Important upcoming changes to Microsoft Defender for Cloud

Note

Azure Security Center and Azure Defender are now called Microsoft Defender for Cloud. We've also renamed Azure Defender plans to Microsoft Defender plans. For example, Azure Defender for Storage is now Microsoft Defender for Storage.

Learn more about the recent renaming of Microsoft security services.

Important

The information on this page relates to pre-release products or features, which may be substantially modified before they are commercially released, if ever. Microsoft makes no commitments or warranties, express or implied, with respect to the information provided here.

On this page, you'll learn about changes that are planned for Defender for Cloud. It describes planned modifications to the product that might impact things like your secure score or workflows.

If you're looking for the latest release notes, you'll find them in the What's new in Microsoft Defender for Cloud.

Planned changes

Planned change Estimated date for change
Deprecating a preview alert: ARM.MCAS_ActivityFromAnonymousIPAddresses November 2021
Legacy implementation of ISO 27001 is being replaced with new ISO 27001:2013 November 2021
Container security features to be grouped under Defender for Containers December 2021
Multiple changes to identity recommendations December 2021
Enhancements to recommendation to classify sensitive data in SQL databases Q1 2022
Changes to recommendations for managing endpoint protection solutions March 2022

Deprecating a preview alert: ARM.MCAS_ActivityFromAnonymousIPAddresses

Estimated date for change: November 2021

We'll be deprecating the following preview alert:

Alert name Description
PREVIEW - Activity from a risky IP address
(ARM.MCAS_ActivityFromAnonymousIPAddresses)
Users activity from an IP address that has been identified as an anonymous proxy IP address has been detected.
These proxies are used by people who want to hide their device's IP address, and can be used for malicious intent. This detection uses a machine learning algorithm that reduces false positives, such as mis-tagged IP addresses that are widely used by users in the organization.
Requires an active Microsoft Defender for Cloud Apps license.

We've created new alerts that provide this information and add to it. In addition, the newer alerts (ARM_OperationFromSuspiciousIP, ARM_OperationFromSuspiciousProxyIP) don't require a license for Microsoft Defender for Cloud Apps (formerly known as Microsoft Cloud App Security).

Legacy implementation of ISO 27001 is being replaced with new ISO 27001:2013

Estimated date for change: November 2021

The legacy implementation of ISO 27001 will be removed from Defender for Cloud's regulatory compliance dashboard. If you're tracking your ISO 27001 compliance with Defender for Cloud, onboard the new ISO 27001:2013 standard for all relevant management groups or subscriptions, and the current legacy ISO 27001 will soon be removed from the dashboard.

Defender for Cloud's regulatory compliance dashboard showing the message about the removal of the legacy implementation of ISO 27001.

Multiple changes to identity recommendations

Estimated date for change: December 2021

Defender for Cloud includes multiple recommendations for improving the management of users and accounts. In December, we'll be making the changes outlined below.

Container security features to be grouped under Defender for Containers

Estimated date for change: December 2021

Microsoft Defender for Cloud's container security features are currently available through two Microsoft Defender plans: Microsoft Defender for Kubernetes and Microsoft Defender for container registries.

With this change:

  • These two plans will be deprecated.
  • The two existing recommendations to enable the current plans will also be deprecated: Azure Defender for Kubernetes should be enabled and Azure Defender for container registries should be enabled.
  • A new, combined plan, Microsoft Defender for Containers, will include all their features as well as a more streamlined and feature-rich experience to help you protect your container solutions.

There'll be no change to subscriptions that already have Defender for Kubernetes or Defender for container registries enabled. You'll have the option to upgrade your existing subscriptions to Microsoft Defender for Containers.

When we release Microsoft Defender for Containers for general availability, new subscriptions won't have the option to use the deprecated plans.

Learn more about Container security in Microsoft Defender for Cloud.

Enhancements to recommendation to classify sensitive data in SQL databases

Estimated date for change: Q1 2022

The recommendation Sensitive data in your SQL databases should be classified in the Apply data classification security control will be replaced with a new version that's better aligned with Microsoft's data classification strategy. As a result the recommendation's ID will also change (currently, it's b0df6f56-862d-4730-8597-38c0fd4ebd59).

Changes to recommendations for managing endpoint protection solutions

Estimated date for change: March 2022

In August 2021, we added two new preview recommendations to deploy and maintain the endpoint protection solutions on your machines. For full details, see the release note.

When the recommendations are released to general availability, they will replace the following existing recommendations:

Learn more:

Next steps

For all recent changes to Defender for Cloud, see What's new in Microsoft Defender for Cloud?