Azure landing zone Documentation
Home GitHub Issue Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage

Turn off Defender Plans

Defender plans are enabled by default. To turn off individual Defender plans, follow the steps below.

  1. Update the parPolicyAssignmentParameterOverrides section in the appropriate management group’s .bicepparam file.
  2. Find the Deploy-MDFC-Config-H224 policy assignment block.
  3. Set the desired Defender plan parameters to Disabled.
Warning
Update the correct management group’s .bicepparam file where the Deploy-MDFC-Config-H224 policy assignment is deployed.

Example: turn off a subset of Defender plans.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
param parPolicyAssignmentParameterOverrides = {
  'Deploy-MDFC-Config-H224': {
    parameters: {
      ascExportResourceGroupName: {
        value: '<rg_name>'
      }
      ascExportResourceGroupLocation: {
        value: '<location>'
      }
      emailSecurityContact: {
        value: 'security_contact@replace_me'
      }
      enableAscForServers: {
        value: 'Disabled'
      }
      enableAscForServersVulnerabilityAssessments: {
        value: 'DeployIfNotExists'
      }
      enableAscForSql: {
        value: 'DeployIfNotExists'
      }
      enableAscForAppServices: {
        value: 'DeployIfNotExists'
      }
      enableAscForStorage: {
        value: 'DeployIfNotExists'
      }
      enableAscForContainers: {
        value: 'DeployIfNotExists'
      }
      enableAscForKeyVault: {
        value: 'DeployIfNotExists'
      }
      enableAscForSqlOnVm: {
        value: 'Disabled'
      }
      enableAscForArm: {
        value: 'DeployIfNotExists'
      }
      enableAscForOssDb: {
        value: 'Disabled'
      }
      enableAscForCosmosDbs: {
        value: 'DeployIfNotExists'
      }
      enableAscForCspm: {
        value: 'DeployIfNotExists'
      }
    }
  }
}
Tip
The complete list of supported parameters can be found in the Deploy-MDFC-Config-H224 policy assignment within the Azure Landing Zones Library.

Exclude MDFC Policy Assignment

To prevent the Deploy-MDFC-Config-H224 policy assignment from being deployed, add it to the managementGroupExcludedPolicyAssignments array.

1
2
3
4
5
param landingZonesConfig = {
  managementGroupExcludedPolicyAssignments: [
    'Deploy-MDFC-Config-H224'
  ]
}

Configure MDFC Policy Assignment in DoNotEnforce Mode

To deploy the policy assignment without enforcing it, add it to the managementGroupDoNotEnforcePolicyAssignments array.

1
2
3
4
5
param landingZonesConfig = {
  managementGroupDoNotEnforcePolicyAssignments: [
    'Deploy-MDFC-Config-H224'
  ]
}

Validate Configuration

After deployment:

  1. Verify that the Deploy-MDFC-Config-H224 policy assignment exists at the expected management group scope.
  2. Verify that the policy assignment parameters contain the expected values.
  3. Review Microsoft Defender for Cloud and confirm that the desired Defender plans are enabled or disabled as expected.
  4. Review policy compliance results to confirm the deployment completed successfully.