboard the Windows Defender from Windows Servers
hello all, In our organization we have a S1 agent installed on the Windows servers running on Azure, therefore I need to uninstall the Microsoft defender completely from the servers, but even after remove the role for Windows Defender the services…
Microsoft 365 Business Premium : network protection for out-of-office endpoints
Hello, I would like to know if a service included in the Microsoft 365 Business Premium subscription can protect endpoints network when they are not behind an office firewall? IPS / IDS, DNS Filtering, etc. Thank you!
MS Defender Automated Simulation Training: How to have new users to live attack simulation training
Hi I am trying to setup MS Defender attack simulation training for staff. I have a number of queries regarding setup. 1: We have a live training campaign which we require all new staff members to complete. Please outline the process of having a new user…
Assistance Needed to Enable Microsoft Defender Real-Time Protection on Azure VM
Good afternoon, I am attempting to enable Microsoft Defender Real-Time Protection on my Azure VM running Windows Server 2022. However, the option to enable it is disabled, displaying the message: “This setting is managed by your administrator.” The VM is…
OpenSSL vulnerabilities in Defender for latest version Microsoft Products
My org has several OpenSSL vulnerabilities for OneDrive and Azure Disk Encryption. The CVEs are CVE-2024-4603, CVE-2024-4741, CVE-2024-5535, and Defender was said to fix inaccuracies with these last month (Sept. 2024).…
Defender for Endpoint blocking reddit
I added Reddit.com to my whitelist and can sort of go to Reddit. Windows notification is listing a couple sites it says it can't get to. Is there a way to setup one rule that will cover all sub-domains and such like doing reddit.com/* or such (which…
Azure ATP sensor issue -DC not visible under the security portal
Hi,we have installed the Azure ATP sensor on 33 DC's. But one DC's sensor status was unhealthy. To resolve this, we have cleared the DC entry from security portal and again re-install the ATP but unfortunately this time the affected DCS is visible in…
Issues installing Microsoft Defender for Endpoint (mdatp) on Debian 12 (Bookworm)
Hi, I have two Debian 12 VMs running in Azure which I would like to install Defender for Endpoint (mdatp) on, but I am having issues with the Linux Software Repository for Microsoft products. I am following the instructions here: Deploy Microsoft…
AxiosError: Request failed with status code 400
Hi, When we are trying to raise our secure score we encountered this problem: Something went wrong We have encountered an error loading this page, please try again later: AxiosError: Request failed with status code 400 Can someone explain why its having…
Attack Simulator Training, not receiving the e-mail.
After adding myself to an attack simulator training, training campaign I am not getting a notification. The training has no end time and is applied to an group. I was told that even if you add new users to the training campaign the should still receive…
OpenSSL Vulnerability Shown on Microsoft Defender for Cloud Dashboard - OneDrive affected app
An OpenSSL vulnerability has been flagged on one of our devices by Microsoft Defender for Cloud. The vulnerability has listed two dll files as the main culprits (both installed via OneDrive): libcrypto-3-x64.dll libssl-3-x64.dll The OneDrive version…
MS Defender web protection / SmartScreen for Google Chrome and Firefox
Hi. We have our CE+ assessment in a few weeks. In our CE basic, we provided information about our browsers Edge, Google Chrome and Firefox they have MS Defender / SmartScreen options enabled for malicious sites and downloads. Unfortunately, MS Defender…