You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/recommendations-reference.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: This article lists all Microsoft Defender for Cloud security recomm
4
4
author: dcurwin
5
5
ms.service: defender-for-cloud
6
6
ms.topic: reference
7
-
ms.date: 03/13/2024
7
+
ms.date: 03/31/2024
8
8
ms.author: dacurwin
9
9
ms.custom: generated
10
10
ai-usage: ai-assisted
@@ -659,17 +659,17 @@ Learn more about [Trusted launch for Azure virtual machines](../virtual-machines
659
659
660
660
**Severity**: High
661
661
662
-
### [[Preview]: Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/GenericRecommendationDetailsBlade/assessmentKey/a40cc620-e72c-fdf4-c554-c6ca2cd705c0)
662
+
### [Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/GenericRecommendationDetailsBlade/assessmentKey/a40cc620-e72c-fdf4-c554-c6ca2cd705c0)
663
663
664
664
**Description**: By default, a virtual machine's OS and data disks are encrypted-at-rest using platform-managed keys; temp disks and data caches aren't encrypted, and data isn't encrypted when flowing between compute and storage resources. Use Azure Disk Encryption or EncryptionAtHost to encrypt all this data. Visit [https://aka.ms/diskencryptioncomparison](https://aka.ms/diskencryptioncomparison) to compare encryption offerings. This policy requires two prerequisites to be deployed to the policy assignment scope. For details, visit [https://aka.ms/gcpol](https://aka.ms/gcpol).
665
-
(Related policy: [[Preview]: Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2fproviders%2fmicrosoft.authorization%2fpolicyDefinitions%2fca88aadc-6e2b-416c-9de2-5a0f01d1693f)).
665
+
(Related policy: [Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2fproviders%2fmicrosoft.authorization%2fpolicyDefinitions%2fca88aadc-6e2b-416c-9de2-5a0f01d1693f)).
666
666
667
667
**Severity**: High
668
668
669
-
### [[Preview]: Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/GenericRecommendationDetailsBlade/assessmentKey/0cb5f317-a94b-6b80-7212-13a9cc8826af)
669
+
### [Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/GenericRecommendationDetailsBlade/assessmentKey/0cb5f317-a94b-6b80-7212-13a9cc8826af)
670
670
671
671
**Description**: By default, a virtual machine's OS and data disks are encrypted-at-rest using platform-managed keys; temp disks and data caches aren't encrypted, and data isn't encrypted when flowing between compute and storage resources. Use Azure Disk Encryption or EncryptionAtHost to encrypt all this data. Visit [https://aka.ms/diskencryptioncomparison](https://aka.ms/diskencryptioncomparison) to compare encryption offerings. This policy requires two prerequisites to be deployed to the policy assignment scope. For details, visit [https://aka.ms/gcpol](https://aka.ms/gcpol).
672
-
(Related policy: [[Preview]: Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2fproviders%2fMicrosoft.Authorization%2fpolicyDefinitions%2f3dc5edcd-002d-444c-b216-e123bbfa37c0)).
672
+
(Related policy: [Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2fproviders%2fMicrosoft.Authorization%2fpolicyDefinitions%2f3dc5edcd-002d-444c-b216-e123bbfa37c0)).
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/release-notes.md
+24-1Lines changed: 24 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Release notes
3
3
description: This page is updated frequently with the latest updates in Defender for Cloud.
4
4
ms.topic: overview
5
-
ms.date: 03/25/2024
5
+
ms.date: 03/31/2024
6
6
---
7
7
8
8
# What's new in Microsoft Defender for Cloud?
@@ -20,6 +20,29 @@ To learn about *planned* changes that are coming soon to Defender for Cloud, see
20
20
21
21
If you're looking for items older than six months, you can find them in the [Archive for What's new in Microsoft Defender for Cloud](release-notes-archive.md).
22
22
23
+
## April 2024
24
+
25
+
|Date | Update |
26
+
|--|--|
27
+
| April 30 | General Availability of Unified Disk Encryption recommendations[General Availability of Unified Disk Encryption recommendations](#general-availability-of-unified-disk-encryption-recommendations)|
28
+
29
+
### General Availability of Unified Disk Encryption recommendations
30
+
31
+
April 30, 2024
32
+
33
+
The following Unified Disk Encryption recommendations are now generally available (GA) within Azure Public Cloud. The recommendations enable customers to audit encryption compliance of virtual machines with Azure Disk Encryption or EncryptionAtHost.
34
+
35
+
| Recommendation name | Assessment key |
36
+
| ---- | ---- |
37
+
|[Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost](recommendations-reference.md#linux-virtual-machines-should-enable-azure-disk-encryption-or-encryptionathosthttpsmsportalazurecomviewmicrosoft_azure_securitygenericrecommendationdetailsbladeassessmentkeya40cc620-e72c-fdf4-c554-c6ca2cd705c0)| a40cc620-e72c-fdf4-c554-c6ca2cd705c0 |
38
+
|[Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost](recommendations-reference.md#windows-virtual-machines-should-enable-azure-disk-encryption-or-encryptionathosthttpsmsportalazurecomviewmicrosoft_azure_securitygenericrecommendationdetailsbladeassessmentkey0cb5f317-a94b-6b80-7212-13a9cc8826af)| 0cb5f317-a94b-6b80-7212-13a9cc8826af |
39
+
40
+
Azure Disk Encryption (ADE) and EncryptionAtHost provide encryption at rest coverage, as described in [Overview of managed disk encryption options - Azure Virtual Machines](/azure/virtual-machines/disk-encryption-overview), and we recommend enabling either of these on virtual machines.
41
+
42
+
The recommendations depend on [Guest configuration](/azure/governance/machine-configuration/overview). The recommendations in this document are dependent on the configuration of the guest operating system. To ensure that the recommendations can be properly assessed for compliance, it is necessary to enable the required prerequisites on all virtual machines.
43
+
44
+
These recommendations replace the recommendation [Virtual machines should encrypt temp disks, caches, and data flows between Compute and Storage resources](recommendations-reference.md#virtual-machines-should-encrypt-temp-disks-caches-and-data-flows-between-compute-and-storage-resourceshttpsportalazurecomblademicrosoft_azure_securityrecommendationsbladeassessmentkeyd57a4221-a804-52ca-3dea-768284f06bb7).
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/upcoming-changes.md
-22Lines changed: 0 additions & 22 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,7 +25,6 @@ If you're looking for the latest release notes, you can find them in the [What's
25
25
26
26
| Planned change | Announcement date | Estimated date for change |
27
27
|--|--|--|
28
-
|[General Availability of Unified Disk Encryption recommendations](#general-availability-of-unified-disk-encryption-recommendations)| March 28, 2024 | April 30, 2024 |
29
28
|[Defender for open-source relational databases updates](#defender-for-open-source-relational-databases-updates)| March 6, 2024 | April, 2024 |
30
29
|[Changes in where you access Compliance offerings and Microsoft Actions](#changes-in-where-you-access-compliance-offerings-and-microsoft-actions)| March 3, 2024 | September 30, 2025 |
31
30
|[Microsoft Security Code Analysis (MSCA) is no longer operational](#microsoft-security-code-analysis-msca-is-no-longer-operational)| February 26, 2024 | February 26, 2024 |
@@ -46,27 +45,6 @@ If you're looking for the latest release notes, you can find them in the [What's
46
45
|[Deprecating two security incidents](#deprecating-two-security-incidents)|| November 2023 |
47
46
|[Defender for Cloud plan and strategy for the Log Analytics agent deprecation](#defender-for-cloud-plan-and-strategy-for-the-log-analytics-agent-deprecation)|| August 2024 |
48
47
49
-
## General Availability of Unified Disk Encryption recommendations
50
-
51
-
**Announcement date: March 28, 2024**
52
-
53
-
**Estimated date of change: April 30, 2024**
54
-
55
-
Unified Disk Encryption recommendations will be released for General Availability (GA) within Azure Public Cloud in April 2024. The recommendations enable customers to audit encryption compliance of virtual machines with Azure Disk Encryption or EncryptionAtHost.
56
-
57
-
**Recommendations moving to GA:**
58
-
59
-
| Recommendation name | Assessment key |
60
-
| ---- | ---- |
61
-
| Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost | a40cc620-e72c-fdf4-c554-c6ca2cd705c0 |
62
-
| Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost | 0cb5f317-a94b-6b80-7212-13a9cc8826af |
63
-
64
-
Azure Disk Encryption (ADE) and EncryptionAtHost provide encryption at rest coverage, as described in [Overview of managed disk encryption options - Azure Virtual Machines](/azure/virtual-machines/disk-encryption-overview), and we recommend enabling either of these on virtual machines.
65
-
66
-
The recommendations depend on [Guest Configuration](/azure/governance/machine-configuration/overview). Prerequisites to onboard to Guest configuration should be enabled on virtual machines for the recommendations to complete compliance scans as expected.
67
-
68
-
These recommendations will replace the recommendation "Virtual machines should encrypt temp disks, caches, and data flows between Compute and Storage resources."
69
-
70
48
## Defender for open-source relational databases updates
0 commit comments