You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/upcoming-changes.md
+20Lines changed: 20 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,6 +25,7 @@ If you're looking for the latest release notes, you can find them in the [What's
25
25
26
26
| Planned change | Announcement date | Estimated date for change |
27
27
|--|--|--|
28
+
|[Deprecation of fileless attack alerts](#deprecation-of-fileless-attack-alerts)| April 18, 2024 | May 2024 |
28
29
|[Change in CIEM assessment IDs](#change-in-ciem-assessment-ids)| April 16.2024 | May 2024 |
29
30
|[Deprecation of encryption recommendation](#deprecation-of-encryption-recommendation)| April 3, 2024 | May 2024 |
30
31
|[Deprecating of virtual machine recommendation](#deprecating-of-virtual-machine-recommendation)| April 2, 2024 | April 30, 2024 |
@@ -46,6 +47,25 @@ If you're looking for the latest release notes, you can find them in the [What's
46
47
|[Deprecating two security incidents](#deprecating-two-security-incidents)|| November 2023 |
47
48
|[Defender for Cloud plan and strategy for the Log Analytics agent deprecation](#defender-for-cloud-plan-and-strategy-for-the-log-analytics-agent-deprecation)|| August 2024 |
48
49
50
+
## Deprecation of fileless attack alerts
51
+
52
+
**Announcement date: April 18, 2024**
53
+
54
+
**Estimated date for change: May 2024**
55
+
56
+
In May 2024, to enhance the quality of security alerts for Defender for Servers, the fileless attack alerts specific to Windows and Linux virtual machines will be discontinued. These alerts will instead be generated by Defender for Endpoint:
All security scenarios covered by the deprecated alerts are fully covered Defender for Endpoint threat alerts.
66
+
67
+
If you already have the Defender for Endpoint integration enabled, there's no action required on your part. In May 2024 you might experience a decrease in your alerts volume, but still remain protected. If you don't currently have Defender for Endpoint integration enabled in Defender for Servers, you need to enable integration to maintain and improve your alert coverage. All Defender for Server customers can access the full value of Defender for Endpoint's integration at no additional cost. For more information, see [Enable Defender for Endpoint integration](enable-defender-for-endpoint.md).
0 commit comments