MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.2k stars 21.34k forks source link

mssence.svc is referenced in Exclusions, but Windows Defender Threat Protection is MsSense.exe #75925

Closed cutecycle closed 3 years ago

cutecycle commented 3 years ago

https://docs.microsoft.com/en-us/azure/virtual-machines/extensions/iaas-antimalware-windows#template-deployment

When adopting the virtualmachine Antimalware extension verbatim and running in parallel with powershell-based Custom Script Extensions, Azure Security Center raises a high severity alert.

We noticed that the arm template set we inherited used the code from here, though we don't have an IIS Server or SQL database on our VM.

We also noticed mssence.svc, which we're assuming to mean "Exclude Windows Defender from the antimalware scan", but Windows Defender is MsSense.exe:

image image

[Enter feedback here]


Document Details

Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

cutecycle commented 3 years ago

Proposal: https://github.com/MicrosoftDocs/azure-docs/pull/75926

Karishma-Tiwari-MSFT commented 3 years ago

Thanks for the feedback! I have assigned the issue to the content author to investigate further and review your pull request.

TerryLanfear commented 3 years ago

@cutecycle - Thank you for your feedback. You are correct that the sample code needed an update. The sample code is updated to align with similar documentation on this subject.

please-close