-
Notifications
You must be signed in to change notification settings - Fork 254
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix EXO deprecated alert policies in MS.EXO.16.1 #29
Comments
Baseline policy updates will happen as part of larger baseline updates, but this issue is related specifically to fixing the Rego to ensure it is fixed post baseline update. |
Related #235 |
This should be addressed as part of Defender and EXO policy updates noting that the associated Defender baseline policy item is now MS.DEFENDER.5.1v1. |
…436) * adjudicate exo comments and refactor implementation * address #29 in the baseline document * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Get-OrganizationConfig Spacing Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Defender apostrophe typo fix Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * first pass at addressing comments * address all current feedback * clean up Defender duplicated policy linking * clean up missing clarification * address 2nd round of feedback * clean up the defender links round 2 * fix the brain fart * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * spacing the rationale --------- Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
Latest EXO policy has now been merged to Emerald, so the referenced alerts are no longer indicated in the baselines. Code updates are pending to realign rego assessments with updated policy language. Removed baseline-document label since this is purely a Rego code update issue now. Issue is resolved when MS.EXO.16.1 assessment check updates its list of alerts to match the updated policy. |
…436) * adjudicate exo comments and refactor implementation * address #29 in the baseline document * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Get-OrganizationConfig Spacing Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Defender apostrophe typo fix Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * first pass at addressing comments * address all current feedback * clean up Defender duplicated policy linking * clean up missing clarification * address 2nd round of feedback * clean up the defender links round 2 * fix the brain fart * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * spacing the rationale --------- Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
…436) * adjudicate exo comments and refactor implementation * address #29 in the baseline document * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Get-OrganizationConfig Spacing Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Defender apostrophe typo fix Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * first pass at addressing comments * address all current feedback * clean up Defender duplicated policy linking * clean up missing clarification * address 2nd round of feedback * clean up the defender links round 2 * fix the brain fart * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * spacing the rationale --------- Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
Code updates were made in #527 |
…436) * adjudicate exo comments and refactor implementation * address #29 in the baseline document * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Get-OrganizationConfig Spacing Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Defender apostrophe typo fix Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * first pass at addressing comments * address all current feedback * clean up Defender duplicated policy linking * clean up missing clarification * address 2nd round of feedback * clean up the defender links round 2 * fix the brain fart * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * spacing the rationale --------- Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
…436) * adjudicate exo comments and refactor implementation * address #29 in the baseline document * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Get-OrganizationConfig Spacing Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * Defender apostrophe typo fix Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * first pass at addressing comments * address all current feedback * clean up Defender duplicated policy linking * clean up missing clarification * address 2nd round of feedback * clean up the defender links round 2 * fix the brain fart * Update baselines/exo.md Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com> * spacing the rationale --------- Co-authored-by: Addam Schroll <108814318+schrolla@users.noreply.github.com>
Defender 2.9 was showing as a fail in the report and highlighted 2 policies.
Both of these prebuilt alert policies have disappeared from the Alert Policy list and thus from current Provider exports.
I looked back at an older Provider JSON and found that policies were still there a little over month ago.
The names of these policies are listed in EXO 2.16, so this will require both a baseline policy update and a Rego code change.
The text was updated successfully, but these errors were encountered: