Skip to content

Commit 7240c5c

Browse files
authored
Merge pull request #4580 from DeCohen/WI474429-mda-discovery-exclude-entities
add note about excluding entity limitations
2 parents 50b8222 + 62daee6 commit 7240c5c

File tree

1 file changed

+17
-11
lines changed

1 file changed

+17
-11
lines changed

CloudAppSecurityDocs/discovered-apps.md

Lines changed: 17 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ This procedure describes how to get an initial, general picture of your cloud di
2323

2424
For example:
2525

26-
:::image type="content" source="media/cloud-discovery-dashboard.png" alt-text="Screenshot of the Cloud discovery dashboard":::
26+
:::image type="content" source="media/cloud-discovery-dashboard.png" alt-text="Screenshot of the Cloud discovery dashboard" lightbox="media/cloud-discovery-dashboard.png":::
2727

2828
Supported apps include Windows and macOS apps, which are both listed under the **Defender - managed endpoints** stream.
2929

@@ -57,7 +57,8 @@ For example, if you want to identify commonly used, risky cloud storage and coll
5757

5858
1. Set the **Security risk factor** for **Data at rest encryption** equals **Not supported**. Then set **Risk score** equals 6 or lower.
5959

60-
![Screenshot of sample discovered app filters.](media/discovered-app-filters.png)
60+
61+
:::image type="content" source="media/discovered-app-filters.png" alt-text="Screenshot of discovered app filters." lightbox="media/discovered-app-filters.png":::
6162

6263
After the results are filtered, [unsanction and block](governance-discovery.md) them by using the bulk action checkbox to unsanction them all in one action. Once they're unsanctioned, use a blocking script to block them from being used in your environment.
6364

@@ -83,11 +84,13 @@ For example, if a large amount of data is uploaded, discover what resource it's
8384

8485
1. In the Microsoft Defender portal, under **Cloud Apps**, select **Cloud discovery**. Then choose the **Discovered resources** tab.
8586

86-
![Screenshot of the discovered resources menu.](media/discovered-resources-menu.png)
87+
:::image type="content" source="media/discovered-resources-menu.png" alt-text="Screenshot that shows the discovered resources menu." lightbox="media/discovered-resources-menu.png":::
8788

8889
1. In the **Discovered resources** page, drill down into each resource to see what kinds of transactions occurred, who accessed it, and then drill down to investigate the users even further.
8990

90-
![Screenshot of the Discovered resources tab.](media/discovery-resources.png)
91+
92+
:::image type="content" source="media/discovery-resources.png" alt-text="Screenshot that shows a list of discovered resources.":::
93+
9194

9295
1. For custom apps, select the options menu at the end of the row and then select **Add new custom app**. This opens the **Add this app** dialog, where you can name and identify the app so it can be included in the cloud discovery dashboard.
9396

@@ -104,7 +107,7 @@ The best way to get an overview of Shadow IT use across your organization is by
104107
1. Optionally, change the report name, and then select **Generate**.
105108

106109
> [!NOTE]
107-
> The executive summary report is revamped to a 6-pager report with a goal to provide a clear, concise & actionable overview while preserving the depth and integrity of the original analysis.
110+
> The executive summary report is revamped to a six-pager report with a goal to provide a clear, concise & actionable overview while preserving the depth and integrity of the original analysis.
108111
109112
## Exclude entities
110113

@@ -118,10 +121,12 @@ If you have system users, IP addresses, or devices that are noisy but uninterest
118121

119122
1. Add a user alias, IP address, or device name. We recommend adding information about why the exclusion was made.
120123

121-
![Screenshot of excluding a user.](media/exclude-user.png "exclude user")
124+
:::image type="content" source="media/exclude-user.png" alt-text="Screenshot that shows the option to exclude users from the Cloud Discovery report." lightbox="media/exclude-user.png":::
125+
122126

123127
>[!NOTE]
124-
>All entity exclusions apply to newly received data only. Historical data of the excluded entities remains through the retention period (90 days).
128+
> - All entity exclusions apply to newly received data only. Historical data of the excluded entities remains through the retention period (90 days).
129+
> - Entity exclusion is only supported for the Global report stream. Entities from Microsoft Defender for Endpoint and the Cloud App Security proxy stream aren't supported for exclusion.
125130
126131
## Manage continuous reports
127132

@@ -141,10 +146,11 @@ Custom continuous reports provide you with more granularity when monitoring your
141146

142147
1. Set the filters you want on the data. These filters can be **User groups**, **IP address tags**, or **IP address ranges**. For more information on working with IP address tags and IP address ranges, see [Organize the data according to your needs](ip-tags.md).
143148

144-
![Screenshot of creating a custom continuous report.](media/create-custom-continuous-report.png)
149+
150+
:::image type="content" source="media/create-custom-continuous-report.png" alt-text="Screenshot that shows how to create a continuous report.":::
145151

146152
> [!NOTE]
147-
> All custom reports are limited to a maximum of 1 GB of uncompressed data. If there is more than 1 GB of data, the first 1 GB of data will be exported into the report.
153+
> All custom reports are limited to a maximum of 1 GB of uncompressed data. If there's more than 1 GB of data, the first 1 GB of data will be exported into the report.
148154
149155
## Deleting cloud discovery data
150156

@@ -166,10 +172,10 @@ We recommend deleting cloud discovery data in the following cases:
166172

167173
1. Select the **Delete** button.
168174

169-
![Screenshot of deleting cloud discovery data.](media/delete-data.png "delete data")
175+
:::image type="content" source="media/delete-data.png" alt-text="Screenshot of deleting cloud discovery data." lightbox="media/delete-data.png":::
170176

171177
> [!NOTE]
172-
> The deletion process takes a few minutes and is not immediate.
178+
> The deletion process takes a few minutes and isn't immediate.
173179
174180
## Next steps
175181

0 commit comments

Comments
 (0)