1,529 questions with Microsoft Defender for Cloud-related tags
Email sent by External User are being Quarantined by EOP
Hello, We have recently observed a significant increase in legitimate emails being quarantined by Microsoft 365 Defender (EOP) for both Exchange Online and on-premises users. These emails are being flagged by the anti-spam policies, and this behavior…
Microsoft Defender for Cloud
Issue retrieving CVE details using responseType: reduced in Defender EASM Assets API
I'm working with the Microsoft Defender External Attack Surface Management (EASM) API, specifically the assets endpoint. When I make a request using responseType: reduced and apply a filter for a specific CVE ID, the response does not include any…
Microsoft Defender for Cloud
Anonymous User Succeeded Download Limit
My company received an alert that a user succeeded the file download limit (total was 58/min). Upon investigating the alert in Defender, the user ID is displaying as…
Microsoft Defender for Cloud
How to deactivate Microsoft Defender for Endpoint in Azure for a specific resource group?
Hello community, We are currently using Microsoft Defender for Servers – Plan 2 in Azure, which is active and enforced at the subscription level. We have a use case where we need to exclude or deactivate Defender for Endpoint (MDE) for a specific…
Microsoft Defender for Cloud
Legitimacy and Purpose of Azure Defender PowerShell Script Execution
Hello Microsoft Community, I noticed that on my Windows Server, the following file is triggering PowerShell script execution: C:\Packages\Plugins\Microsoft.Azure.AzureDefenderForServers.MDE.Windows\1.0.9.1\HandlerUtilities.psm1 This script seems to be…
Microsoft Defender for Cloud

Offboarding VMs from Defender for Servers Plan 2
After enabling Defender for Servers Plan 2 on a subscription for testing, the plan has been deactivated; however, the servers are still visible in the Defender for Server Portal. In the Azure portal, the MDE.Windows extension remains installed on the VM.…
Microsoft Defender for Cloud

Update Defender for SQL Servers on Machines plan configuration ,What action take for this protection plan
We got email from client for Update Defender for SQL Servers on Machines plan configuration is this update applicable to our environment and if yes what action we have to take, please provide the steps ?
Microsoft Defender for Cloud

Legitimacy and Documentation of PowerShell Script in Windows Defender ATP Data Collection Path
Hi Team, We’ve observed the following script being executed on several servers: C:\ProgramData\Microsoft\Windows Defender Advanced Threat…
Microsoft Defender for Cloud
how to assign an Owner to a recommendation in defender.
Hello, • When i try to set an owner and due date for a recommendation, the owner field is not been shown, only the due date. • Since i was not able to do it manually, i tried to do it with a governance rule. • I was able to create the governance…
Microsoft Defender for Cloud
PCI Policy Not Displaying on Regulatory Compliance Dashboard
I enabled the PCI policy under Regulatory Compliance and initiated it, but it's still not appearing on the Regulatory Compliance dashboard.
Microsoft Defender for Cloud
Deploying Microsoft Defender for Endpoint for Computers for computers already using another 3rd party EDR or XDR?
After reading this: https://techcommunity.microsoft.com/event/microsoftintuneevents/unified-security-intune--microsoft-defender-for-endpoint/4376209 Can I deploy and integrate all of my global Workstations (PC and Laptop) that are already secured and…
Microsoft Defender for Cloud

Set parameters for security policy
I want to add NCSC Cyber Assessment Framework (CAF) v3.2 to Regulatory Compliance for all subscriptions. When I toggle the standard to "On" I'm presented with a fly-out titled "Set parameters" (see attached screenshot). However, I…
Microsoft Defender for Cloud
How to block an IPv4 blacklisted IP.
I have an IPv4 address that keeps trying to get into our mailboxes. So far the account keeps locking out instead of letting them in. What is the typical solution for a bad address trying to get in? Block them or is there something else that should be…
Microsoft Defender for Cloud

How to delete devices without them popping back up?
I have configured sensor with subnet mask then within Azure portal for Defender4IOT yet workstations I do not want to monitor continues to resurface.
Microsoft Defender for Cloud
how to Protect my Docker containers from Kinsing - Kdevtmpfsi crypto mining malware
how to Protect my Docker containers from Kinsing - Kdevtmpfsi crypto mining malware I have tried everything and it seems to keep re-appearing on my container.
Microsoft Defender for Cloud
Graph API Error – BadRequest on runHuntingQuery with DeviceProcessEvents
We are encountering a BadRequest error when invoking the /security/runHuntingQuery endpoint via the Microsoft Graph API SDK (Java). The query references DeviceProcessEvents, but the API response indicates a semantic…
Microsoft Defender for Cloud
duplicate devices in Microsoft Defender Device Inventory
In the Microsoft Defender portal Device Inventory page for my tenant there are several instances where one and the same PC appears twice with different names. One entry shows the default name "desktop-" + 7 random characters assigned by Windows…
Microsoft Defender for Cloud
How to remove unwanted device from sensor?
How do you remove devices that do not need monitoring or alerts?
Microsoft Defender for Cloud
Access to the Microsoft Defender XDR Portal is currently not available.
We are currently unable to access the Microsoft Defender XDR Portal when attempting to sign in using a user account that holds the Global Administrator role in Microsoft Entra ID. URL:https://security.microsoft.com Error Message: "The selected user…
Microsoft Defender for Cloud
Unable to create AWS and GCP connectors in Defender for Cloud
Hello, I'm trying to connect an AWS account and a GCP project to Defender for Cloud. My roles is contributor and security admin, but I get an insufficient permissions issue in both cases: Failed to create security connector. Error: 'Insufficient…