Skip to content

Commit 9b51bf0

Browse files
authored
Merge pull request #190258 from ElazarK/release-note-update
updated release notes, archive and upcoming
2 parents 79c5281 + 6fbb7b2 commit 9b51bf0

File tree

3 files changed

+32
-31
lines changed

3 files changed

+32
-31
lines changed

articles/defender-for-cloud/release-notes-archive.md

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Archive of what's new in Microsoft Defender for Cloud
33
description: A description of what's new and changed in Microsoft Defender for Cloud from six months ago and earlier.
44
ms.topic: reference
5-
ms.date: 02/27/2022
5+
ms.date: 03/02/2022
66
---
77
# Archive for what's new in Defender for Cloud?
88

@@ -16,6 +16,21 @@ This page provides you with information about:
1616
- Bug fixes
1717
- Deprecated functionality
1818

19+
## September 2021
20+
21+
In September, the following update was released:
22+
23+
### Two new recommendations to audit OS configurations for Azure security baseline compliance (in preview)
24+
25+
The following two recommendations have been released to assess your machines' compliance with the [Windows security baseline](../governance/policy/samples/guest-configuration-baseline-windows.md) and the [Linux security baseline](../governance/policy/samples/guest-configuration-baseline-linux.md):
26+
27+
- For Windows machines, [Vulnerabilities in security configuration on your Windows machines should be remediated (powered by Guest Configuration)](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/1f655fb7-63ca-4980-91a3-56dbc2b715c6)
28+
- For Linux machines, [Vulnerabilities in security configuration on your Linux machines should be remediated (powered by Guest Configuration)](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/8c3d9ad0-3639-4686-9cd2-2b2ab2609bda)
29+
30+
These recommendations make use of the guest configuration feature of Azure Policy to compare the OS configuration of a machine with the baseline defined in the [Azure Security Benchmark](/security/benchmark/azure/overview).
31+
32+
Learn more about using these recommendations in [Harden a machine's OS configuration using guest configuration](apply-security-baseline.md).
33+
1934
## August 2021
2035

2136
Updates in August include:

articles/defender-for-cloud/release-notes.md

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Release notes for Microsoft Defender for Cloud
33
description: A description of what's new and changed in Microsoft Defender for Cloud
44
ms.topic: reference
5-
ms.date: 03/01/2022
5+
ms.date: 03/02/2022
66
---
77
# What's new in Microsoft Defender for Cloud?
88

@@ -17,6 +17,21 @@ To learn about *planned* changes that are coming soon to Defender for Cloud, see
1717
> [!TIP]
1818
> If you're looking for items older than six months, you'll find them in the [Archive for What's new in Microsoft Defender for Cloud](release-notes-archive.md).
1919
20+
## March 2022
21+
22+
Updates in March include:
23+
24+
- [Deprecated the recommendations to install the network traffic data collection agent](#deprecated-the-recommendations-to-install-the-network-traffic-data-collection-agent)
25+
26+
### Deprecated the recommendations to install the network traffic data collection agent
27+
28+
Changes in our roadmap and priorities have removed the need for the network traffic data collection agent. Consequently, the following two recommendations and their related policies were deprecated.
29+
30+
|Recommendation |Description |Severity |
31+
|---|---|---|
32+
|[Network traffic data collection agent should be installed on Linux virtual machines](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/8c3e93d3-0276-4d06-b20a-9a9f3012742c) |Defender for Cloud uses the Microsoft Dependency agent to collect network traffic data from your Azure virtual machines to enable advanced network protection features such as traffic visualization on the network map, network hardening recommendations and specific network threats.<br />(Related policy: [Network traffic data collection agent should be installed on Linux virtual machines](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2fproviders%2fMicrosoft.Authorization%2fpolicyDefinitions%2f04c4380f-3fae-46e8-96c9-30193528f602)) |Medium |
33+
|[Network traffic data collection agent should be installed on Windows virtual machines](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/24d8af06-d441-40b4-a49c-311421aa9f58) |Defender for Cloud uses the Microsoft Dependency agent to collect network traffic data from your Azure virtual machines to enable advanced network protection features such as traffic visualization on the network map, network hardening recommendations, and specific network threats.<br />(Related policy: [Network traffic data collection agent should be installed on Windows virtual machines](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2fproviders%2fMicrosoft.Authorization%2fpolicyDefinitions%2f2f2ee1de-44aa-4762-b6bd-0893fc3f306d)) |Medium |
34+
|||
2035
## February 2022
2136

2237
Updates in February include:
@@ -664,18 +679,3 @@ These alerts are generated based on a new machine learning model and Kubernetes
664679
|||
665680

666681
For a full list of the Kubernetes alerts, see [Alerts for Kubernetes clusters](alerts-reference.md#alerts-k8scluster).
667-
668-
## September 2021
669-
670-
In September, the following update was released:
671-
672-
### Two new recommendations to audit OS configurations for Azure security baseline compliance (in preview)
673-
674-
The following two recommendations have been released to assess your machines' compliance with the [Windows security baseline](../governance/policy/samples/guest-configuration-baseline-windows.md) and the [Linux security baseline](../governance/policy/samples/guest-configuration-baseline-linux.md):
675-
676-
- For Windows machines, [Vulnerabilities in security configuration on your Windows machines should be remediated (powered by Guest Configuration)](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/1f655fb7-63ca-4980-91a3-56dbc2b715c6)
677-
- For Linux machines, [Vulnerabilities in security configuration on your Linux machines should be remediated (powered by Guest Configuration)](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/8c3d9ad0-3639-4686-9cd2-2b2ab2609bda)
678-
679-
These recommendations make use of the guest configuration feature of Azure Policy to compare the OS configuration of a machine with the baseline defined in the [Azure Security Benchmark](/security/benchmark/azure/overview).
680-
681-
Learn more about using these recommendations in [Harden a machine's OS configuration using guest configuration](apply-security-baseline.md).

articles/defender-for-cloud/upcoming-changes.md

Lines changed: 0 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,6 @@ If you're looking for the latest release notes, you'll find them in the [What's
2626
| [Multiple changes to identity recommendations](#multiple-changes-to-identity-recommendations) | February 2022 |
2727
| [Deprecating the recommendation to use service principals to protect your subscriptions](#deprecating-the-recommendation-to-use-service-principals-to-protect-your-subscriptions) | February 2022 |
2828
| [Moving recommendation Vulnerabilities in container security configurations should be remediated from the secure score to best practices](#moving-recommendation-vulnerabilities-in-container-security-configurations-should-be-remediated-from-the-secure-score-to-best-practices) | February 2022 |
29-
| [Deprecating the recommendations to install the network traffic data collection agent](#deprecating-the-recommendations-to-install-the-network-traffic-data-collection-agent) | February 2022 |
3029
| [Changes to recommendations for managing endpoint protection solutions](#changes-to-recommendations-for-managing-endpoint-protection-solutions) | March 2022 |
3130
| [AWS recommendations to GA](#aws-recommendations-to-ga) | March 2022 |
3231
| [Relocation of custom recommendations](#relocation-of-custom-recommendations) | March 2022 |
@@ -118,19 +117,6 @@ Learn more:
118117
- [Overview of Azure Cloud Services (classic)](../cloud-services/cloud-services-choose-me.md)
119118
- [Workflow of Windows Azure classic VM Architecture - including RDFE workflow basics](../cloud-services/cloud-services-workflow-process.md)
120119

121-
122-
### Deprecating the recommendations to install the network traffic data collection agent
123-
124-
**Estimated date for change:** February 2022
125-
126-
Changes in our roadmap and priorities have removed the need for the network traffic data collection agent. Consequently, we'll be deprecating the following two recommendations and their related policies.
127-
128-
|Recommendation |Description |Severity |
129-
|---|---|---|
130-
|[Network traffic data collection agent should be installed on Linux virtual machines](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/8c3e93d3-0276-4d06-b20a-9a9f3012742c) |Defender for Cloud uses the Microsoft Dependency agent to collect network traffic data from your Azure virtual machines to enable advanced network protection features such as traffic visualization on the network map, network hardening recommendations and specific network threats.<br />(Related policy: [Network traffic data collection agent should be installed on Linux virtual machines](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2fproviders%2fMicrosoft.Authorization%2fpolicyDefinitions%2f04c4380f-3fae-46e8-96c9-30193528f602)) |Medium |
131-
|[Network traffic data collection agent should be installed on Windows virtual machines](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/24d8af06-d441-40b4-a49c-311421aa9f58) |Defender for Cloud uses the Microsoft Dependency agent to collect network traffic data from your Azure virtual machines to enable advanced network protection features such as traffic visualization on the network map, network hardening recommendations, and specific network threats.<br />(Related policy: [Network traffic data collection agent should be installed on Windows virtual machines](https://portal.azure.com/#blade/Microsoft_Azure_Policy/PolicyDetailBlade/definitionId/%2fproviders%2fMicrosoft.Authorization%2fpolicyDefinitions%2f2f2ee1de-44aa-4762-b6bd-0893fc3f306d)) |Medium |
132-
|||
133-
134120
### Moving recommendation Vulnerabilities in container security configurations should be remediated from the secure score to best practices
135121

136122
**Estimated date for change:** February 2022

0 commit comments

Comments
 (0)