• ApeNo1@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    1 day ago

    I have been on the cloud vendor side forced into using these crappy Microsoft protection tools because of the daft Azure compliance framework. Customers would ask for your score on this and your score was impacted by how many of these very expensive services you had enabled. THEY DID NOT WORK! We had an independent security testing org prove that uploaded malware was half flagged by defender for storage but then no subsequent downstream events were triggered. Microsoft simply said “known issue and will be fixed at some point”. Un-fucking-believable. Azure compliance framework is 100% an Azure services upsell versus a genuine security focus initiative.

    • blargh513@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 day ago

      I had to push defender to an entire enterprise. So many issues on Linux. We had to take it off and swap in a different edr just so we would stop breaking our Linux hosts.

      Different company, rolled out crowdstrike. Not perfect, but far fewer issues by a longshot.

      I’m so over Microsoft and their bs nickel and dining, enable features and then once you’re dependent on them , start charging. Fuck that shitbag of a company. Go back to making office software, that’s the only thing they did marginally well. Microsoft security is an oxymoron.

      Greedy fucks.

    • corsicanguppy@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      Azure compliance framework is 100% an Azure services upsell versus a genuine security focus initiative.

      You’re telling me that a compliance test made by a vendor seems to only test how much you’ve spent with the vendor and not how secure you are?

      I’m shocked.