You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
You must update Log Analytics agent to the latest version, by following below steps:
179
179
180
-
Check the current version of Log Analytics agent for your machine: Go to the installation path - *C:\ProgramFiles\Microsoft Monitoring Agent\Agent* and right-click on *HealthService.exe* to check **Properties**. In the **Details** tab, the field **Product version** provides version number of the Log Analytics agent.
180
+
1.Check the current version of Log Analytics agent for your machine: Go to the installation path - *C:\ProgramFiles\Microsoft Monitoring Agent\Agent* and right-click on *HealthService.exe* to check **Properties**. In the **Details** tab, the field **Product version** provides version number of the Log Analytics agent.
181
181
182
-
If your Log Analytics agent version is prior to [10.20.18053 (bundle) and 1.0.18053.0 (extension)](../../virtual-machines/extensions/oms-windows.md#agent-and-vm-extension-version), upgrade to the latest version of the Windows Log Analytics agent, following these [guidelines](../../azure-monitor/agents/agent-manage.md).
182
+
1.If your Log Analytics agent version is prior to [10.20.18053 (bundle) and 1.0.18053.0 (extension)](../../virtual-machines/extensions/oms-windows.md#agent-and-vm-extension-version), upgrade to the latest version of the Windows Log Analytics agent, following these [guidelines](../../azure-monitor/agents/agent-manage.md).
183
183
184
184
>[!NOTE]
185
185
> During the upgrade process, update management schedules might fail. Ensure to do this when there is no planned schedule.
To use [managed identity authentication (preview)](container-insights-onboard.md#authentication), add the `configuration-settings` parameter as in the following:
Checkout the [resource requests and limits section of Helm chart](https://github.com/microsoft/Docker-Provider/blob/ci_prod/charts/azuremonitor-containers/values.yaml) for the available configuration settings.
@@ -144,7 +144,7 @@ Checkout the [resource requests and limits section of Helm chart](https://github
144
144
If the Azure Arc-enabled Kubernetes cluster is on Azure Stack Edge, then a custom mount path `/home/data/docker` needs to be used.
Copy file name to clipboardExpand all lines: articles/cost-management-billing/costs/enable-preview-features-cost-management-labs.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -71,7 +71,7 @@ Cost analysis is your tool for interactive analytics and insights. You've seen t
71
71
72
72
The first time you open the cost analysis preview, you'll see a list of all views. When you return, you'll see a list of the recently used views to help you get back to where you left off quicker than ever. You can pin any view or even rename or subscribe to alerts for your saved views.
73
73
74
-
The recent and pinned views can be enabled from the [Try preview](https://aka.ms/costmgmt/trypreview) page in the Azure portal. Use the **How would you rate the cost analysis preview?** option at the bottom of the page to share feedback about the preview.
74
+
**Recent and pinned views are available by default in the cost analysis preview.** Use the **How would you rate the cost analysis preview?** option at the bottom of the page to share feedback.
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/custom-security-policies.md
+23-13Lines changed: 23 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -3,7 +3,7 @@ title: Create custom Azure security policies in Microsoft Defender for Cloud
3
3
description: Azure custom policy definitions monitored by Microsoft Defender for Cloud.
4
4
ms.topic: how-to
5
5
ms.custom: ignite-2022
6
-
ms.date: 07/20/2022
6
+
ms.date: 01/22/2023
7
7
zone_pivot_groups: manage-asc-initiatives
8
8
---
9
9
@@ -35,26 +35,36 @@ You can view your custom initiatives organized by controls, similar to the contr
35
35
36
36
:::image type="content" source="media/custom-security-policies/accessing-security-policy-page.png" alt-text="Screenshot of accessing the security policy page in Microsoft Defender for Cloud." lightbox="media/custom-security-policies/accessing-security-policy-page.png":::
37
37
38
-
1.In the Add custom initiatives page, review the list of custom policies already created in your organization.
38
+
1.Review the list of custom policies already created in your organization, and select **Add** to assign a policy to your subscription.
39
39
40
-
- If you see one you want to assign to your subscription, select **Add**.
41
-
- If there isn't an initiative in the list that meets your needs, create a new custom initiative:
40
+
If there isn't an initiative in the list that meets your needs, you can create one.
42
41
43
-
1. Select **Create new**.
44
-
1. Enter the definition's location and name.
45
-
1. Select the policies to include and select **Add**.
46
-
1. Enter any desired parameters.
47
-
1. Select **Save**.
48
-
1. In the Add custom initiatives page, select refresh. Your new initiative will be available.
49
-
1. Select **Add** and assign it to your subscription.
42
+
**To create a new custom initiative**:
43
+
44
+
1. Select **Create new**.
45
+
46
+
1. Enter the definition's location and custom name.
47
+
48
+
> [!NOTE]
49
+
> Custom initiatives shouldn't have the same name as other initiatives (custom or built-in). If you create a custom initiative with the the same name, it will cause a conflict in the information displayed in the dashboard.
50
+
51
+
1. Select the policies to include and select **Add**.
52
+
53
+
1. Enter any desired parameters.
54
+
55
+
1. Select **Save**.
56
+
57
+
1. In the Add custom initiatives page, select refresh. Your new initiative will be available.
58
+
59
+
1. Select **Add** and assign it to your subscription.
50
60
51
61

52
62
53
63
54
64
> [!NOTE]
55
65
> Creating new initiatives requires subscription owner credentials. For more information about Azure roles, see [Permissions in Microsoft Defender for Cloud](permissions.md).
56
66
57
-
Your new initiative takes effect and you can see the impact in the following two ways:
67
+
Your new initiative takes effect and you can see the results in the following two ways:
58
68
59
69
* From the Defender for Cloud menu, select **Regulatory compliance**. The compliance dashboard opens to show your new custom initiative alongside the built-in initiatives.
60
70
@@ -250,7 +260,7 @@ The metadata should be added to the policy definition for a policy that is part
250
260
},
251
261
```
252
262
253
-
Below is an example of a custom policy including the metadata/securityCenter property:
263
+
Here's another example of a custom policy including the metadata/securityCenter property:
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/governance-rules.md
+11-8Lines changed: 11 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,12 +2,11 @@
2
2
title: Driving your organization to remediate security issues with recommendation governance in Microsoft Defender for Cloud
3
3
description: Learn how to assign owners and due dates to security recommendations and create rules to automatically assign owners and due dates
4
4
services: defender-for-cloud
5
-
author: bmansheim
6
-
ms.author: benmansheim
7
5
ms.service: defender-for-cloud
8
6
ms.topic: how-to
9
-
ms.date: 11/13/2022
7
+
ms.date: 01/23/2023
10
8
---
9
+
11
10
# Drive your organization to remediate security recommendations with governance
12
11
13
12
Security teams are responsible for improving the security posture of their organizations but they may not have the resources or authority to actually implement security recommendations. [Assigning owners with due dates](#manually-assigning-owners-and-due-dates-for-recommendation-remediation) and [defining governance rules](#building-an-automated-process-for-improving-security-with-governance-rules) creates accountability and transparency so you can drive the process of improving the security posture in your organization.
@@ -40,9 +39,9 @@ You can then review the progress of the tasks by subscription, recommendation, o
40
39
41
40
### Defining governance rules to automatically set the owner and due date of recommendations
42
41
43
-
Governance rules can identify resources that require remediation according to specific recommendations or severities, and the rule assigns an owner and due date to make sure the recommendations are handled. Many governance rules can apply to the same recommendations, so the rule with lower priority value is the one that assigns the owner and due date.
42
+
Governance rules can identify resources that require remediation according to specific recommendations or severities. The rule assigns an owner and due date to ensure the recommendations are handled. Many governance rules can apply to the same recommendations, so the rule with lower priority value is the one that assigns the owner and due date.
44
43
45
-
The due date set for the recommendation to be remediated is based on a timeframe of 7, 14, 30, or 90 days from when the recommendation is found by the rule. For example, if the rule identifies the resource on March 1st and the remediation timeframe is 14 days, March 15th is the due date. You can apply a grace period so that the resources that are given a due date don't impact your secure score until they're overdue.
44
+
The due date set for the recommendation to be remediated is based on a timeframe of 7, 14, 30, or 90 days from when the recommendation is found by the rule. For example, if the rule identifies the resource on March 1 and the remediation timeframe is 14 days, March 15 is the due date. You can apply a grace period so that the resources that 's given a due date don't affect your secure score until they're overdue.
46
45
47
46
You can also set the owner of the resources that are affected by the specified recommendations. In organizations that use resource tags to associate resources with an owner, you can specify the tag key and the governance rule reads the name of the resource owner from the tag.
48
47
@@ -72,7 +71,7 @@ To define a governance rule that assigns an owner and due date:
72
71
-**By resource tag** - Enter the resource tag on your resources that defines the resource owner.
73
72
-**By email address** - Enter the email address of the owner to assign to the recommendations.
74
73
1. Set the **remediation timeframe**, which is the time between when the resources are identified to require remediation and the time that the remediation is due.
75
-
1. If you don't want the resources to impact your secure score until they're overdue, select **Apply grace period**.
74
+
1. If you don't want the resources to affect your secure score until they're overdue, select **Apply grace period**.
76
75
1. If you don't want either the owner or the owner's manager to receive weekly emails, clear the notification options.
77
76
1. Select **Create**.
78
77
@@ -90,9 +89,13 @@ If there are existing recommendations that match the definition of the governanc
90
89
> - Create and apply rules on multiple scopes at once using management scopes cross cloud.
91
90
> - Check effective rules on selected scope using the scope filter.
92
91
92
+
To view the effect of rules on a specific scope, use the Scope filter to select a specific scope.
93
+
94
+
Conflicting rules are applied in priority order. For example, rules on a management scope (Azure management groups, AWS accounts and GCP organizations), take effect before rules on scopes (for example, Azure subscriptions, AWS accounts, or GCP projects).
95
+
93
96
## Manually assigning owners and due dates for recommendation remediation
94
97
95
-
For every resource affected by a recommendation, you can assign an owner and a due date so that you know who needs to implement the security changes to improve your security posture and when they're expected to do it by. You can also apply a grace period so that the resources that are given a due date don't impact your secure score unless they become overdue.
98
+
For every resource affected by a recommendation, you can assign an owner and a due date so that you know who needs to implement the security changes to improve your security posture and when they're expected to do it by. You can also apply a grace period so that the resources that 's given a due date don't affect your secure score unless they become overdue.
96
99
97
100
To manually assign owners and due dates to recommendations:
98
101
@@ -108,7 +111,7 @@ To manually assign owners and due dates to recommendations:
108
111
1. For any resource that doesn't have an owner or due date, select the resources and select **Assign owner**.
109
112
1. Enter the email address of the owner that needs to make the changes that remediate the recommendation for those resources.
110
113
1. Select the date by which to remediate the recommendation for the resources.
111
-
1. You can select **Apply grace period** to keep the resource from impacting the secure score until it's overdue.
114
+
1. You can select **Apply grace period** to keep the resource from affecting the secure score until it's overdue.
112
115
1. Select **Save**.
113
116
114
117
The recommendation is now shown as assigned and on time.
Copy file name to clipboardExpand all lines: articles/machine-learning/how-to-secure-workspace-vnet.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -219,7 +219,7 @@ Azure Container Registry can be configured to use a private endpoint. Use the fo
219
219
If you've [installed the Machine Learning extension v2 for Azure CLI](how-to-configure-cli.md), you can use the `az ml workspace show` command to show the workspace information. The v1 extension does not return this information.
220
220
221
221
```azurecli-interactive
222
-
az ml workspace show -w yourworkspacename -g resourcegroupname --query 'container_registry'
222
+
az ml workspace show -n yourworkspacename -g resourcegroupname --query 'container_registry'
223
223
```
224
224
225
225
This command returns a value similar to `"/subscriptions/{GUID}/resourceGroups/{resourcegroupname}/providers/Microsoft.ContainerRegistry/registries/{ACRname}"`. The last part of the string is the name of the Azure Container Registry for the workspace.
description: Learn about round-trip latency statistics between Azure regions.
4
4
services: networking
5
5
author: mbender-ms
6
6
ms.service: virtual-network
7
7
ms.topic: article
8
-
ms.date: 06/08/2021
8
+
ms.date: 06/30/2022
9
9
ms.author: mbender
10
-
11
10
---
11
+
12
12
# Azure network round-trip latency statistics
13
13
14
14
Azure continuously monitors the latency (speed) of core areas of its network using internal monitoring tools as well as measurements collected by [ThousandEyes](https://thousandeyes.com), a third-party synthetic monitoring service.
@@ -23,9 +23,11 @@ The monthly Percentile P50 round trip times between Azure regions for the past 3
23
23
24
24
:::image type="content" source="media/azure-network-latency/azure-network-latency-thmb-july-2022.png" alt-text="Chart of the inter-region latency statistics as of June 30, 2022." lightbox="media/azure-network-latency/azure-network-latency-july-2022.png":::
25
25
26
-
> [IMPORTANT!}
26
+
> [!IMPORTANT]
27
27
> Monthly latency numbers across Azure regions do not change regulary. Given this, you can expect an update of this table every 6 to 9 months outside of the addition of new regions. When new regions come online, we will update this document as soon as data is available.
28
28
29
29
## Next steps
30
30
31
31
Learn about [Azure regions](https://azure.microsoft.com/global-infrastructure/regions/).
0 commit comments