Configuration Compliance integration with MS Defender for cloud - Incomplete data.

Raghav Kakkar
Tera Expert

Hi all,

 

I have a few questions regarding implementation of Configuration Compliance via integration with MS Defender for Cloud. I know it's a lot of information to ask for, but I'm fairly new to Config compliance with no prior knowledge about VR or MS Defender for cloud. Help would be highly appreciated 🙂

 

Currently, I am able to fetch data to Test Groups (sn_vulc_policy) and Configuration Tests (sn_vulc_tests) tables.

 

1. What data is this exactly that is being fetched? I checked the Secure Score recommendations on MS Defender for cloud console. There were only 250 recommendations while I have around 3000 Test groups.

2. I have fetched 900 configuration tests. What exactly is this data in terms of MS Defender for Cloud? Why are there less configurations tests than test groups?

3. The test group record is also incomplete (Attached SS). It doesn't show the number of CIs we need to remediate.

4. Similarly, configuration test records are also incomplete. They do not have remediation details filled in (Check SS).

5. Tables that are empty: Test results, Remediation tasks, Technologies, Authoritative sources. Why are these tables empty?

 

Note: MS Defender for cloud has 6 integrations. 5 integrations run perfectly but one of the integration always fails "ASC Resource Integration". Error: "Encountered error running the integration. Error: Invalid response code received from ASCResourceIntegration: Bad Request 400". What is this integration about?

 

RaghavKakkar_1-1700413773980.png

 

RaghavKakkar_0-1700413669896.png

 

0 REPLIES 0