Defender Findings Release Notes -- 2026-02-18 Initial Batch
This release note retroactively documents all Defender for Cloud findings resolved prior to the establishment of the formal tracking process.
Resolved Findings
[DEVOPS-28] Storage account public access should be disallowed
What happened: Defender flagged that storage accounts had public blob access enabled, exposing data to potential unauthorized access.
Solution:
- Disabled public blob access on all affected eshars storage accounts
QA considerations: Verified application functionality was not impacted — apps use private endpoints and SAS tokens for storage access.
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-29] Secure transfer to storage accounts should be enabled
What happened: Defender identified storage accounts (storageesharsuat, storageesharsnonprod, storageesharsprod, etc.) not enforcing HTTPS-only transfers.
Solution:
- Enabled “Secure transfer required” on all affected storage accounts to enforce HTTPS
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-32] Private endpoint connections on Azure SQL databases should be enabled
What happened: Defender flagged that Azure SQL databases were accessible without private endpoint connections, potentially exposing them to public network traffic.
Solution:
- Configured private endpoint connections for Azure SQL databases to restrict access to private network only
QA considerations: Verified all application connection strings use private endpoints and connectivity is maintained.
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-34] Machine should have vulnerability findings resolved
What happened: Defender identified vulnerability findings on virtual machines that needed remediation.
Solution:
- Reviewed and resolved identified vulnerabilities on affected machines
- Applied recommended patches and configuration changes
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-39] Transparent Data Encryption on SQL databases should be enabled
What happened: Defender flagged SQL databases without Transparent Data Encryption (TDE), leaving data at rest unencrypted.
Solution:
- Enabled Transparent Data Encryption on all affected SQL databases
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-50] Azure Cosmos DB accounts should have firewall rules
What happened: Defender flagged that Cosmos DB accounts lacked firewall rules, allowing unrestricted network access.
Solution:
- Configured firewall rules on Azure Cosmos DB accounts to restrict access to authorized networks only
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-51] Diagnostic logs in Key Vault should be enabled
What happened: Defender flagged that diagnostic logging was not enabled on Key Vault resources, limiting audit trail and monitoring capabilities.
Solution:
- Enabled diagnostic logging on all eshars Key Vault instances
- Configured log retention per organizational policy
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-52] Diagnostic logs in App Service should be enabled
What happened: Defender flagged that diagnostic logging was not enabled on App Service resources.
Solution:
- Enabled diagnostic logging on all eshars App Service instances
- Configured log output to Application Insights and storage
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-54] Web Application should only be accessible over HTTPS
What happened: Defender flagged web applications that were accessible over HTTP, allowing unencrypted traffic.
Solution:
- Enforced HTTPS-only access on all eshars web applications
- Configured HTTP-to-HTTPS redirect rules
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-55] Auditing on SQL server should be enabled
What happened: Defender flagged that auditing was not enabled on SQL Server instances, limiting ability to track database operations.
Solution:
- Enabled SQL Server auditing on all eshars SQL Server instances
- Configured audit log retention
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-56] Key vaults should have purge protection enabled
What happened: Defender flagged Key Vault resources without purge protection, risking permanent deletion of secrets and certificates.
Solution:
- Enabled purge protection on all eshars Key Vault instances (90-day soft-delete retention)
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-57] SQL servers should have an Azure Active Directory administrator provisioned
What happened: Defender flagged SQL Server instances without an Azure AD administrator, preventing centralized identity management.
Solution:
- Provisioned Azure AD administrator on affected SQL Server instances
- Configured Azure AD authentication for database access
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-58] Key Vault secrets should have an expiration date
What happened: Defender flagged Key Vault secrets without expiration dates, allowing credentials to remain valid indefinitely.
Solution:
- Set expiration dates on all Key Vault secrets across eshars environments
- Configured secret rotation reminders
QA considerations: N/A
One-time script: N/A
Deployment considerations: N/A
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A
[DEVOPS-77] Apply security updates to VMs
What happened: Defender flagged virtual machines running without the latest security updates applied.
Solution:
- Applied recommended security updates to all affected VMs
- Rebooted VMs to complete update installation
- Verified VMs are running latest updates
QA considerations: N/A
One-time script: N/A
Deployment considerations: VMs were rebooted during maintenance window.
Wave tool required: N/A
Unit test case: N/A
Loom video: N/A