Skip to content

Commit 63177fd

Browse files
Update upcoming-changes.md
1 parent 3bb6685 commit 63177fd

File tree

1 file changed

+7
-17
lines changed

1 file changed

+7
-17
lines changed

articles/defender-for-cloud/upcoming-changes.md

Lines changed: 7 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Important upcoming changes
33
description: Upcoming changes to Microsoft Defender for Cloud that you might need to be aware of and for which you might need to plan
44
ms.topic: overview
5-
ms.date: 01/09/2024
5+
ms.date: 01/10/2024
66
---
77

88
# Important upcoming changes to Microsoft Defender for Cloud
@@ -28,12 +28,6 @@ If you're looking for the latest release notes, you can find them in the [What's
2828
| [Four new recommendations for Azure Stack HCI resource type](#four-new-recommendations-for-azure-stack-hci-resource-type) | January 9, 2024 | January 2024 |
2929
| [Defender for Servers built-in vulnerability assessment (Qualys) retirement path](#defender-for-servers-built-in-vulnerability-assessment-qualys-retirement-path) | January 9, 2024 | May 2024 |
3030
| [Retirement of the Defender for Cloud Containers Vulnerability Assessment powered by Qualys](#retirement-of-the-defender-for-cloud-containers-vulnerability-assessment-powered-by-qualys) | January 9, 2023 | March 2024 |
31-
32-
| [Four new recommendations for Azure Stack HCI resource type](#four-new-recommendations-for-azure-stack-hci-resource-type) | January 9, 2024 | January 2024 |
33-
34-
| [Defender for Servers built-in vulnerability assessment (Qualys) retirement path](#defender-for-servers-built-in-vulnerability-assessment-qualys-retirement-path) | January 9, 2024 | May 2024 |
35-
| [Retirement of the Defender for Cloud Containers Vulnerability Assessment powered by Qualys](#retirement-of-the-defender-for-cloud-containers-vulnerability-assessment-powered-by-qualys) | January 9, 2023 | March 2024 |
36-
3731
| [New version of Defender Agent for Defender for Containers](#new-version-of-defender-agent-for-defender-for-containers) | January 4, 2024 | February 2024 |
3832
| [Upcoming change for the Defender for Cloud’s multicloud network requirements](#upcoming-change-for-the-defender-for-clouds-multicloud-network-requirements) | January 3, 2024 | May 2024 |
3933
| [Deprecation and severity changes to security alerts](#deprecation-and-severity-changes-to-security-alerts) | December 27, 2023 | January 2024 |
@@ -47,23 +41,20 @@ If you're looking for the latest release notes, you can find them in the [What's
4741
| [Deprecating two security incidents](#deprecating-two-security-incidents) | | November 2023 |
4842
| [Defender for Cloud plan and strategy for the Log Analytics agent deprecation](#defender-for-cloud-plan-and-strategy-for-the-log-analytics-agent-deprecation) | | August 2024 |
4943

50-
5144
## Four new recommendations for Azure Stack HCI resource type
5245

53-
**Announcement date: January 9, 2024**
46+
**Announcement date: January 10, 2024**
5447

55-
**Estimated date for change: January 2024**
48+
**Estimated date for change: February 2024**
5649

5750
Azure Stack HCI is set to be a new resource type that can be managed through Microsoft Defender for Cloud. We're adding 4 recommendations that are specific to the HCI resource type:
5851

5952
| Recommendation | Description | Severity |
6053
|----------|----------|----------|
61-
| Azure Stack HCI servers should meet Secured-core requirements | Ensure that all Azure Stack HCI servers meet the Secured-core requirements. (Related policy: [Guest Configuration extension should be installed on machines - Microsoft Azure](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/GenericRecommendationDetailsBlade/assessmentKey/6c99f570-2ce7-46bc-8175-cde013df43bc)) | Low |
62-
| Enforce consistent application control policies on Azure Stack HCI servers | At a minimum, apply the Microsoft WDAC base policy in enforced mode on all Azure Stack HCI servers. Applied Windows Defender Application Control (WDAC) application control policies must be consistent across servers in the same cluster. | High |
63-
| Encrypt volumes on Azure Stack HCI systems | Use BitLocker to encrypt the OS and data volumes on Azure Stack HCI systems | High |
64-
| Protect host and VM networking on Azure Stack HCI systems | Protect data on the Azure Stack HCI host’s network and on virtual machine network connections. | Low |
65-
66-
Learn more about how to use [Defender for App Service to protect your Azure App Service web apps and APIs](defender-for-app-service-introduction.md).
54+
| Azure Stack HCI servers should meet secured-core requirements | Ensure that all Azure Stack HCI servers meet the secured-core requirements. (Related policy: [Guest Configuration extension should be installed on machines - Microsoft Azure](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/GenericRecommendationDetailsBlade/assessmentKey/6c99f570-2ce7-46bc-8175-cde013df43bc)) | Low |
55+
| Azure Stack HCI servers should have consistently enforced application control policies | At a minimum, apply the Microsoft WDAC base policy in enforced mode on all Azure Stack HCI servers. Applied Windows Defender Application Control (WDAC) application control policies must be consistent across servers in the same cluster. | High |
56+
| Azure Stack HCI systems should have encrypted volumes | Use BitLocker to encrypt the OS and data volumes on Azure Stack HCI systems | High |
57+
| Host and VM networking should be protected on Azure Stack HCI systems | Protect data on the Azure Stack HCI host’s network and on virtual machine network connections. | Low |
6758

6859
## Defender for Servers built-in vulnerability assessment (Qualys) retirement path
6960

@@ -91,7 +82,6 @@ For more information about transitioning to our new container vulnerability asse
9182

9283
For common questions about the transition to Microsoft Defender Vulnerability Management, see [Common questions about the Microsoft Defender Vulnerability Management solution](common-questions-microsoft-defender-vulnerability-management.md).
9384

94-
9585
## New version of Defender Agent for Defender for Containers
9686

9787
**Announcement date: January 4, 2024**

0 commit comments

Comments
 (0)