|
- Suppress alerts from Microsoft Defender for Cloud
You can specify a single resource, multiple resources, or resources that contain a partial resource ID If you don't specify any resources, the rule applies to all resources in the subscription
- security - How to Identify and Suppress Azure Overprovisioned . . .
Recently, I received a recommendation from Microsoft Defender for Cloud regarding "Azure overprovisioned identities should have only the necessary permissions "
- Microsoft Defender: Alert Suppression to Whitelist - Armor
If you are experiencing many false or benign positives by trusted infrastructure, you can suppress alerts and create suppression rules by various attributes The following instructions can be found on Microsoft’s site:
- Manage Microsoft Defender for Endpoint suppression rules - Microsoft . . .
Sign in to the Microsoft Defender portal using an account with the Security administrator or Global Administrator role assigned In the navigation pane, select Settings > Endpoints > Rules > Alert suppression The list of suppression rules that users in your organization have created is displayed
- Manage your alert rules - Azure Monitor | Microsoft Learn
Selecting multiple rules can be useful when you want to perform maintenance on specific alert rule resources If you select a single alert rule, you can edit, disable, duplicate, or delete the rule in the alert rule pane
- Exempt resources from recommendation in Microsoft Defender for Cloud . . .
To create a rule, you need permissions to edit policies in Azure Policy Learn more You can create exemptions for recommendations included in Defender for Cloud's default Microsoft cloud security benchmark standard, or any of the supplied regulatory standards
- Overview of Azure Monitor alerts - Azure Monitor | Microsoft Learn
Write permission on the resource group in which the alert rule is created If you're creating the alert rule from the Azure portal, the alert rule is created by default in the same resource group in which the target resource resides
- Introducing the new alert suppression experience
Alert suppression provides the ability to tune and manage alerts in advance This streamlines the alert queue and saves triage time by hiding or resolving alerts automatically, each time a certain expected organizational behavior occurs, and rule conditions are met
|
|
|