1,622 questions with Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud tags

Sort by: Updated
0 answers

Azure VM Alerts

Hello, my team and I provisioned a Server 2025 VM, and we keep receiving an alert that the machine is vulnerable to an internet attack, but we can't identify what is causing this alert to fire

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-11-11T16:29:30.41+00:00
Christopher Johnson 0 Reputation points
edited a comment 2025-11-12T18:18:19.1833333+00:00
Christopher Johnson 0 Reputation points
2 answers

Why Microsoft Defender for Cloud showing Zero Secure Score for security reader role?

I cannot see cloud secure score in defender for cloud dashboard overview or under security posture. However, security recommendations, regulatory compliance etc are visible. I have reader and security reader permissions assigned via RBAC at management…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-11-12T06:32:06.43+00:00
Satheesh Kumar S 0 Reputation points
answered 2025-11-12T09:34:38.8433333+00:00
SUNOJ KUMAR YELURU 16,851 Reputation points MVP Volunteer Moderator
0 answers

What is the best method to limit a user to access specific websites and block all others?

What is the best method for limiting a users access to specific websites and blocking all others? We have a small group of special users who will be accessing a virtual machine and we want them to only be able to access specific websites and block all…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-11-03T20:30:27.6133333+00:00
David Evans 0 Reputation points
edited a comment 2025-11-06T21:51:04.4933333+00:00
Sridevi Machavarapu 2,780 Reputation points Microsoft External Staff Moderator
0 answers

Windows Defender flagged our company digital certificate as Win32/Malgent

Hello everyone, We are a legitimate software publisher (adlice), and all our applications are digitally signed with an EV code signing certificate. Recently, Microsoft Defender started detecting binaries signed with our certificate as…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-11-05T16:46:21.9766667+00:00
Tigzy 0 Reputation points
commented 2025-11-05T16:48:48.74+00:00
Tigzy 0 Reputation points
1 answer One of the answers was accepted by the question author.

Auto provisioning setting fails when enabling Defender for Containers

During enabling of Defender for Containers plan on my subscription, as part of the setup I see an error in the activity logs: Create auto provisioning setting - fails Error code: Deprecated Message: Log Analytics auto provisioning is deprecated and can…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-11-03T15:48:19.3966667+00:00
Assaf L 317 Reputation points
accepted 2025-11-05T14:02:52.5766667+00:00
Assaf L 317 Reputation points
1 answer

Cannot remove JIT rules from Defender for Servers

We are using Microsoft Defender for Cloud. We need to turn off a JIT access rule for a particular NSG, however, the delete action never removes the rule. One guidance suggests to turn of Defender for the entire subscription, which we don't want to do.…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-09-22T22:10:15.7566667+00:00
ChristianSievers 0 Reputation points
commented 2025-11-05T11:45:29.3233333+00:00
Catherine Kyalo 2,465 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Does Azure Stack licensing include Microsoft Defender for Endpoint and Microsoft Defender Antivirus licenses?

你好,我们已经购买了azure Stack授权,节点服务器想使用Microsoft Defender for Endpoint或者Microsoft Defender Antivirus,请问是否需要额外购买授权。 Hello, we have purchased Azure Stack licensing and intend to use Microsoft Defender for Endpoint or Microsoft Defender Antivirus on our node…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-31T06:25:02.8366667+00:00
wangting 王婷6 40 Reputation points
accepted 2025-11-05T09:45:25.7166667+00:00
wangting 王婷6 40 Reputation points
2 answers

What need to do to offboard more than 10 devices using local script from defender portal??

Hello Experts, We are currently in the process of planning the offboarding of multiple devices, including Windows servers, Windows 10, and others, using a local script (cmd file). However, the Microsoft documentation mentions that this method applies to…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
Windows for business | Windows Server | User experience | Other
asked 2023-12-26T04:38:12.2133333+00:00
Anant Bera 251 Reputation points
edited an answer 2025-11-04T17:19:05.39+00:00
stein559 0 Reputation points
5 answers

MS Threat Modeling Tool Stencils

Is there a template containing stencils for Azure and for desktop applications, or can 2 stencils be loaded or combined? I have a medical device application with an on-premise and cloud component hosted in Azure. It seems when I load the Azure template,…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2020-07-06T16:49:53.79+00:00
Larry Greenspan 1 Reputation point
edited an answer 2025-11-04T12:28:27.61+00:00
Olga_Gh 10 Reputation points Microsoft Employee Admin
0 answers

Sale que mi cuenta no “existe”

Desde ayer Domingo 1 de noviembre del 2025 mi cuenta de Microsoft dejo de funcionar ya que se me cerraron las sesiones de todos los juegos y aplicaciones y al volver a intentar iniciar sesión me salía que la cuenta no existe y intente a crear de nuevo la…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-11-03T22:18:31.2566667+00:00
2 answers One of the answers was accepted by the question author.

Retirement of Sentinel in Azure Portal, transition to Microsoft Defender XDR portal

I am investigating the upcoming retirement (july 2026) of Microsoft Sentinel in the Azure Portal and its full migration to the Microsoft Defender XDR portal.As an MSSP, I currently use Azure Sentinel with Azure Lighthouse to manage multiple Sentinel…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-24T13:36:01.45+00:00
Patrick Bus 20 Reputation points
answered 2025-11-03T14:06:14.5666667+00:00
Patrick Bus 20 Reputation points
0 answers

[Defender for Cloud] Recomendação “Machines should have vulnerability findings resolved” - Inconsistente

Olá, pessoal. Desde sexta 10/10, notei um comportamento inconsistente na recomendação “Machines should have vulnerability findings resolved” no Defender for Cloud: Durante a varredura, várias VMs aparecem em “Recursos não íntegros” com vulnerabilidades…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-14T14:30:45.64+00:00
Gilson Guilherme Ribeiro Kley 0 Reputation points
commented 2025-11-03T12:58:45.0166667+00:00
Catherine Kyalo 2,465 Reputation points Microsoft Employee
1 answer

I Have deleted a VM and its associated RG and infrastructures yet, I keep receiving vulnerability alerts!

I have deleted the VM long time ago yet I keep receiving this: which related to None of the infrastructures related to TestEasyBuild longer exist!!! Any advice? Regards Roberto Scipioni Red Oak Consulting

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-29T12:18:00.2566667+00:00
Roberto Scipioni 0 Reputation points
edited an answer 2025-11-03T08:42:35.88+00:00
Catherine Kyalo 2,465 Reputation points Microsoft Employee
1 answer

Windows Defender consuming 40% CPU even though folders are excluded

Hi, We have a VM where MS Defender has already been turned off, and we had also configured folders to be excluded from scanning. But the Windows Performance Monitor still showed the MsMpEng process consuming 40% CPU at 8am this morning. At other times,…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-21T03:59:19.32+00:00
Foo Yuen 20 Reputation points
commented 2025-11-03T08:35:12.9866667+00:00
Catherine Kyalo 2,465 Reputation points Microsoft Employee
0 answers

When we add new stencil like GitHub, ArgoCD how do we know what threats will be associated with the new component?

I have design model in which I have Azure cloud services along with non-azure cloud services like Github, Jenkins, Argo CD etc. I want to add these stencils in MS Threat modeling template and also have threats and mitigations associated with it. How to…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-09T12:18:39.39+00:00
Geeta Nadgauda-Godbole 0 Reputation points
commented 2025-10-30T12:08:33.13+00:00
Catherine Kyalo 2,465 Reputation points Microsoft Employee
1 answer

What do the NIST CSF mapping numbers (e.g., “02”) in Azure Security Assessments represent?

While reviewing Azure Cloud Security Assessments, I noticed that the mappings to NIST CSF often show numbers such as “02.” I’m unsure where to look these up to find the corresponding NIST CSF control eg: PR.DS-01. Can someone clarify what these numbers…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-27T06:48:48.2133333+00:00
K.Ashok 0 Reputation points
commented 2025-10-28T07:22:46.7333333+00:00
Monalisha Jena 3,680 Reputation points Microsoft External Staff Moderator
4 answers

stop MS Defender from adding certain alerts to a multi-stage incident

We use Splunk SOAR to run enrichments on MS Defender alerts. There are 2 specific alerts that MS Defender is grouping together into a multi-stage incident. The problem is that we want to investigate each alert separately, and have alert-specific…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-15T09:36:12.7033333+00:00
Oswald, Michael 0 Reputation points
answered 2025-10-23T12:30:04.11+00:00
Andrew Blumhardt 10,066 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

oracle single sign on

i am trying to login on oracle for my job but it is giving me error message saying that single sign on has to be disable please help

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-09-23T19:21:00.4833333+00:00
Jessica L E Marshall 20 Reputation points
commented 2025-10-22T06:46:41.4933333+00:00
Naresh Koppisetti 0 Reputation points
0 answers

How to get an inbound/outbound traffic report for an endpoint device?

Hi All. I need to get a report for a user using a desktop in the office and laptop out of the office both devices in Azure with a Global Secure Access (GSA) agent installed. Thanks GR

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-21T16:03:39.32+00:00
Guitze H. Rodriguez 0 Reputation points
1 answer

JIT for RDP with Windows 11 AVD Pools

Hello, I am a newbie and set up my first Azure testing environment to see if Azure Virtual Desktop Pools will work for a new company project. I set up a Workspace pool and will need RDP access for testing and eventually for users if my tests are…

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
asked 2025-10-20T16:44:08.01+00:00
Ray German 0 Reputation points
commented 2025-10-21T14:56:50.3533333+00:00
Ray German 0 Reputation points