Skip to content

Commit dbc8262

Browse files
Merge pull request #312628 from netapp-manishc/patch-914810
Update ransomware protection configuration details
2 parents f7f5627 + fc3555b commit dbc8262

1 file changed

Lines changed: 4 additions & 3 deletions

File tree

articles/azure-netapp-files/ransomware-configure.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ services: azure-netapp-files
55
author: b-ahibbard
66
ms.service: azure-netapp-files
77
ms.topic: how-to
8-
ms.date: 02/24/2026
8+
ms.date: 03/05/2026
99
ms.author: anfdocs
1010
ms.custom: references_regions
1111
---
@@ -28,7 +28,8 @@ Advanced ransomware protection's alert mechanisms enable you to stay vigilant in
2828
* Attack reports are retained for 30 days.
2929
* Ransomware threat notifications are sent in the Azure Activity log.
3030
* It’s recommended that you enable no more than five volumes per Azure region with advanced ransomware protection to mitigate performance issues.
31-
* It's recommended you increase QoS capacity by 5 to 10 percent due to potential performance impacts of advanced ransomware protection. The scale of the impact can vary based on the configurations across your Azure NetApp Files deployment.
31+
* It's recommended you increase QoS capacity by 5 to 10 percent due to potential performance impacts of advanced ransomware protection. The scale of the impact can vary based on the configurations across your Azure NetApp Files deployment.
32+
* If your volumes have workloads with a high level of encryption and deletion, it may increase the possibility of false positives. It is recommended not to enable advanced ransomware protection on these volumes.
3233

3334
## Supported regions
3435

@@ -127,7 +128,7 @@ You can also use [Azure CLI commands](/cli/azure/feature) `az feature register`
127128
128129
:::image type="content" source="./media/ransomware-configure/ransomware-threats.png" alt-text="Screenshot of ransomware threats." lightbox="./media/ransomware-configure/ransomware-threats.png":::
129130
130-
1. If you know the files are **not** an active threat, mark the files as a **False positive**.
131+
1. If you know the files are **not** an active threat, mark the active threat as a **False positive**.
131132
132133
If you believe the files are a threat, select **Threat**. You can then [revert the volume](snapshots-revert-volume.md) based on the last snapshot captured before the threat.
133134
1. Once you've resolved the threat, you can view archived ransomware reports on the same page. Reports are archived for 30 days.

0 commit comments

Comments
 (0)