1,529 questions with Microsoft Defender for Cloud-related tags

Sort by: Updated
0 answers

Email sent by External User are being Quarantined by EOP

Hello, We have recently observed a significant increase in legitimate emails being quarantined by Microsoft 365 Defender (EOP) for both Exchange Online and on-premises users. These emails are being flagged by the anti-spam policies, and this behavior…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-30T08:31:24.4133333+00:00
Parsian02 20 Reputation points
commented 2025-05-02T18:51:01.3966667+00:00
Bandela Siri Chandana 2,560 Reputation points Microsoft External Staff
1 answer

Issue retrieving CVE details using responseType: reduced in Defender EASM Assets API

I'm working with the Microsoft Defender External Attack Surface Management (EASM) API, specifically the assets endpoint. When I make a request using responseType: reduced and apply a filter for a specific CVE ID, the response does not include any…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-28T08:07:52.6366667+00:00
Dev Parmar 0 Reputation points
commented 2025-05-02T18:06:58.5266667+00:00
Navya 17,900 Reputation points Microsoft External Staff
0 answers

Anonymous User Succeeded Download Limit

My company received an alert that a user succeeded the file download limit (total was 58/min). Upon investigating the alert in Defender, the user ID is displaying as…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-05-02T14:46:08.9633333+00:00
ShallowCopy 25 Reputation points
0 answers

How to deactivate Microsoft Defender for Endpoint in Azure for a specific resource group?

Hello community, We are currently using Microsoft Defender for Servers – Plan 2 in Azure, which is active and enforced at the subscription level. We have a use case where we need to exclude or deactivate Defender for Endpoint (MDE) for a specific…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-30T15:16:33.4266667+00:00
Hotak, Mustafa 0 Reputation points
commented 2025-05-02T11:30:18.6533333+00:00
Rukmini 1,616 Reputation points Microsoft External Staff
1 answer

Legitimacy and Purpose of Azure Defender PowerShell Script Execution

Hello Microsoft Community, I noticed that on my Windows Server, the following file is triggering PowerShell script execution: C:\Packages\Plugins\Microsoft.Azure.AzureDefenderForServers.MDE.Windows\1.0.9.1\HandlerUtilities.psm1 This script seems to be…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-05-01T10:57:36.7833333+00:00
Hitesh Sungar 0 Reputation points
answered 2025-05-01T12:54:49.9233333+00:00
Michael Morten Sonne 605 Reputation points MVP
0 answers

Offboarding VMs from Defender for Servers Plan 2

After enabling Defender for Servers Plan 2 on a subscription for testing, the plan has been deactivated; however, the servers are still visible in the Defender for Server Portal. In the Azure portal, the MDE.Windows extension remains installed on the VM.…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-05-01T10:02:46.0366667+00:00
PM 0 Reputation points
commented 2025-05-01T12:48:32.4833333+00:00
Jose Benjamin Solis Nolasco 1,476 Reputation points
0 answers

Update Defender for SQL Servers on Machines plan configuration ,What action take for this protection plan

We got email from client for Update Defender for SQL Servers on Machines plan configuration is this update applicable to our environment and if yes what action we have to take, please provide the steps ?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-05-01T09:26:51.1633333+00:00
Venkata Subbareddy 0 Reputation points
commented 2025-05-01T12:44:09.3766667+00:00
Jose Benjamin Solis Nolasco 1,476 Reputation points
0 answers

Legitimacy and Documentation of PowerShell Script in Windows Defender ATP Data Collection Path

Hi Team, We’ve observed the following script being executed on several servers: C:\ProgramData\Microsoft\Windows Defender Advanced Threat…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-05-01T10:59:20.1733333+00:00
Hitesh Sungar 0 Reputation points
0 answers

how to assign an Owner to a recommendation in defender.

Hello, • When i try to set an owner and due date for a recommendation, the owner field is not been shown, only the due date. • Since i was not able to do it manually, i tried to do it with a governance rule. • I was able to create the governance…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-28T08:38:43.1566667+00:00
Mimoun Mendoughe 0 Reputation points
commented 2025-04-30T19:59:45.42+00:00
Mimoun Mendoughe 0 Reputation points
1 answer

PCI Policy Not Displaying on Regulatory Compliance Dashboard

I enabled the PCI policy under Regulatory Compliance and initiated it, but it's still not appearing on the Regulatory Compliance dashboard.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-19T13:32:04.52+00:00
AA 5 Reputation points
commented 2025-04-30T17:17:01.3+00:00
AA 5 Reputation points
1 answer

Deploying Microsoft Defender for Endpoint for Computers for computers already using another 3rd party EDR or XDR?

After reading this: https://techcommunity.microsoft.com/event/microsoftintuneevents/unified-security-intune--microsoft-defender-for-endpoint/4376209   Can I deploy and integrate all of my global Workstations (PC and Laptop) that are already secured and…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-29T06:17:30.2566667+00:00
EnterpriseArchitect 5,766 Reputation points
answered 2025-04-30T15:58:49.8733333+00:00
Jyotishree Moharana 795 Reputation points Microsoft External Staff
1 answer

Set parameters for security policy

I want to add NCSC Cyber Assessment Framework (CAF) v3.2 to Regulatory Compliance for all subscriptions. When I toggle the standard to "On" I'm presented with a fly-out titled "Set parameters" (see attached screenshot). However, I…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-25T15:45:38.4066667+00:00
Steven Rook 0 Reputation points
commented 2025-04-30T13:42:32.82+00:00
Sakshi Devkante 3,335 Reputation points Microsoft External Staff
1 answer

How to block an IPv4 blacklisted IP.

I have an IPv4 address that keeps trying to get into our mailboxes. So far the account keeps locking out instead of letting them in. What is the typical solution for a bad address trying to get in? Block them or is there something else that should be…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-28T14:58:42.5+00:00
Ford, Edward 6 Reputation points
commented 2025-04-30T13:41:35.4966667+00:00
Jose Benjamin Solis Nolasco 1,476 Reputation points
1 answer

How to delete devices without them popping back up?

I have configured sensor with subnet mask then within Azure portal for Defender4IOT yet workstations I do not want to monitor continues to resurface.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-28T15:24:26.92+00:00
Shaun Lewis 0 Reputation points
answered 2025-04-29T09:35:09.06+00:00
Venkata Jagadeep 1,085 Reputation points Microsoft External Staff
0 answers

how to Protect my Docker containers from Kinsing - Kdevtmpfsi crypto mining malware

how to Protect my Docker containers from Kinsing - Kdevtmpfsi crypto mining malware I have tried everything and it seems to keep re-appearing on my container.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-28T08:00:53.1766667+00:00
Jinal Shah 0 Reputation points
1 answer

Graph API Error – BadRequest on runHuntingQuery with DeviceProcessEvents

We are encountering a BadRequest error when invoking the /security/runHuntingQuery endpoint via the Microsoft Graph API SDK (Java). The query references DeviceProcessEvents, but the API response indicates a semantic…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-23T11:08:35.04+00:00
Jovkhar Issayev 0 Reputation points
commented 2025-04-25T22:21:17.4333333+00:00
Kancharla Saiteja 3,565 Reputation points Microsoft External Staff
1 answer One of the answers was accepted by the question author.

duplicate devices in Microsoft Defender Device Inventory

In the Microsoft Defender portal Device Inventory page for my tenant there are several instances where one and the same PC appears twice with different names. One entry shows the default name "desktop-" + 7 random characters assigned by Windows…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-24T08:29:19.5433333+00:00
Tilman Schmidt 100 Reputation points
commented 2025-04-25T07:54:46.69+00:00
Tilman Schmidt 100 Reputation points
1 answer

How to remove unwanted device from sensor?

How do you remove devices that do not need monitoring or alerts?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-23T22:36:02.15+00:00
Shaun Lewis 0 Reputation points
answered 2025-04-24T10:56:56.0066667+00:00
Venkata Jagadeep 1,085 Reputation points Microsoft External Staff
1 answer

Access to the Microsoft Defender XDR Portal is currently not available.

We are currently unable to access the Microsoft Defender XDR Portal when attempting to sign in using a user account that holds the Global Administrator role in Microsoft Entra ID. URL:https://security.microsoft.com Error Message: "The selected user…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-23T01:24:35.21+00:00
未来 坂野 0 Reputation points
answered 2025-04-23T11:44:09.19+00:00
Venkata Jagadeep 1,085 Reputation points Microsoft External Staff
1 answer

Unable to create AWS and GCP connectors in Defender for Cloud

Hello, I'm trying to connect an AWS account and a GCP project to Defender for Cloud. My roles is contributor and security admin, but I get an insufficient permissions issue in both cases: Failed to create security connector. Error: 'Insufficient…

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,529 questions
asked 2025-04-22T11:22:38.5766667+00:00
Ragusa, Carmelo 0 Reputation points
commented 2025-04-22T17:54:33.6566667+00:00
Navya 17,900 Reputation points Microsoft External Staff