You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/upcoming-changes.md
+24Lines changed: 24 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -20,8 +20,32 @@ If you're looking for the latest release notes, you'll find them in the [What's
20
20
|--|--|
21
21
|[Recommendation to find vulnerabilities in running container images to be released for General Availability (GA)](#recommendation-to-find-vulnerabilities-in-running-container-images-to-be-released-for-general-availability-ga)| February 2023 |
22
22
|[The built-in policy [Preview]: Private endpoint should be configured for Key Vault is set to be deprecated](#the-built-in-policy-preview-private-endpoint-should-be-configured-for-key-vault-is-set-to-be-deprecated)| February 2023 |
23
+
|[Three alerts in Defender for ARM plan are set to be deprecated](#three-alerts-in-defender-for-arm-plan-are-set-to-be-deprecated)| March 2023 |
24
+
|[Alerts automatic export to Log Analytics workspace is set to be deprecated](#alerts-automatic-export-to-log-analytics-workspace-is-set-to-be-deprecated)| March 2023 |
23
25
|[Deprecation and improvement of selected alerts for Windows and Linux Servers](#deprecation-and-improvement-of-selected-alerts-for-windows-and-linux-servers)| April 2023 |
24
26
27
+
### Three alerts in Defender for ARM plan are set to be deprecated
28
+
29
+
**Estimated date for change: March 2023**
30
+
31
+
As we continue to improve the quality of our alerts, the following three alerts from the Defender for ARM plan are set to be deprecated:
32
+
1.`Activity from a risky IP address (ARM.MCAS_ActivityFromAnonymousIPAddresses)`
33
+
1.`Activity from infrequent country (ARM.MCAS_ActivityFromInfrequentCountry)`
You can learn more details about each of these alerts from the [alerts reference list](alerts-reference.md#alerts-resourcemanager).
37
+
38
+
In the scenario where an activity from a suspicious IP address is detected, one of the following Defender for ARM plan alert `Azure Resource Manager operation from suspicious IP address` or ' Azure Resource Manager operation from suspicious proxy IP address' will be presented.
39
+
40
+
### Alerts automatic export to Log Analytics workspace is set to be deprecated
41
+
42
+
**Estimated date for change: March 2023**
43
+
44
+
Currently, Defender for Cloud security alerts are automatically exported to a default Log Analytics workspace on the resource level. This causes an indeterministic behavior and therefore, this feature is set to be deprecated.
45
+
46
+
You can export your security alerts to a dedicated Log Analytics workspace with the [Continuous Export](continuous-export.md#set-up-a-continuous-export) feature.
47
+
If you have already configured continuous export of your alerts to a Log Analytics workspace, no further action is required.
48
+
25
49
### Recommendation to find vulnerabilities in running container images to be released for General Availability (GA)
0 commit comments