Microsoft Defender for Endpoint (MDE) must be connected to a central log server.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-272889MSDE-00-000450SV-272889r1119412_ruleCCI-001851high
Description
Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common process in information systems with limited audit storage capacity. Satisfies: SRG-APP-000515, SRG-APP-000086, SRG-APP-000108, SRG-APP-000125, SRG-APP-000181, SRG-APP-000358, SRG-APP-000745
STIGDate
Microsoft Defender for Endpoint Security Technical Implementation Guide2025-11-25

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · V1R2 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-001851
1.00
  • DISA · V1R2 · disa_xccdf · related

Details

Check Text (C-272889r1119412_chk)

Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the navigation pane, select Settings >> Microsoft Sentinel. 2. Under "Workspaces", verify a Sentinel Workspace has been assigned. If a Sentinel Workspace has not been assigned, this is a finding. If another documented and authorizing official (AO)-approved SIEM/Central Log Server is in use, this is not a finding.

Fix Text (F-76885r1119367_fix)

Access the MDE portal as a user with at least an MDE Administrator or equivalent role: 1. In the MDE portal select Settings >> Microsoft Sentinel. 2. Under Workspaces connect a Sentinel Workspace.