檢視並修復 適用於雲端的 Microsoft Defender 中的作業系統錯誤設定

適用於雲端的 Microsoft Defender 提供安全性建議,以改善組織安全性狀態並降低風險。 降低風險的重要元素是機器強化。

適用於雲端的 Defender 會根據 Microsoft 雲端安全性效能評定 (MCSB) 所提供的運算安全性基準來評估作業系統設定。 機器資訊是透過在機器上使用 Azure 原則 機器配置擴充功能(前稱訪客配置)來收集以供評估。 如需更多資訊,請參閱適用於雲端的 Defender 中的作業系統設定錯誤。

本文說明如何審查並補救OS基線評估的建議。

Prerequisites

在您檢視並修正作業系統基線建議之前,請確保以下先決條件已達成。

要求 詳細資料
Plan 必須啟用適用於伺服器的 Defender 方案 2
擴充功能 Azure 原則 機器設定必須安裝在各機器上。

此功能先前使用 Microsoft 監控代理程式(MMA)來收集資料。 如果MMA仍在使用,你可能會看到重複的推薦。 為了避免重複,請 在機器上關閉 MMA。

檢閱並修正 OS 基準設定建議

檢閱並修正作業系統基線設定建議:

  1. 在適用於雲端的 Defender 中,開啟 [建議] 頁面。

  2. 選取相關建議。

  3. 在建議詳情頁面,檢視受影響的資源及具體的安全發現。

  4. 要完成修復,請參閱 「如何修復安全建議」。

查詢建議

適用於雲端的 Defender 使用 Azure Resource Graph 來進行應用程式介面(API)及入口網站查詢。 你可以使用 Azure Resource Graph 及其查詢介面建立自己的查詢並取得推薦資訊。

您可以瞭解如何在 Azure Resource Graph 中檢閱建議。

以下是您可以使用的兩項範例查詢:

  • 查詢特定資源的所有異常規則

    Securityresources 
    | where type == "microsoft.security/assessments/subassessments" 
    | extend assessmentKey=extract(@"(?i)providers/Microsoft.Security/assessments/([^/]*)", 1, id) 
    | where assessmentKey == '1f655fb7-63ca-4980-91a3-56dbc2b715c6' or assessmentKey ==  '8c3d9ad0-3639-4686-9cd2-2b2ab2609bda' 
    | parse-where id with machineId:string '/providers/Microsoft.Security/' * 
    | where machineId  == '{machineId}'
    
  • 所有不健康規則,以及每項規則對應的不健康機器數量

    securityresources 
    | where type == "microsoft.security/assessments/subassessments" 
    | extend assessmentKey=extract(@"(?i)providers/Microsoft.Security/assessments/([^/]*)", 1, id) 
    | where assessmentKey == '1f655fb7-63ca-4980-91a3-56dbc2b715c6' or assessmentKey ==  '8c3d9ad0-3639-4686-9cd2-2b2ab2609bda' 
    | parse-where id with * '/subassessments/' subAssessmentId:string 
    | parse-where id with machineId:string '/providers/Microsoft.Security/' * 
    | extend status = tostring(properties.status.code) 
    | summarize count() by subAssessmentId, status
    

下一步

深入瞭解 Azure Resource Graph 的查詢語言。