diff --git a/en/azure/securitycenter/monitor-system-updates.md b/en/azure/securitycenter/monitor-system-updates.md index 03f0bcd67..e9f5d0fb8 100644 --- a/en/azure/securitycenter/monitor-system-updates.md +++ b/en/azure/securitycenter/monitor-system-updates.md @@ -16,15 +16,14 @@ ## Detailed Remediation Steps -1. Log into the Microsoft Azure Management Console. -2. Select the "Search resources, services, and docs" option at the top and search for Security Center.
-3. Scroll down the "Security Center" and select the "Security policy" option under "Management" in the left navigation panel.
-4. On the "Policy Management" page under "Name" column select the "Subscription Name" that needs to be verified.
-5. In the "Security Policy" page scroll down and click on the "Azure Security Benchmark".
-6. In the "Azure Security Benchmark" click on the Next button.
-7. In the "Azure Security Benchmark", check for the "System updates should be installed on your machines" Parameter and if it's set to "Disable" then the encryption is not enabled.
-8. Repeat steps number 2 - 7 to check other "Subscriptions" under the "Security Center."
-9. Navigate to the "Security Center", select the "Security policy" and under "Policy Management" select the "Subscription" that needs to enable the "Monitor System Updates."
-10. Select the "Subscription" link under the "Security policy" at the top to get into the configuration settings.
-11. Scroll down the page and under "Parameter" choose the "System updates should be installed on your machines" and select the "AuditIfNotExists" option from the dropdown menu and click on the "Save" button at the bottom to make the necessary changes.
-12. Repeat steps number 9 - 11 to ensure System Update monitoring is configured for virtual machines from the Azure Security Center.
+1. Log in to the Microsoft Azure Management Console. +2. Select the "Search resources, services, and docs" option at the top and search for "Microsoft Defender for Cloud".
+3. Scroll down the left navigation panel and select the "Environment Settings" under "Management".
+4. On the "Microsoft Defender for Cloud | Environment settings" page, under "Name" column select the "Subscription Name" that needs to be verified by clicking on its Name.
+5. On the "Settings" page scroll down the "Policy settings" section and select "Security Policy".
+6. On the "Settings | Security policy" page, Select the "Subscription" link under the "Security policy" at the top to get into the configuration settings.
+7. On the Settings page, select the "Parameters" tab and uncheck "Only show parameters that need input or review". It will show you a list of parameters.
+8. In the list search for the setting "System updates should be installed on your machines". If it's set to "Disabled" then "System Update monitoring" is not enabled on the selected "Subscription".
+9. To enable "System Update monitoring" click to open the dropdown of "System updates should be installed on your machines" and select the "AuditIfNotExists" option. Click on the "Review + save" button at the bottom.
+10. On the "Review + save" page, click on "Save" button to make the necessary changes.
+11. Repeat steps number 3 - 10 to ensure "System Update monitoring" is configured from the Azure Security Center.
diff --git a/resources/azure/securitycenter/monitor-system-updates/step10.png b/resources/azure/securitycenter/monitor-system-updates/step10.png index 9df01ccdb..dda4eb200 100644 Binary files a/resources/azure/securitycenter/monitor-system-updates/step10.png and b/resources/azure/securitycenter/monitor-system-updates/step10.png differ diff --git a/resources/azure/securitycenter/monitor-system-updates/step11.png b/resources/azure/securitycenter/monitor-system-updates/step11.png deleted file mode 100644 index abb53fa39..000000000 Binary files a/resources/azure/securitycenter/monitor-system-updates/step11.png and /dev/null differ diff --git a/resources/azure/securitycenter/monitor-system-updates/step2.png b/resources/azure/securitycenter/monitor-system-updates/step2.png index cfde9d1e4..a47b64e4a 100644 Binary files a/resources/azure/securitycenter/monitor-system-updates/step2.png and b/resources/azure/securitycenter/monitor-system-updates/step2.png differ diff --git a/resources/azure/securitycenter/monitor-system-updates/step3.png b/resources/azure/securitycenter/monitor-system-updates/step3.png index 4a8dc2082..0afa159aa 100644 Binary files a/resources/azure/securitycenter/monitor-system-updates/step3.png and b/resources/azure/securitycenter/monitor-system-updates/step3.png differ diff --git a/resources/azure/securitycenter/monitor-system-updates/step4.png b/resources/azure/securitycenter/monitor-system-updates/step4.png index b8a515918..c9483c269 100644 Binary files a/resources/azure/securitycenter/monitor-system-updates/step4.png and b/resources/azure/securitycenter/monitor-system-updates/step4.png differ diff --git a/resources/azure/securitycenter/monitor-system-updates/step5.png b/resources/azure/securitycenter/monitor-system-updates/step5.png index 13fbb99d1..a6ecf9a05 100644 Binary files a/resources/azure/securitycenter/monitor-system-updates/step5.png and b/resources/azure/securitycenter/monitor-system-updates/step5.png differ diff --git a/resources/azure/securitycenter/monitor-system-updates/step6.png b/resources/azure/securitycenter/monitor-system-updates/step6.png index ff30e7ae5..0b12ebd18 100644 Binary files a/resources/azure/securitycenter/monitor-system-updates/step6.png and b/resources/azure/securitycenter/monitor-system-updates/step6.png differ diff --git a/resources/azure/securitycenter/monitor-system-updates/step7.png b/resources/azure/securitycenter/monitor-system-updates/step7.png index e321e3a10..55ddf2b87 100644 Binary files a/resources/azure/securitycenter/monitor-system-updates/step7.png and b/resources/azure/securitycenter/monitor-system-updates/step7.png differ diff --git a/resources/azure/securitycenter/monitor-system-updates/step8.png b/resources/azure/securitycenter/monitor-system-updates/step8.png index 40aa71be2..2dbb868db 100644 Binary files a/resources/azure/securitycenter/monitor-system-updates/step8.png and b/resources/azure/securitycenter/monitor-system-updates/step8.png differ diff --git a/resources/azure/securitycenter/monitor-system-updates/step9.png b/resources/azure/securitycenter/monitor-system-updates/step9.png index 86f67d202..b36adcf72 100644 Binary files a/resources/azure/securitycenter/monitor-system-updates/step9.png and b/resources/azure/securitycenter/monitor-system-updates/step9.png differ