Microsoft Defender for Cloud
Cloud and workloads

Validate your Microsoft Defender for APIs alerts

In brief

The article now uses clearer descriptions, explicitly links to prerequisites for onboarding and API publication, and renames the section to “Next steps.”

What Defender admins need to know

Administrators can use the updated prerequisites and streamlined instructions when testing suspicious-user-agent alerts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Validate your Microsoft Defender for APIs alerts

Microsoft Defender for APIs offers full lifecycleprovides protection, detection, and response coverage for APIs that are published in Azure API Management. One of the main capabilitiesA key feature is the ability to detect exploitsdetection of the Open Web Application Security Project (OWASP)OWASP API Top 10 vulnerabilities throughvulnerabilities. It spots anomalies at runtime observations of anomaliesby using machine learning-basedlearning and rule-based detections.methods.

This pagearticle walks you through the stepshow to trigger ana test alert for one of your API endpoints through Defender for APIs. In this scenario, theendpoints. The alert is for thecovers detection of a suspicious user agent. Before you start, make sure you meet the prerequisites, including having an API published and Defender for APIs onboarded.

Prerequisites

Simulate an alert

It's important to validateValidate that Defender for APIs is working as expected. To validate that Defender for APIs is monitoring your API correctly, simulate an alert by sendingSend a request to your endpoint with a suspicious user agent.agent to simulate an alert.

  1. Sign in to the Azure portal.

After some time, Defender for APIs triggers an alert with detailed information about the simulated suspicious user-agent activity.

Next stepsteps

[!div class="nextstepaction"]