Skip to content

Commit 8ebcb59

Browse files
authored
Merge branch 'main' into v-smandalika-9618437
2 parents 95854a9 + c09f72e commit 8ebcb59

File tree

5 files changed

+209
-101
lines changed

5 files changed

+209
-101
lines changed

ATPDocs/whats-new.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,22 @@ For more information, see also:
2222

2323
For updates about versions and features released six months ago or earlier, see the [What's new archive for Microsoft Defender for Identity](whats-new-archive.md).
2424

25+
## December 2024
26+
27+
### New security posture assessment: Prevent Certificate Enrollment with arbitrary Application Policies (ESC15)
28+
29+
Defender for Identity has added the new **Prevent Certificate Enrollment with arbitrary Application Policies (ESC15)** recommendation in Microsoft Secure Score.
30+
31+
This recommendation directly addresses the recently published [CVE-2024-49019](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-49019), which highlights security risks associated with vulnerable AD CS configurations. This security posture assessment lists all vulnerable certificate templates found in customer environments due to unpatched AD CS servers.
32+
33+
The new recommendation is added to other AD CS-related recommendations. Together, these assessments offer security posture reports that surface security issues and severe misconfigurations that post risks to the entire organization, together with related detections.
34+
35+
For more information, see:
36+
37+
- [Security assessment: Prevent Certificate Enrollment with arbitrary Application Policies (ESC15)](https://go.microsoft.com/fwlink/?linkid=2296922)
38+
39+
- [Microsoft Defender for Identity's security posture assessments](security-assessment.md)
40+
2541
## October 2024
2642

2743
### MDI is expanding coverage with new 10 Identity posture recommendations (preview)
@@ -532,6 +548,7 @@ This version includes improvements and bug fixes for cloud services and the Defe
532548

533549
- [What is Microsoft Defender for Identity?](what-is.md)
534550
- [Frequently asked questions](technical-faq.yml)
551+
535552
- [Defender for Identity prerequisites](prerequisites.md)
536553
- [Defender for Identity capacity planning](capacity-planning.md)
537554
- [Check out the Defender for Identity forum!](<https://aka.ms/MDIcommunity>)

defender-endpoint/android-configure.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,8 @@ For more information about how to set up Defender for Endpoint on Android and Co
3737

3838
> [!NOTE]
3939
> Defender for Endpoint on Android only supports creating custom indicators for IP addresses and URLs/domains.
40+
>
41+
> Also, alerts for custom indicators are currently not supported for Defender for Endpoint on Android.
4042
4143
Defender for Endpoint on Android enables admins to configure custom indicators to support Android devices as well. For more information on how to configure custom indicators, see [Overview of indicators](indicators-overview.md).
4244

0 commit comments

Comments
 (0)