Skip to content

Commit 875adc6

Browse files
author
David Curwin
committed
Example queries for recommendations
1 parent 2357831 commit 875adc6

File tree

2 files changed

+11
-5
lines changed

2 files changed

+11
-5
lines changed

articles/defender-for-cloud/faq-general.yml

Lines changed: 11 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,8 +3,8 @@ metadata:
33
title: Microsoft Defender for Cloud common questions - General questions
44
description: Frequently asked general questions about Microsoft Defender for Cloud, a product that helps you prevent, detect, and respond to threats
55
services: defender-for-cloud
6-
author: elkrieger
7-
ms.author: elkrieger
6+
author: dcurwin
7+
ms.author: dacurwin
88
manager: raynew
99
ms.topic: faq
1010
ms.custom: ignite-2022
@@ -94,7 +94,7 @@ sections:
9494
answer: |
9595
The Microsoft Security Response Center (MSRC) performs select security monitoring of the Azure network and infrastructure and receives threat intelligence and abuse complaints from third parties. When MSRC becomes aware that customer data has been accessed by an unlawful or unauthorized party or that the customer’s use of Azure does not comply with the terms for Acceptable Use, a security incident manager notifies the customer. Notification typically occurs by sending an email to the security contacts specified in Microsoft Defender for Cloud or the Azure subscription owner if a security contact is not specified.
9696
97-
Defender for Cloud is an Azure service that continuously monitors the customers Azure, multicloud, and on-premises environment and applies analytics to automatically detect a wide range of potentially malicious activity. These detections are surfaced as security alerts in the workload protection dashboard.
97+
Defender for Cloud is an Azure service that continuously monitors the customer's Azure, multicloud, and on-premises environment and applies analytics to automatically detect a wide range of potentially malicious activity. These detections are surfaced as security alerts in the workload protection dashboard.
9898
9999
100100
- question: |
@@ -187,7 +187,7 @@ sections:
187187
- question: |
188188
Can I exempt or dismiss some of the accounts?
189189
answer: |
190-
The capability to exempt some accounts that dont use MFA is available on the new recommendations in preview:
190+
The capability to exempt some accounts that don't use MFA is available on the new recommendations in preview:
191191
192192
- Accounts with owner permissions on Azure resources should be MFA enabled
193193
- Accounts with write permissions on Azure resources should be MFA enabled
@@ -213,7 +213,7 @@ sections:
213213
214214
- Identity recommendations aren't available for subscriptions with more than 6,000 accounts. In these cases, these types of subscriptions will be listed under Not applicable tab.
215215
- Identity recommendations aren't available for Cloud Solution Provider (CSP) partner's admin agents.
216-
- Identity recommendations dont identify accounts that are managed with a privileged identity management (PIM) system. If you're using a PIM tool, you might see inaccurate results in the **Manage access and permissions** control.
216+
- Identity recommendations don't identify accounts that are managed with a privileged identity management (PIM) system. If you're using a PIM tool, you might see inaccurate results in the **Manage access and permissions** control.
217217
- Identity recommendations don't support Azure AD conditional access policies with included Directory Roles instead of users and groups.
218218
219219

@@ -327,6 +327,12 @@ sections:
327327
answer: |
328328
Different recommendations have different compliance evaluation intervals, which can range from every few minutes to every few days. So, the amount of time that it takes for recommendations to appear in your exports varies.
329329
330+
- question: |
331+
How can I get an example query for a recommendation?
332+
answer: |
333+
To get an example query for a recommendation, open the recommendation in Defender for Cloud, select **Open query**, and then select **Query returning security findings**.
334+
335+
:::image type="content" source="media/faq-general/recommendation-example-query.png" alt-text="Screenshot of how to create example query for recommendation.":::
330336
331337
- question: |
332338
Does continuous export support any business continuity or disaster recovery (BCDR) scenarios?
48.3 KB
Loading

0 commit comments

Comments
 (0)