Turn off Defender Plans
Defender plans are enabled by default. To turn off individual Defender plans, follow the steps below.
- Update the
parPolicyAssignmentParameterOverridessection in the appropriate management group’s.bicepparamfile. - Find the
Deploy-MDFC-Config-H224policy assignment block. - Set the desired Defender plan parameters to
Disabled.
WarningUpdate the correct management group’s.bicepparamfile where theDeploy-MDFC-Config-H224policy assignment is deployed.
Example: turn off a subset of Defender plans.
| |
TipThe complete list of supported parameters can be found in the Deploy-MDFC-Config-H224 policy assignment within the Azure Landing Zones Library.
To prevent the Deploy-MDFC-Config-H224 policy assignment from being deployed, add it to the managementGroupExcludedPolicyAssignments array.
| |
To deploy the policy assignment without enforcing it, add it to the managementGroupDoNotEnforcePolicyAssignments array.
| |
After deployment:
- Verify that the
Deploy-MDFC-Config-H224policy assignment exists at the expected management group scope. - Verify that the policy assignment parameters contain the expected values.
- Review Microsoft Defender for Cloud and confirm that the desired Defender plans are enabled or disabled as expected.
- Review policy compliance results to confirm the deployment completed successfully.
