Skip to content

Commit c152f3f

Browse files
Merge pull request #234660 from AlizaBernstein/WI-69853b-april-new-alert-azure-defender-for-resource-manager
WI-69853b-release-notes-april-new-alert-azure-defender-for-resource-manager
2 parents 49924cb + a164633 commit c152f3f

File tree

1 file changed

+11
-12
lines changed

1 file changed

+11
-12
lines changed

articles/defender-for-cloud/release-notes.md

Lines changed: 11 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -19,11 +19,21 @@ To learn about *planned* changes that are coming soon to Defender for Cloud, see
1919
## April 2023
2020

2121
Updates in April include:
22-
22+
- [New alert in Defender for Resource Manager](#new-alert-in-defender-for-resource-manager)
2323
- [New preview Unified Disk Encryption recommendation](#unified-disk-encryption-recommendation-preview)
2424
- [Changes in the recommendation "Machines should be configured securely"](#changes-in-the-recommendation-machines-should-be-configured-securely)
2525
- [Deprecation of App Service language monitoring policies](#deprecation-of-app-service-language-monitoring-policies)
2626

27+
### New alert in Defender for Resource Manager
28+
29+
Defender for Resource Manager has the following new alert:
30+
31+
| Alert (alert type) | Description | MITRE tactics | Severity |
32+
|---|---|:-:|---|
33+
| **PREVIEW - Suspicious creation of compute resources detected**<br>(ARM_SuspiciousComputeCreation) | Microsoft Defender for Resource Manager identified a suspicious creation of compute resources in your subscription utilizing Virtual Machines/Azure Scale Set. The identified operations are designed to allow administrators to efficiently manage their environments by deploying new resources when needed. While this activity may be legitimate, a threat actor might utilize such operations to conduct crypto mining.<br> The activity is deemed suspicious as the compute resources scale is higher than previously observed in the subscription. <br> This can indicate that the principal is compromised and is being used with malicious intent. | Impact | Medium |
34+
35+
You can see a list of all of the [alerts available for Resource Manager](alerts-reference.md#alerts-resourcemanager).
36+
2737
### Unified Disk Encryption recommendation (preview)
2838

2939
We have introduced a unified disk encryption recommendation in public preview, `Windows virtual machines should enable Azure Disk Encryption or EncryptionAtHost` and `Linux virtual machines should enable Azure Disk Encryption or EncryptionAtHost`.
@@ -67,7 +77,6 @@ These policies are no longer available in Defender for Cloud's built-in recommen
6777

6878
Updates in March include:
6979

70-
- [New alert in Defender for Resource Manager](#new-alert-in-defender-for-resource-manager)
7180
- [A new Defender for Storage plan is available, including near-real time malware scanning and sensitive data threat detection](#a-new-defender-for-storage-plan-is-available-including-near-real-time-malware-scanning-and-sensitive-data-threat-detection)
7281
- [Data-aware security posture (preview)](#data-aware-security-posture-preview)
7382
- [Improved experience for managing the default Azure security policies](#improved-experience-for-managing-the-default-azure-security-policies)
@@ -78,16 +87,6 @@ Updates in March include:
7887
- [New preview recommendation for Azure SQL Servers](#new-preview-recommendation-for-azure-sql-servers)
7988
- [New alert in Defender for Key Vault](#new-alert-in-defender-for-key-vault)
8089

81-
### New alert in Defender for Resource Manager
82-
83-
Defender for Resource Manager has the following new alert:
84-
85-
| Alert (alert type) | Description | MITRE tactics | Severity |
86-
|---|---|:-:|---|
87-
| **PREVIEW - Suspicious creation of compute resources detected**<br>(ARM_SuspiciousComputeCreation) | Microsoft Defender for Resource Manager identified a suspicious creation of compute resources in your subscription utilizing Virtual Machines/Azure Scale Set. The identified operations are designed to allow administrators to efficiently manage their environments by deploying new resources when needed. While this activity may be legitimate, a threat actor might utilize such operations to conduct crypto mining.<br> The activity is deemed suspicious as the compute resources scale is higher than previously observed in the subscription. <br> This can indicate that the principal is compromised and is being used with malicious intent. | Impact | Medium |
88-
89-
You can see a list of all of the [alerts available for Resource Manager](alerts-reference.md#alerts-resourcemanager).
90-
9190
### A new Defender for Storage plan is available, including near-real time malware scanning and sensitive data threat detection
9291

9392
Cloud storage plays a key role in the organization and stores large volumes of valuable and sensitive data. Today we are announcing a new Defender for Storage plan. If you’re using the previous plan (now renamed to "Defender for Storage (classic)"), you will need to proactively [migrate to the new plan](defender-for-storage-classic-migrate.md) in order to use the new features and benefits.

0 commit comments

Comments
 (0)