I need a solution
Are anyone else experiencing problems with the 14 RU1 cloud portal?
When you enroll into the RU1 cloud you are no longer able to create an "allow application" exclusions from the on-premise SEPM risk Monitor logs. You have to wait for the incident to appear in the Cloud portal and then create an exclusion by hash from the cloud event using the new whitelist policies.
My problem is that incidents never seem to reach the cloud portal. If i manually create an exclusion in the cloud whitelist policy it will eventually reach the SEPM (5-10 minutes later) so I know that the SEPM is enrolled and communicating.
0