Skip to content

Commit e68f3f0

Browse files
committed
add note about excluding entity limitations
1 parent b577f9c commit e68f3f0

File tree

1 file changed

+19
-10
lines changed

1 file changed

+19
-10
lines changed

CloudAppSecurityDocs/discovered-apps.md

Lines changed: 19 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ This procedure describes how to get an initial, general picture of your cloud di
2323

2424
For example:
2525

26-
:::image type="content" source="media/cloud-discovery-dashboard.png" alt-text="Screenshot of the Cloud discovery dashboard":::
26+
:::image type="content" source="media/cloud-discovery-dashboard.png" alt-text="Screenshot of the Cloud discovery dashboard" lightbox="media/cloud-discovery-dashboard.png":::
2727

2828
Supported apps include Windows and macOS apps, which are both listed under the **Defender - managed endpoints** stream.
2929

@@ -57,7 +57,8 @@ For example, if you want to identify commonly used, risky cloud storage and coll
5757

5858
1. Set the **Security risk factor** for **Data at rest encryption** equals **Not supported**. Then set **Risk score** equals 6 or lower.
5959

60-
![Screenshot of sample discovered app filters.](media/discovered-app-filters.png)
60+
61+
:::image type="content" source="media/discovered-app-filters.png" alt-text="Screenshot of discovered app filters." lightbox="media/discovered-app-filters.png":::
6162

6263
After the results are filtered, [unsanction and block](governance-discovery.md) them by using the bulk action checkbox to unsanction them all in one action. Once they're unsanctioned, use a blocking script to block them from being used in your environment.
6364

@@ -83,11 +84,13 @@ For example, if a large amount of data is uploaded, discover what resource it's
8384

8485
1. In the Microsoft Defender portal, under **Cloud Apps**, select **Cloud discovery**. Then choose the **Discovered resources** tab.
8586

86-
![Screenshot of the discovered resources menu.](media/discovered-resources-menu.png)
87+
:::image type="content" source="media/discovered-resources-menu.png" alt-text="Screenshot that shows the discovered resources menu." lightbox="media/discovered-resources-menu.png":::
8788

8889
1. In the **Discovered resources** page, drill down into each resource to see what kinds of transactions occurred, who accessed it, and then drill down to investigate the users even further.
8990

90-
![Screenshot of the Discovered resources tab.](media/discovery-resources.png)
91+
92+
:::image type="content" source="media/discovery-resources.png" alt-text="Screenshot that shows a list of discovered resources.":::
93+
9194

9295
1. For custom apps, select the options menu at the end of the row and then select **Add new custom app**. This opens the **Add this app** dialog, where you can name and identify the app so it can be included in the cloud discovery dashboard.
9396

@@ -104,7 +107,7 @@ The best way to get an overview of Shadow IT use across your organization is by
104107
1. Optionally, change the report name, and then select **Generate**.
105108

106109
> [!NOTE]
107-
> The executive summary report is revamped to a 6-pager report with a goal to provide a clear, concise & actionable overview while preserving the depth and integrity of the original analysis.
110+
> The executive summary report is revamped to a six-pager report with a goal to provide a clear, concise & actionable overview while preserving the depth and integrity of the original analysis.
108111
109112
## Exclude entities
110113

@@ -118,11 +121,16 @@ If you have system users, IP addresses, or devices that are noisy but uninterest
118121

119122
1. Add a user alias, IP address, or device name. We recommend adding information about why the exclusion was made.
120123

121-
![Screenshot of excluding a user.](media/exclude-user.png "exclude user")
124+
:::image type="content" source="media/exclude-user.png" alt-text="Screenshot that shows the option to exclude users from the the Cloud Discovery report." lightbox="media/exclude-user.png":::
125+
122126

123127
>[!NOTE]
124128
>All entity exclusions apply to newly received data only. Historical data of the excluded entities remains through the retention period (90 days).
125129
130+
>[!NOTE]
131+
>Entity exclusion is only supported for the Global report stream.
132+
>Entities from Microsoft Defender for Endpoint and the Cloud App Security proxy stream are not supported for exclusion.
133+
126134
## Manage continuous reports
127135

128136
Custom continuous reports provide you with more granularity when monitoring your organization's cloud discovery log data. Create custom reports to filter on specific geographic locations, networks, and sites, or organizational units. By default, only the following reports appear in your cloud discovery report selector:
@@ -141,10 +149,11 @@ Custom continuous reports provide you with more granularity when monitoring your
141149

142150
1. Set the filters you want on the data. These filters can be **User groups**, **IP address tags**, or **IP address ranges**. For more information on working with IP address tags and IP address ranges, see [Organize the data according to your needs](ip-tags.md).
143151

144-
![Screenshot of creating a custom continuous report.](media/create-custom-continuous-report.png)
152+
153+
:::image type="content" source="media/create-custom-continuous-report.png" alt-text="Screenshot that shows how to create a continous report.":::
145154

146155
> [!NOTE]
147-
> All custom reports are limited to a maximum of 1 GB of uncompressed data. If there is more than 1 GB of data, the first 1 GB of data will be exported into the report.
156+
> All custom reports are limited to a maximum of 1 GB of uncompressed data. If there's more than 1 GB of data, the first 1 GB of data will be exported into the report.
148157
149158
## Deleting cloud discovery data
150159

@@ -166,10 +175,10 @@ We recommend deleting cloud discovery data in the following cases:
166175

167176
1. Select the **Delete** button.
168177

169-
![Screenshot of deleting cloud discovery data.](media/delete-data.png "delete data")
178+
:::image type="content" source="media/delete-data.png" alt-text="Screenshot of deleting cloud discovery data." lightbox="media/delete-data.png":::
170179

171180
> [!NOTE]
172-
> The deletion process takes a few minutes and is not immediate.
181+
> The deletion process takes a few minutes and isn't immediate.
173182
174183
## Next steps
175184

0 commit comments

Comments
 (0)