Skip to content

Defender Findings Release Notes -- 2026-02-18 Initial Batch

This release note retroactively documents all Defender for Cloud findings resolved prior to the establishment of the formal tracking process.

Resolved Findings

[DEVOPS-28] Storage account public access should be disallowed

What happened: Defender flagged that storage accounts had public blob access enabled, exposing data to potential unauthorized access.

Solution:

  1. Disabled public blob access on all affected eshars storage accounts

QA considerations: Verified application functionality was not impacted — apps use private endpoints and SAS tokens for storage access.

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-29] Secure transfer to storage accounts should be enabled

What happened: Defender identified storage accounts (storageesharsuat, storageesharsnonprod, storageesharsprod, etc.) not enforcing HTTPS-only transfers.

Solution:

  1. Enabled “Secure transfer required” on all affected storage accounts to enforce HTTPS

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-32] Private endpoint connections on Azure SQL databases should be enabled

What happened: Defender flagged that Azure SQL databases were accessible without private endpoint connections, potentially exposing them to public network traffic.

Solution:

  1. Configured private endpoint connections for Azure SQL databases to restrict access to private network only

QA considerations: Verified all application connection strings use private endpoints and connectivity is maintained.

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-34] Machine should have vulnerability findings resolved

What happened: Defender identified vulnerability findings on virtual machines that needed remediation.

Solution:

  1. Reviewed and resolved identified vulnerabilities on affected machines
  2. Applied recommended patches and configuration changes

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-39] Transparent Data Encryption on SQL databases should be enabled

What happened: Defender flagged SQL databases without Transparent Data Encryption (TDE), leaving data at rest unencrypted.

Solution:

  1. Enabled Transparent Data Encryption on all affected SQL databases

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-50] Azure Cosmos DB accounts should have firewall rules

What happened: Defender flagged that Cosmos DB accounts lacked firewall rules, allowing unrestricted network access.

Solution:

  1. Configured firewall rules on Azure Cosmos DB accounts to restrict access to authorized networks only

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-51] Diagnostic logs in Key Vault should be enabled

What happened: Defender flagged that diagnostic logging was not enabled on Key Vault resources, limiting audit trail and monitoring capabilities.

Solution:

  1. Enabled diagnostic logging on all eshars Key Vault instances
  2. Configured log retention per organizational policy

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-52] Diagnostic logs in App Service should be enabled

What happened: Defender flagged that diagnostic logging was not enabled on App Service resources.

Solution:

  1. Enabled diagnostic logging on all eshars App Service instances
  2. Configured log output to Application Insights and storage

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-54] Web Application should only be accessible over HTTPS

What happened: Defender flagged web applications that were accessible over HTTP, allowing unencrypted traffic.

Solution:

  1. Enforced HTTPS-only access on all eshars web applications
  2. Configured HTTP-to-HTTPS redirect rules

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-55] Auditing on SQL server should be enabled

What happened: Defender flagged that auditing was not enabled on SQL Server instances, limiting ability to track database operations.

Solution:

  1. Enabled SQL Server auditing on all eshars SQL Server instances
  2. Configured audit log retention

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-56] Key vaults should have purge protection enabled

What happened: Defender flagged Key Vault resources without purge protection, risking permanent deletion of secrets and certificates.

Solution:

  1. Enabled purge protection on all eshars Key Vault instances (90-day soft-delete retention)

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-57] SQL servers should have an Azure Active Directory administrator provisioned

What happened: Defender flagged SQL Server instances without an Azure AD administrator, preventing centralized identity management.

Solution:

  1. Provisioned Azure AD administrator on affected SQL Server instances
  2. Configured Azure AD authentication for database access

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-58] Key Vault secrets should have an expiration date

What happened: Defender flagged Key Vault secrets without expiration dates, allowing credentials to remain valid indefinitely.

Solution:

  1. Set expiration dates on all Key Vault secrets across eshars environments
  2. Configured secret rotation reminders

QA considerations: N/A

One-time script: N/A

Deployment considerations: N/A

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A


[DEVOPS-77] Apply security updates to VMs

What happened: Defender flagged virtual machines running without the latest security updates applied.

Solution:

  1. Applied recommended security updates to all affected VMs
  2. Rebooted VMs to complete update installation
  3. Verified VMs are running latest updates

QA considerations: N/A

One-time script: N/A

Deployment considerations: VMs were rebooted during maintenance window.

Wave tool required: N/A

Unit test case: N/A

Loom video: N/A