Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard

A security engineer is reviewing the recommendations in Microsoft Defender for Cloud and finds one stating, 'Endpoint protection solution should be installed on virtual machines'. The organization uses a specific third-party endpoint detection and response (EDR) solution. The engineer needs to ensure that Defender for Cloud accurately reflects the security posture of VMs running this EDR without flagging them as non-compliant for a missing Microsoft-specific solution. How can the engineer achieve this?

  1. AInstall the Microsoft Defender for Endpoint agent alongside the third-party solution.
  2. BManually mark the recommendation as 'resolved' for each affected VM.
  3. CDisable the 'Endpoint protection solution should be installed' recommendation for the subscription.
  4. DCreate a custom Azure Policy to exempt VMs with the third-party EDR from the recommendation.
Show answer & explanation

Correct answer: D. Create a custom Azure Policy to exempt VMs with the third-party EDR from the recommendation.

To accurately reflect the security posture while using a third-party EDR, the most scalable and compliant method is to create a custom Azure Policy. This policy can identify VMs that have the approved third-party EDR installed (e.g., by checking for a specific installed application or extension) and then exempt them from the built-in Defender for Cloud recommendation for endpoint protection. This keeps the recommendation active for truly unprotected VMs.

Why the other options are wrong

  • A. Installing two EDR solutions simultaneously is generally not recommended due to potential conflicts and performance issues.
  • B. Manually marking as 'resolved' is not scalable or sustainable for a large number of VMs and does not address the underlying policy evaluation.
  • C. Disabling the recommendation entirely would hide the security gap for VMs that genuinely lack any endpoint protection, which is not desired.

Custom Azure Policy for Endpoint Exemption

Custom Azure Policies can be used in Microsoft Defender for Cloud to create exemptions for built-in security recommendations, allowing organizations to maintain compliance while using alternative security controls, such as a specific third-party EDR solution.

  • Provides granular control over recommendation evaluation.
  • Allows for 'DeployIfNotExists' or 'AuditIfNotExists' effects.
  • Can be based on resource tags, installed software, or other properties.
  • Helps achieve accurate secure score and compliance reporting.

Memory trick: Policy's precision: Exempt specific, enforce general, ensure compliance.

More Mitigate threats using Microsoft Defender for Cloud questions