You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- US (East US, East US 2, West US, West US 2, West US 3, Central US, North Central US, South Central US, West Central US, East US 2 EUAP, Central US EUAP)
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/enable-api-security-posture.md
+8-1Lines changed: 8 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,7 +4,7 @@ description: Learn how to enable API security posture management in Microsoft De
4
4
ms.author: elkrieger
5
5
author: Elazark
6
6
ms.topic: how-to
7
-
ms.date: 01/04/2026
7
+
ms.date: 03/31/2026
8
8
ms.custom: sfi-image-nochange, references_regions
9
9
#customer intent: As a cloud administrator, I want to learn how to enable API security posture management to protect my APIs in Azure API Management, Function Apps, and Logic Apps.
10
10
---
@@ -34,8 +34,15 @@ API Security Posture Management within Defender CSPM is available in the Azure c
- US (East US, East US 2, West US, West US 2, West US 3, Central US, North Central US, South Central US, West Central US, East US 2 EUAP, Central US EUAP)
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/recommendations-reference-data.md
+22Lines changed: 22 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1925,6 +1925,28 @@ Even with key owner precautions, keys can be easily leaked by less than optimum
1925
1925
1926
1926
**Severity**: High
1927
1927
1928
+
### Geo-redundant backups should be enabled for PostgreSQL Servers
1929
+
1930
+
**Description**:
1931
+
__What is geo-redundant backup?__ Geo-redundant backup replicates server backups to a paired Azure region, providing resilience against regional failures.
1932
+
1933
+
__Why is it a security concern?__ If geo-redundant backups are disabled, a regional outage could result in data loss and extended downtime, impacting availability and compliance.
1934
+
1935
+
__How could attackers exploit it or how could it lead to data breaches?__ While not directly exploitable, lack of geo-redundancy increases the impact of disasters or targeted attacks on a single region.
1936
+
1937
+
**Severity**: Low
1938
+
1939
+
### require_secure_transport should be set to “on” for Azure Database for PostgreSQL Servers
1940
+
1941
+
**Description**:
1942
+
__What is require_secure_transport?__ require_secure_transport is a server-level parameter that enforces the use of SSL/TLS for all client connections to PostgreSQL. When set to on, clients must connect using encrypted channels.
1943
+
1944
+
__Why is it a security concern?__ If this setting is disabled (off), clients may connect over unencrypted channels, exposing sensitive data such as credentials, queries, and results to interception or manipulation.
1945
+
1946
+
__How could attackers exploit it or how could it lead to data breaches?__ An attacker on the network could perform a man-in-the-middle attack, intercepting or altering data exchanged between the client and server if encryption is not enforced.
1947
+
1948
+
**Severity**: High
1949
+
1928
1950
## Related content
1929
1951
1930
1952
-[Learn about security recommendations](security-policy-concept.md)
| March 30, 2026 | Alert | Preview | The following alert is now in Preview: <br> * Malicious content detected in uploaded AI model |
52
+
| March 29, 2026 | Recommendation | Preview | The following recommendations are now available in preview for Azure Database for PostgreSQL Flexible Servers as part of Defender CSPM:<br/>* Geo-redundant backups should be enabled for PostgreSQL Servers <br/>* require_secure_transport should be set to "on" for Azure Database for PostgreSQL Servers |
52
53
| March 29, 2026 | Recommendation | Deprecation | Following the announcement from December 3, 2025, The recommendation `Microsoft Defender for SQL status should be protected for Arc-enabled SQL Servers` for Defender for SQL Servers on Machines plan, is now deprecated. |
53
54
| March 04, 2026 | Recommendation | Upcoming deprecation | The following grouped container vulnerability recommendations are set for deprecation on April 13, 2026:<br/>**Container recommendations:**<br/>\* [Preview] Containers running in Azure should have vulnerability findings resolved<br/>\* [Preview] Containers running in AWS should have vulnerability findings resolved<br/>\* [Preview] Containers running in GCP should have vulnerability findings resolved<br/>**Container image recommendations:**<br/>\* [Preview] Container images in Azure registry should have vulnerability findings resolved<br/>\* [Preview] Container images in AWS registry should have vulnerability findings resolved<br/>\* [Preview] Container images in GCP registry should have vulnerability findings resolved<br/><br/>These grouped recommendations are being replaced by individual recommendations that provide more granular visibility, better prioritization, and improved governance. Learn more in [Deprecation of preview of container and container images vulnerability recommendations](release-notes.md#deprecation-of-preview-of-container-and-container-images-vulnerability-recommendations). |
54
55
| February 24, 2026 | Recommendation | GA | The following data recommendations are GA: <br><br> - [Storage accounts should restrict network access using virtual network rules](recommendations-reference-data.md#storage-accounts-should-restrict-network-access-using-virtual-network-rules). <br><br> - [Storage account should use a private link connection](recommendations-reference-data.md#storage-account-should-use-a-private-link-connection). <br><br> - [Storage accounts should prevent shared key access](recommendations-reference-data.md#storage-accounts-should-prevent-shared-key-access). |
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/release-notes.md
+26-3Lines changed: 26 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,8 @@
2
2
title: What's new in Microsoft Defender for Cloud features
3
3
description: What's new and updated in Microsoft Defender for Cloud features
4
4
ms.topic: overview
5
-
ms.date: 03/30/2026
5
+
ms.custom: references_regions
6
+
ms.date: 03/31/2026
6
7
---
7
8
8
9
# What's new in Defender for Cloud features
@@ -31,6 +32,7 @@ This article summarizes what's new in Microsoft Defender for Cloud. It includes
31
32
32
33
| Date | Category | Update |
33
34
| -------- | -------- | -------- |
35
+
| March 31, 2026| Update |[Support for additional Azure regions for Defender for APIs and API security posture management with Defender CSPM](#support-for-additional-azure-regions-for-defender-for-apis-and-api-security-posture-management-with-defender-cspm)|
34
36
| March 30, 2026 | Preview |[AI model security for Azure Machine Learning (Preview)](#ai-model-security-for-azure-machine-learning-preview)|
35
37
| March 29, 2026 | Preview |[Expanded multicloud coverage for AWS and GCP (Preview)](#expanded-multicloud-coverage-for-aws-and-gcp-preview)|
36
38
| March 22, 2026| Update |[File Integrity Monitoring requires MDE agent version 10.8799+ for legacy Windows machines](#file-integrity-monitoring-requires-mde-agent-version-108799-for-legacy-windows-machines)|
@@ -41,9 +43,31 @@ This article summarizes what's new in Microsoft Defender for Cloud. It includes
41
43
| March 04, 2026 | Deprecation |[Deprecation of preview of container and container images vulnerability recommendations](#deprecation-of-preview-of-container-and-container-images-vulnerability-recommendations)|
42
44
| March 04, 2026 | Preview |[New individual recommendations format in Azure portal (Preview)](#new-individual-recommendations-format-in-azure-portal-preview)|
43
45
46
+
### Support for additional Azure regions for Defender for APIs and API security posture management with Defender CSPM
47
+
48
+
49
+
Microsoft Defender for APIs and API security posture management with Defender CSPM has expanded to provide its capabilities in the following Azure regions:
50
+
- Sweden Central
51
+
- Sweden South
52
+
- Germany West Central
53
+
- Germany North
54
+
- Italy North
55
+
- France Central
56
+
- France South
57
+
- Norway East
58
+
- Norway West
59
+
- Switzerland North
60
+
- Switzerland West
61
+
- Korea Central
62
+
- Korea South
63
+
64
+
Customers who have Azure API Management services in these regions can now use the capabilities offered by Microsoft Defender for APIs and API security posture management with Defender CSPM.
65
+
API discovery and security posture capabilities in Defender CSPM for Azure Function Apps and Azure Logic Apps have also been expanded to these regions. This feature is still in Preview.
66
+
67
+
Learn more about [Microsoft Defender for APIs](defender-for-apis-introduction.md) and [API security posture management with Defender CSPM](api-security-posture-overview.md).
68
+
44
69
### AI model security for Azure Machine Learning (Preview)
45
70
46
-
March 30, 2026
47
71
48
72
Microsoft Defender for Cloud now offers AI model security in preview for Azure Machine Learning registries and workspaces. AI model security helps security teams discover and scan custom AI models for risks before deployment, and review findings in Defender for Cloud.
49
73
@@ -78,7 +102,6 @@ Learn more about [security recommendations](review-security-recommendations.md).
78
102
79
103
### File Integrity Monitoring requires MDE agent version 10.8799+ for legacy Windows machines
80
104
81
-
March 22, 2026
82
105
83
106
Due to a pipeline change in Microsoft Defender for Endpoint (MDE), File Integrity Monitoring now requires the **Defender for Servers Windows client (Microsoft Defender for Endpoint agent) version 10.8799 or above** for proper functionality on legacy Windows machines (downlevel clients).
0 commit comments