Skip to content

Commit 67ffc6b

Browse files
Merge pull request #226541 from berlihie/patch-2
Two feature deprecations for alerts
2 parents 74893dd + 91ae90f commit 67ffc6b

File tree

1 file changed

+24
-0
lines changed

1 file changed

+24
-0
lines changed

articles/defender-for-cloud/upcoming-changes.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,32 @@ If you're looking for the latest release notes, you'll find them in the [What's
2020
|--|--|
2121
| [Recommendation to find vulnerabilities in running container images to be released for General Availability (GA)](#recommendation-to-find-vulnerabilities-in-running-container-images-to-be-released-for-general-availability-ga) | February 2023 |
2222
| [The built-in policy [Preview]: Private endpoint should be configured for Key Vault is set to be deprecated](#the-built-in-policy-preview-private-endpoint-should-be-configured-for-key-vault-is-set-to-be-deprecated) | February 2023 |
23+
| [Three alerts in Defender for ARM plan are set to be deprecated](#three-alerts-in-defender-for-arm-plan-are-set-to-be-deprecated) | March 2023 |
24+
| [Alerts automatic export to Log Analytics workspace is set to be deprecated](#alerts-automatic-export-to-log-analytics-workspace-is-set-to-be-deprecated) | March 2023 |
2325
| [Deprecation and improvement of selected alerts for Windows and Linux Servers](#deprecation-and-improvement-of-selected-alerts-for-windows-and-linux-servers) | April 2023 |
2426

27+
### Three alerts in Defender for ARM plan are set to be deprecated
28+
29+
**Estimated date for change: March 2023**
30+
31+
As we continue to improve the quality of our alerts, the following three alerts from the Defender for ARM plan are set to be deprecated:
32+
1. `Activity from a risky IP address (ARM.MCAS_ActivityFromAnonymousIPAddresses)`
33+
1. `Activity from infrequent country (ARM.MCAS_ActivityFromInfrequentCountry)`
34+
1. `Impossible travel activity (ARM.MCAS_ImpossibleTravelActivity)`
35+
36+
You can learn more details about each of these alerts from the [alerts reference list](alerts-reference.md#alerts-resourcemanager).
37+
38+
In the scenario where an activity from a suspicious IP address is detected, one of the following Defender for ARM plan alert `Azure Resource Manager operation from suspicious IP address` or ' Azure Resource Manager operation from suspicious proxy IP address' will be presented.
39+
40+
### Alerts automatic export to Log Analytics workspace is set to be deprecated
41+
42+
**Estimated date for change: March 2023**
43+
44+
Currently, Defender for Cloud security alerts are automatically exported to a default Log Analytics workspace on the resource level. This causes an indeterministic behavior and therefore, this feature is set to be deprecated.
45+
46+
You can export your security alerts to a dedicated Log Analytics workspace with the [Continuous Export](continuous-export.md#set-up-a-continuous-export) feature.
47+
If you have already configured continuous export of your alerts to a Log Analytics workspace, no further action is required.
48+
2549
### Recommendation to find vulnerabilities in running container images to be released for General Availability (GA)
2650

2751
**Estimated date for change: February 2023**

0 commit comments

Comments
 (0)