You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/implement-security-recommendations.md
+15-7Lines changed: 15 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,10 +1,10 @@
1
1
---
2
2
title: Remediate security recommendations in Microsoft Defender for Cloud
3
-
description: Learn how to remediate security recommendations in Microsoft Defender for Cloud
3
+
description: Learn how to remediate security recommendations in Microsoft Defender for Cloud.
4
4
ms.topic: how-to
5
5
ms.author: dacurwin
6
6
author: dcurwin
7
-
ms.date: 11/22/2023
7
+
ms.date: 03/05/2024
8
8
---
9
9
10
10
# Remediate security recommendations
@@ -20,7 +20,7 @@ Before you attempt to remediate a recommendation you should review it in detail.
20
20
> [!IMPORTANT]
21
21
> This page discusses how to use the new recommendations experience where you have the ability to prioritize your recommendations by their effective risk level. To view this experience, you must select **Try it now**.
22
22
>
23
-
> :::image type="content" source="media/review-security-recommendations/try-it-now.png" alt-text="Screenshot that shows where the try it now button is located on the recommendation page." lightbox="media/review-security-recommendations/try-it-now.png":::
23
+
> :::image type="content" source="media/review-security-recommendations/try-it-now.png" alt-text="Screenshot that shows where the try it now button is located on the recommendations page." lightbox="media/review-security-recommendations/try-it-now.png":::
24
24
25
25
## Group recommendations by risk level
26
26
@@ -50,15 +50,15 @@ In addition to risk level, we recommend that you prioritize the security control
50
50
51
51
1. Select a recommendation to remediate.
52
52
53
-
1. Select **Take action**
53
+
1. Select **Take action**.
54
54
55
55
1. Locate the Remediate section and follow the remediation instructions.
56
56
57
57
:::image type="content" source="./media/implement-security-recommendations/security-center-remediate-recommendation.png" alt-text="This screenshot shows manual remediation steps for a recommendation." lightbox="./media/implement-security-recommendations/security-center-remediate-recommendation.png":::
58
58
59
59
## Use the Fix option
60
60
61
-
To simplify remediation and improve your environment's security (and increase your secure score), many recommendations include a **Fix** option to help you quickly remediate a recommendation on multiple resources. If the Fix button is not present in the recommendation, then there is no option to apply a quick fix.
61
+
To simplify remediation and improve your environment's security (and increase your secure score), many recommendations include a **Fix** option to help you quickly remediate a recommendation on multiple resources. If the Fix button isn't present in the recommendation, then there's no option to apply a quick fix.
62
62
63
63
**To remediate a recommendation with the Fix button**:
64
64
@@ -70,12 +70,20 @@ To simplify remediation and improve your environment's security (and increase yo
70
70
71
71
1. Select **Take action** > **Fix**.
72
72
73
-
:::image type="content" source="./media/implement-security-recommendations/microsoft-defender-for-cloud-recommendations-fix-action.png" alt-text="This screenshot shows recommendations with the Fix action" lightbox="./media/implement-security-recommendations/microsoft-defender-for-cloud-recommendations-fix-action.png":::
73
+
:::image type="content" source="./media/implement-security-recommendations/microsoft-defender-for-cloud-recommendations-fix-action.png" alt-text="Screenshot that shows recommendations with the Fix action." lightbox="./media/implement-security-recommendations/microsoft-defender-for-cloud-recommendations-fix-action.png":::
74
74
75
75
1. Follow the rest of the remediation steps.
76
76
77
77
After remediation completes, it can take several minutes for the change to take place.
78
78
79
+
## Use the automated remediation scripts
80
+
81
+
Security admins can fix issues at scale with automatic script generation in AWS and GCP CLI script language. When you select **Take action** > **Fix** on a recommendation where an automated script is available, the following window opens.
82
+
83
+
:::image type="content" source="./media/implement-security-recommendations/automated-remediation-scripts.png" alt-text="Screenshot that shows recommendations with the automated remediation script." lightbox="./media/implement-security-recommendations/automated-remediation-scripts.png":::
84
+
85
+
Copy and run the script to remediate the recommendation.
86
+
79
87
## Next steps
80
88
81
-
[Learn about](governance-rules.md)using governance rules in your remediation processes.
89
+
Learn about[using governance rules in your remediation processes](governance-rules.md).
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/release-notes.md
+46-4Lines changed: 46 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Release notes
3
3
description: This page is updated frequently with the latest updates in Defender for Cloud.
4
4
ms.topic: overview
5
-
ms.date: 02/26/2024
5
+
ms.date: 03/06/2024
6
6
---
7
7
8
8
# What's new in Microsoft Defender for Cloud?
@@ -24,9 +24,52 @@ If you're looking for items older than six months, you can find them in the [Arc
24
24
25
25
|Date | Update |
26
26
|----------|----------|
27
+
| March 13 |[Enhanced AWS and GCP recommendations with automated remediation scripts](#enhanced-aws-and-gcp-recommendations-with-automated-remediation-scripts)|
28
+
| March 6 |[(Preview) Compliance standards added to compliance dashboard](#preview-compliance-standards-added-to-compliance-dashboard)|
27
29
| March 5 |[Deprecation of two recommendations related to PCI](#deprecation-of-two-recommendations-related-to-pci)|
28
30
| March 3 |[Defender for Cloud Containers Vulnerability Assessment powered by Qualys retirement](#defender-for-cloud-containers-vulnerability-assessment-powered-by-qualys-retirement)|
29
31
32
+
### Enhanced AWS and GCP recommendations with automated remediation scripts
33
+
34
+
March 13, 2024
35
+
36
+
We're enhancing the AWS and GCP recommendations with automated remediation scripts that allow you to remediate them programmatically and at scale.
37
+
Learn more about [automated remediation scripts](implement-security-recommendations.md#use-the-automated-remediation-scripts).
38
+
39
+
### (Preview) Compliance standards added to compliance dashboard
40
+
41
+
March 6, 2024
42
+
43
+
Based on customer feedback, we've added the following compliance standards in preview to our compliance dashboard. As shown, these are for reviewing the compliance status of AWS and GCP resources protected by Defender for Cloud.
We are continuously working on adding and updating new standards for Azure, AWS, and GCP environments.
70
+
71
+
Learn how to [assign a security standard](update-regulatory-compliance-packages.md).
72
+
30
73
### Deprecation of two recommendations related to PCI
31
74
32
75
March 5, 2024
@@ -38,7 +81,6 @@ The following two recommendations related to Permission Creep Index (PCI) are be
38
81
39
82
See the [list of deprecated security recommendations](recommendations-reference.md#deprecated-recommendations).
40
83
41
-
42
84
### Defender for Cloud Containers Vulnerability Assessment powered by Qualys retirement
43
85
44
86
March 3, 2024
@@ -430,7 +472,7 @@ November 20, 2023
430
472
431
473
In preparation for the Microsoft Monitoring Agent (MMA) deprecation in August 2024, Defender for Cloud released a SQL Server-targeted Azure Monitoring Agent (AMA) autoprovisioning process. The new process is automatically enabled and configured for all new customers, and also provides the ability for resource level enablement for Azure SQL VMs and Arc-enabled SQL Servers.
432
474
433
-
Customers using the MMA autoprovisioning process are requested to [migrate to the new Azure Monitoring Agent for SQL server on machines autoprovisioning process](/azure/defender-for-cloud/defender-for-sql-autoprovisioning). The migration process is seamless and provides continuous protection for all machines.
475
+
Customers using the MMA autoprovisioning process are requested to [migrate to the new Azure Monitoring Agent for SQL server on machines autoprovisioning process](defender-for-sql-autoprovisioning.md). The migration process is seamless and provides continuous protection for all machines.
434
476
435
477
### General availability of Defender for APIs
436
478
@@ -686,7 +728,7 @@ You can now exempt recommendations for the following Defender for APIs security
686
728
| (Preview) API endpoints that are unused should be disabled and removed from the Azure API Management service | As a security best practice, API endpoints that haven't received traffic for 30 days are considered unused, and should be removed from the Azure API Management service. Keeping unused API endpoints might pose a security risk. These might be APIs that should have been deprecated from the Azure API Management service, but have accidentally been left active. Such APIs typically do not receive the most up-to-date security coverage. | Low |
687
729
| (Preview) API endpoints in Azure API Management should be authenticated | API endpoints published within Azure API Management should enforce authentication to help minimize security risk. Authentication mechanisms are sometimes implemented incorrectly or are missing. This allows attackers to exploit implementation flaws and to access data. For APIs published in Azure API Management, this recommendation assesses the execution of authentication via the Subscription Keys, JWT, and Client Certificate configured within Azure API Management. If none of these authentication mechanisms are executed during the API call, the API will receive this recommendation. | High |
688
730
689
-
Learn more about [exempting recommendations in Defender for Cloud](/azure/defender-for-cloud/exempt-resource).
731
+
Learn more about [exempting recommendations in Defender for Cloud](exempt-resource.md).
690
732
691
733
### Create sample alerts for Defender for APIs detections
0 commit comments