Skip to content

Commit cdbe4ca

Browse files
authored
Merge pull request #266708 from MicrosoftDocs/main
Publish to live, Tuesday 4 AM PST, 2/20
2 parents a38b453 + c320d18 commit cdbe4ca

35 files changed

+349
-64
lines changed

articles/aks/cis-kubernetes.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -154,7 +154,7 @@ Recommendations can have one of the following statuses:
154154
|5.1.12|Minimize access to webhook configuration objects|Not Scored|L1|Depends on Environment|
155155
|5.1.13|Minimize access to the service account token creation|Not Scored|L1|Depends on Environment|
156156
|5.2|Pod Security Policies||||
157-
|5.2.1|Ensure that the clsuter has at least one active policy control mechanism in place|Not Scored|L1|Depends on Environment|
157+
|5.2.1|Ensure that the cluster has at least one active policy control mechanism in place|Not Scored|L1|Depends on Environment|
158158
|5.2.2|Minimize the admission of privileged containers|Not Scored|L1|Depends on Environment|
159159
|5.2.3|Minimize the admission of containers wishing to share the host process ID namespace|Scored|L1|Depends on Environment|
160160
|5.2.4|Minimize the admission of containers wishing to share the host IPC namespace|Scored|L1|Depends on Environment|
@@ -204,4 +204,4 @@ For more information about AKS security, see the following articles:
204204

205205
<!-- INTERNAL LINKS -->
206206
[cis-benchmarks]: /compliance/regulatory/offering-CIS-Benchmark
207-
[security-concepts-aks-apps-clusters]: concepts-security.md
207+
[security-concepts-aks-apps-clusters]: concepts-security.md

articles/azure-app-configuration/enable-dynamic-configuration-dotnet-core.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.custom: devx-track-csharp, devx-track-dotnet
1111
ms.topic: tutorial
1212
ms.date: 07/11/2023
1313
ms.author: malev
14-
#Customer intent: I want to dynamically update my app to use the latest configuration data in App Configuration.
14+
#Customer intent: I want to dynamically update my .NET app to use the latest configuration data in App Configuration.
1515
---
1616
# Tutorial: Use dynamic configuration in a .NET app
1717

articles/azure-app-configuration/quickstart-dotnet-app.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ In this quickstart, a .NET Framework console app is used as an example, but the
2323

2424
- An Azure account with an active subscription. [Create one for free](https://azure.microsoft.com/free/).
2525
- An App Configuration store. [Create a store](./quickstart-azure-app-configuration-create.md#create-an-app-configuration-store).
26-
- [Visual Studio](https://visualstudio.microsoft.com/vs)
26+
- [Visual Studio](https://visualstudio.microsoft.com/downloads)
2727
- [.NET Framework 4.7.2 or later](https://dotnet.microsoft.com/download/dotnet-framework)
2828

2929
## Add a key-value

articles/azure-app-configuration/quickstart-dotnet-core-app.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -119,8 +119,6 @@ You use the [.NET command-line interface (CLI)](/dotnet/core/tools/) to create a
119119
export ConnectionString='connection-string-of-your-app-configuration-store'
120120
```
121121
122-
Restart the command prompt to allow the change to take effect. Print the value of the environment variable to validate that it's set properly.
123-
124122
### [Linux](#tab/linux)
125123
126124
If you use Linux, run the following command:
@@ -129,8 +127,6 @@ You use the [.NET command-line interface (CLI)](/dotnet/core/tools/) to create a
129127
export ConnectionString='connection-string-of-your-app-configuration-store'
130128
```
131129
132-
Restart the command prompt to allow the change to take effect. Print the value of the environment variable to validate that it's set properly.
133-
134130
---
135131
136132
1. Run the following command to build the console app:

articles/azure-netapp-files/understand-path-lengths.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -167,7 +167,7 @@ Using `\\?\Z:` instead allows access and supports longer file paths.
167167
168168
### Workaround if the max path length cannot be increased
169169

170-
If the max path length can't be enabled in the Windows environment or the Windows client versions are too low, there's a workaround. You can mount the SMB share deeper into the directory structure can reduce the queried path length.
170+
If the max path length can't be enabled in the Windows environment or the Windows client versions are too low, there's a workaround. You can mount the SMB share deeper into the directory structure and reduce the queried path length.
171171

172172
For example, rather than mapping `\\NAS-SHARE\AzureNetAppFiles` to `Z:`, map `\\NAS-SHARE\AzureNetAppFiles\folder1\folder2\folder3\folder4` to `Z:`.
173173

@@ -200,4 +200,4 @@ Rather than the name being too long, the error actually results from the charact
200200

201201
## Next steps
202202

203-
* [Understand volume languages](understand-volume-languages.md)
203+
* [Understand volume languages](understand-volume-languages.md)

articles/defender-for-cloud/release-notes.md

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,17 +24,23 @@ If you're looking for items older than six months, you can find them in the [Arc
2424

2525
|Date | Update |
2626
|----------|----------|
27+
| February 20 | [New version of Defender Agent for Defender for Containers](#new-version-of-defender-agent-for-defender-for-containers) |
2728
| February 18| [Open Container Initiative (OCI) image format specification support](#open-container-initiative-oci-image-format-specification-support) |
2829
| February 13 | [AWS container vulnerability assessment powered by Trivy retired](#aws-container-vulnerability-assessment-powered-by-trivy-retired) |
2930
| February 8 | [Recommendations released for preview: four recommendations for Azure Stack HCI resource type](#recommendations-released-for-preview-four-recommendations-for-azure-stack-hci-resource-type) |
3031

31-
### Open Container Initiative (OCI) image format specification support
32+
### New version of Defender Agent for Defender for Containers
33+
34+
February 20, 2024
35+
36+
[A new version](/azure/aks/supported-kubernetes-versions#aks-kubernetes-release-calendar) of the [Defender Agent for Defender for Containers](tutorial-enable-containers-azure.md#deploy-the-defender-agent-in-azure) is available. It includes performance and security improvements, support for both AMD64 and ARM64 arch nodes (Linux only), and uses [Inspektor Gadget](https://www.inspektor-gadget.io/) as the process collection agent instead of Sysdig. The new version is only supported on Linux kernel versions 5.4 and higher, so if you have older versions of the Linux kernel, you need to upgrade. Support for ARM 64 is only available from AKS V1.29 and above. For more information, see [Supported host operating systems](support-matrix-defender-for-containers.md#supported-host-operating-systems).
37+
38+
### Open Container Initiative (OCI) image format specification support
3239

3340
February 18, 2024
3441

3542
The [Open Container Initiative (OCI)](https://github.com/opencontainers/image-spec/blob/main/spec.md) image format specification is now supported by vulnerability assessment, powered by Microsoft Defender Vulnerability Management for AWS, Azure & GCP clouds.
3643

37-
3844
### AWS container vulnerability assessment powered by Trivy retired
3945

4046
February 13, 2024

articles/defender-for-cloud/upcoming-changes.md

Lines changed: 18 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Important upcoming changes
33
description: Upcoming changes to Microsoft Defender for Cloud that you might need to be aware of and for which you might need to plan.
44
ms.topic: overview
5-
ms.date: 02/18/2024
5+
ms.date: 02/20/2024
66
---
77

88
# Important upcoming changes to Microsoft Defender for Cloud
@@ -25,6 +25,7 @@ If you're looking for the latest release notes, you can find them in the [What's
2525

2626
| Planned change | Announcement date | Estimated date for change |
2727
|--|--|--|
28+
| [Update recommendations to align with Azure AI Services resources](#update-recommendations-to-align-with-azure-ai-services-resources) | February 20, 2024 | February 28, 2024 |
2829
| [Deprecation of data recommendation](#deprecation-of-data-recommendation) | February 12, 2024 | March 14, 2024 |
2930
| [Decommissioning of Microsoft.SecurityDevOps resource provider](#decommissioning-of-microsoftsecuritydevops-resource-provider) | February 5, 2024 | March 6, 2024 |
3031
| [Changes in endpoint protection recommendations](#changes-in-endpoint-protection-recommendations) | February 1, 2024 | February 28, 2024 |
@@ -34,7 +35,6 @@ If you're looking for the latest release notes, you can find them in the [What's
3435
| [Deprecation of two recommendations related to PCI](#deprecation-of-two-recommendations-related-to-pci) |January 14, 2024 | February 2024 |
3536
| [Defender for Servers built-in vulnerability assessment (Qualys) retirement path](#defender-for-servers-built-in-vulnerability-assessment-qualys-retirement-path) | January 9, 2024 | May 2024 |
3637
| [Retirement of the Defender for Cloud Containers Vulnerability Assessment powered by Qualys](#retirement-of-the-defender-for-cloud-containers-vulnerability-assessment-powered-by-qualys) | January 9, 2023 | March 2024 |
37-
| [New version of Defender Agent for Defender for Containers](#new-version-of-defender-agent-for-defender-for-containers) | January 4, 2024 | February 2024 |
3838
| [Upcoming change for the Defender for Cloud’s multicloud network requirements](#upcoming-change-for-the-defender-for-clouds-multicloud-network-requirements) | January 3, 2024 | May 2024 |
3939
| [Deprecation of two DevOps security recommendations](#deprecation-of-two-devops-security-recommendations) | November 30, 2023 | January 2024 |
4040
| [Consolidation of Defender for Cloud's Service Level 2 names](#consolidation-of-defender-for-clouds-service-level-2-names) | November 1, 2023 | December 2023 |
@@ -46,6 +46,21 @@ If you're looking for the latest release notes, you can find them in the [What's
4646
| [Deprecating two security incidents](#deprecating-two-security-incidents) | | November 2023 |
4747
| [Defender for Cloud plan and strategy for the Log Analytics agent deprecation](#defender-for-cloud-plan-and-strategy-for-the-log-analytics-agent-deprecation) | | August 2024 |
4848

49+
## Update recommendations to align with Azure AI Services resources
50+
51+
**Announcement date: February 20, 2024**
52+
53+
**Estimated date of change: February 28, 2024**
54+
55+
The Azure AI Services category (formerly known as Cognitive Services) is adding new resource types. As a result, the following recommendations and related policy are set to be updated to comply with the new Azure AI Services naming format and align with the relevant resources.
56+
57+
| Current Recommendation | Updated Recommendation |
58+
| ---- | ---- |
59+
| Cognitive Services accounts should restrict network access | [Azure AI Services resources should restrict network access](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/GenericRecommendationDetailsBlade/assessmentKey/f738efb8-005f-680d-3d43-b3db762d6243) |
60+
| Cognitive Services accounts should have local authentication methods disabled | [Azure AI Services resources should have key access disabled (disable local authentication)](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/GenericRecommendationDetailsBlade/assessmentKey/13b10b36-aa99-4db6-b00c-dcf87c4761e6) |
61+
62+
See the [list of security recommendations](recommendations-reference.md).
63+
4964
## Deprecation of data recommendation
5065

5166
**Announcement date: February 12, 2024**
@@ -70,8 +85,8 @@ Customers that are still using the API version **2022-09-01-preview** under `Mic
7085

7186
Customers currently using Defender for Cloud DevOps security from Azure portal won't be impacted.
7287

73-
For details on the new API version, see [Microsoft Defender for Cloud REST APIs](/rest/api/defenderforcloud/operation-groups?view=rest-defenderforcloud-2023-09-01-preview).
7488

89+
For details on the new API version, see [Microsoft Defender for Cloud REST APIs](/rest/api/defenderforcloud/operation-groups).
7590

7691
## Changes in endpoint protection recommendations
7792

@@ -170,14 +185,6 @@ For more information about transitioning to our new container vulnerability asse
170185

171186
For common questions about the transition to Microsoft Defender Vulnerability Management, see [Common questions about the Microsoft Defender Vulnerability Management solution](common-questions-microsoft-defender-vulnerability-management.md).
172187

173-
## New version of Defender Agent for Defender for Containers
174-
175-
**Announcement date: January 4, 2024**
176-
177-
**Estimated date for change: February 2024**
178-
179-
A new version of the [Defender Agent for Defender for Containers](tutorial-enable-containers-azure.md#deploy-the-defender-agent-in-azure) will be released in February 2024. It includes performance and security improvements, support for both AMD64 and ARM64 arch nodes (Linux only), and uses [Inspektor Gadget](https://www.inspektor-gadget.io/) as the process collection agent instead of Sysdig. The new version is only supported on Linux kernel versions 5.4 and higher, so if you have older versions of the Linux kernel, you'll need to upgrade. For more information, see [Supported host operating systems](support-matrix-defender-for-containers.md#supported-host-operating-systems).
180-
181188
## Upcoming change for the Defender for Cloud’s multicloud network requirements
182189

183190
**Announcement date: January 3, 2024**

0 commit comments

Comments
 (0)