Microsoft Defender for Cloud
Cloud and workloads

Review changes in file integrity monitoring

In brief

The article now explicitly covers tracked file and registry changes, clarifies the Defender for Endpoint agent prerequisite, and expands the explanation of the Log Analytics agent/MMA terminology and previous experience option.

What Defender admins need to know

No administrator action is indicated; use the clarified prerequisite and terminology when following the review instructions.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Review changes in file integrity monitoring

Use File Integrity Monitoring in Defender for Cloud to review tracked file and registry changes.

Prerequisites

Before you review file changes, make sure the following prerequisites are met:

  • Defender for Servers Plan 2 must be enabled.
  • File integrity monitoring with the Defender for Endpoint agent must be enabled. If itfile integrity monitoring with the Defender for Endpoint agent isn't enabledenabled, this message appears -appears: File Integrity Monitoring is not enabled. To enable it, select Onboard subscriptions, and then enable the feature.file integrity monitoring.

Monitor entities and files

  1. If you select the subscription of the resource (under the column Subscription name), a query opens with all the tracked files and registries in that subscription.

Retrieve and analyze file integrity monitoring data