Skip to content

Commit da8ea0c

Browse files
Merge pull request #273861 from dcurwin/wi-244315-245360-upcoming-changes-mma-april30-2024
MMA upcoming changes
2 parents 36f5a61 + f8a686a commit da8ea0c

File tree

1 file changed

+37
-0
lines changed

1 file changed

+37
-0
lines changed

articles/defender-for-cloud/upcoming-changes.md

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,8 @@ If you're looking for the latest release notes, you can find them in the [What's
2525

2626
| Planned change | Announcement date | Estimated date for change |
2727
|--|--|--|
28+
| [Deprecation of system update recommendations](#deprecation-of-system-update-recommendations) | May 1, 2024 | May 2024 |
29+
| [Deprecation of MMA related recommendations](#deprecation-of-mma-related-recommendations) | May 1, 2024 | May 2024 |
2830
| [Deprecation of fileless attack alerts](#deprecation-of-fileless-attack-alerts) | April 18, 2024 | May 2024 |
2931
| [Change in CIEM assessment IDs](#change-in-ciem-assessment-ids) | April 16.2024 | May 2024 |
3032
| [Deprecation of encryption recommendation](#deprecation-of-encryption-recommendation) | April 3, 2024 | May 2024 |
@@ -47,6 +49,41 @@ If you're looking for the latest release notes, you can find them in the [What's
4749
| [Deprecating two security incidents](#deprecating-two-security-incidents) | | November 2023 |
4850
| [Defender for Cloud plan and strategy for the Log Analytics agent deprecation](#defender-for-cloud-plan-and-strategy-for-the-log-analytics-agent-deprecation) | | August 2024 |
4951

52+
## Deprecation of system update recommendations
53+
54+
**Announcement date: May 1, 2024**
55+
56+
**Estimated date for change: May 2024**
57+
58+
As use of the Azure Monitor Agent (AMA) and the Log Analytics agent (also known as the Microsoft Monitoring Agent (MMA)) is [phased out in Defender for Servers](https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/microsoft-defender-for-cloud-strategy-and-plan-towards-log/ba-p/3883341), the following recommendations that rely on those agents are set for deprecation:
59+
60+
- [System updates should be installed on your machines](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/SystemUpdatesRecommendationDetailsWithRulesBlade/assessmentKey/4ab6e3c5-74dd-8b35-9ab9-f61b30875b27)
61+
- [System updates on virtual machine scale sets should be installed](https://ms.portal.azure.com/#view/Microsoft_Azure_Security/GenericRecommendationDetailsBlade/assessmentKey/bd20bd91-aaf1-7f14-b6e4-866de2f43146)
62+
63+
The new recommendations based on Azure Update Manager integration [are Generally Available](release-notes-archive.md#two-recommendations-related-to-missing-operating-system-os-updates-were-released-to-ga) and have no agent dependencies.
64+
65+
## Deprecation of MMA related recommendations
66+
67+
**Announcement date: May 1, 2024**
68+
69+
**Estimated date for change: May 2024**
70+
71+
As part of the [MMA deprecation and the Defender for Servers updated deployment strategy](https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/microsoft-defender-for-cloud-strategy-and-plan-towards-log/ba-p/3883341), all Defender for Servers security features will be provided via a single agent (MDE), or via agentless scanning capabilities, and without dependency on either Log Analytics Agent (MMA) or Azure Monitoring Agent (AMA).
72+
73+
As part of this, and in a goal to reduce complexity, the following recommendations are going to be deprecated:
74+
75+
| Display name | Related feature |
76+
| ------------------------------------------------------------ | ------------------- |
77+
| Log Analytics agent should be installed on Windows-based Azure Arc-enabled machines | MMA enablement |
78+
| Log Analytics agent should be installed on virtual machine scale sets | MMA enablement |
79+
| Auto provisioning of the Log Analytics agent should be enabled on subscriptions | MMA enablement |
80+
| Log Analytics agent should be installed on virtual machines | MMA enablement |
81+
| Log Analytics agent should be installed on Linux-based Azure Arc-enabled machines | MMA enablement |
82+
| Guest Configuration extension should be installed on machines | GC enablement |
83+
| Virtual machines' Guest Configuration extension should be deployed with system-assigned managed identity | GC enablement |
84+
| Adaptive application controls for defining safe applications should be enabled on your machines | AAC |
85+
| Adaptive application controls for defining safe applications should be enabled on your machines | AAC |
86+
5087
## Deprecation of fileless attack alerts
5188

5289
**Announcement date: April 18, 2024**

0 commit comments

Comments
 (0)