Skip to content

Commit 0c248ac

Browse files
committed
Security policy article updates
Updated content and images for the upcoming release.
1 parent 1a75aa4 commit 0c248ac

11 files changed

+20
-20
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -255,7 +255,7 @@
255255
href: workflow-automation.md
256256
- name: Disable a recommendation
257257
displayName: recommendation, disable, security, policy,
258-
href: tutorial-security-policy.md#disable-security-policies-and-disable-recommendations
258+
href: tutorial-security-policy.md#disable-a-security-recommendation
259259
- name: Exempt recommendations per resource, subscription, or management group
260260
displayName: disable, resource, exempt, recommendation
261261
href: exempt-resource.md
346 KB
Loading
322 KB
Loading
267 KB
Loading
220 KB
Loading

articles/defender-for-cloud/multi-factor-authentication-enforcement.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@ To investigate why the recommendations are still being generated, verify the fol
102102
### We're using a third-party MFA tool to enforce MFA. Why do we still get the Defender for Cloud recommendations?
103103
Defender for Cloud's MFA recommendations doesn't support third-party MFA tools (for example, DUO).
104104
105-
If the recommendations are irrelevant for your organization, consider marking them as "mitigated" as described in [Exempting resources and recommendations from your secure score](exempt-resource.md). You can also [disable a recommendation](tutorial-security-policy.md#disable-security-policies-and-disable-recommendations).
105+
If the recommendations are irrelevant for your organization, consider marking them as "mitigated" as described in [Exempting resources and recommendations from your secure score](exempt-resource.md). You can also [disable a recommendation](tutorial-security-policy.md#disable-a-security-recommendation).
106106
107107
### Why does Defender for Cloud show user accounts without permissions on the subscription as "requiring MFA"?
108108
Defender for Cloud's MFA recommendations refers to [Azure RBAC](../role-based-access-control/role-definitions-list.md) roles and the [Azure classic subscription administrators](../role-based-access-control/classic-administrators.md) role. Verify that none of the accounts have such roles.

articles/defender-for-cloud/release-notes-archive.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1424,7 +1424,7 @@ Security Center includes multiple recommendations to encrypt data at rest with c
14241424

14251425
Data in Azure is encrypted automatically using platform-managed keys, so the use of customer-managed keys should only be applied when required for compliance with a specific policy your organization is choosing to enforce.
14261426

1427-
With this change, the recommendations to use CMKs are now **disabled by default**. When relevant for your organization, you can enable them by changing the *Effect* parameter for the corresponding security policy to **AuditIfNotExists** or **Enforce**. Learn more in [Enable a security policy](tutorial-security-policy.md#enable-a-security-policy).
1427+
With this change, the recommendations to use CMKs are now **disabled by default**. When relevant for your organization, you can enable them by changing the *Effect* parameter for the corresponding security policy to **AuditIfNotExists** or **Enforce**. Learn more in [Enable a security recommendation](tutorial-security-policy.md#enable-a-security-recommendation).
14281428

14291429
This change is reflected in the names of the recommendation with a new prefix, **[Enable if required]**, as shown in the following examples:
14301430

articles/defender-for-cloud/review-security-recommendations.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ To get to the list of recommendations:
1717
- In the Defender for Cloud overview, select **Security posture** and then select **View recommendations** for the environment you want to improve.
1818
- Go to **Recommendations** in the Defender for Cloud menu.
1919

20-
You can search for specific recommendations by name. Use the search box and filters above the list of recommendations to find specific recommendations. Look at the [details of the recommendation](security-policy-concept.md#security-recommendation-details) to decide whether to [remediate it](implement-security-recommendations.md), [exempt resources](exempt-resource.md), or [disable the recommendation](tutorial-security-policy.md#disable-security-policies-and-disable-recommendations).
20+
You can search for specific recommendations by name. Use the search box and filters above the list of recommendations to find specific recommendations. Look at the [details of the recommendation](security-policy-concept.md#security-recommendation-details) to decide whether to [remediate it](implement-security-recommendations.md), [exempt resources](exempt-resource.md), or [disable the recommendation](tutorial-security-policy.md#disable-a-security-recommendation).
2121

2222
You can learn more by watching this video from the Defender for Cloud in the Field video series:
2323
- [Security posture management improvements](episode-four.md)

articles/defender-for-cloud/secure-score-security-controls.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -111,12 +111,12 @@ You can also [configure the Enforce and Deny options](prevent-misconfigurations.
111111

112112
The table below lists the security controls in Microsoft Defender for Cloud. For each control, you can see the maximum number of points you can add to your secure score if you remediate *all* of the recommendations listed in the control, for *all* of your resources.
113113

114-
The set of security recommendations provided with Defender for Cloud is tailored to the available resources in each organization's environment. You can [disable policies](tutorial-security-policy.md#disable-security-policies-and-disable-recommendations) and [exempt specific resources from a recommendation](exempt-resource.md) to further customize the recommendations.
114+
The set of security recommendations provided with Defender for Cloud is tailored to the available resources in each organization's environment. You can [disable recommendations](tutorial-security-policy.md#disable-a-security-recommendation) and [exempt specific resources from a recommendation](exempt-resource.md) to further customize the recommendations.
115115

116116
We recommend every organization carefully reviews their assigned Azure Policy initiatives.
117117

118118
> [!TIP]
119-
> For details about reviewing and editing your initiatives, see [Working with security policies](tutorial-security-policy.md).
119+
> For details about reviewing and editing your initiatives, see [manage security policies](tutorial-security-policy.md).
120120
121121
Even though Defender for Cloud's default security initiative, the Azure Security Benchmark, is based on industry best practices and standards, there are scenarios in which the built-in recommendations listed below might not completely fit your organization. It's sometimes necessary to adjust the default initiative - without compromising security - to ensure it's aligned with your organization's own policies, industry standards, regulatory standards, and benchmarks.<br><br>
122122

@@ -130,7 +130,7 @@ No. It won't change until you remediate all of the recommendations for a single
130130

131131
### If a recommendation isn't applicable to me, and I disable it in the policy, will my security control be fulfilled and my secure score updated?
132132

133-
Yes. We recommend disabling recommendations when they're inapplicable in your environment. For instructions on how to disable a specific recommendation, see [Disable security policies](./tutorial-security-policy.md#disable-security-policies-and-disable-recommendations).
133+
Yes. We recommend disabling recommendations when they're inapplicable in your environment. For instructions on how to disable a specific recommendation, see [Disable security recommendations](./tutorial-security-policy.md#disable-a-security-recommendation).
134134

135135
### If a security control offers me zero points towards my secure score, should I ignore it?
136136

articles/defender-for-cloud/security-policy-concept.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -127,5 +127,5 @@ If you're reviewing the list of recommendations on our [Security recommendations
127127
This page explained, at a high level, the basic concepts and relationships between policies, initiatives, and recommendations. For related information, see:
128128

129129
- [Create custom initiatives](custom-security-policies.md)
130-
- [Disable security policies to disable recommendations](tutorial-security-policy.md#disable-security-policies-and-disable-recommendations)
130+
- [Disable security recommendations](tutorial-security-policy.md#disable-a-security-recommendation)
131131
- [Learn how to edit a security policy in Azure Policy](../governance/policy/tutorials/create-and-manage.md)

0 commit comments

Comments
 (0)