391
Total Pages
285
Linux-Friendly Pages
106
Pages with Bias
27.1%
Bias Rate

Bias Trend Over Time

Pages with Bias Issues

488 issues found
Showing 326-350 of 488 flagged pages
Sentinel Advanced Security Information Model (ASIM) schemas | Microsoft Docs .../main/articles/sentinel/normalization-about-schemas.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation provides a detailed overview of ASIM schemas and normalization concepts, but the only concrete example given is for Windows event 4624. No equivalent Linux or macOS event normalization example is provided, and the Windows example is presented as the sole mapping illustration. This may create friction for users seeking to normalize Linux/macOS audit or authentication events.
Recommendations
  • Add a sample entity mapping and normalization example for a common Linux audit event (e.g., a Linux authentication or process event from syslog or auditd).
  • Explicitly mention that ASIM schemas are designed to normalize data from both Windows and non-Windows sources, and provide links or references to Linux/macOS event normalization.
  • Where possible, balance Windows and Linux/macOS examples in documentation sections that are not inherently Windows-only.
Sentinel Develop Microsoft Sentinel Advanced Security Information Model (ASIM) parsers | Microsoft Docs ...ain/articles/sentinel/normalization-develop-parsers.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation is generally cross-platform, focusing on KQL and Azure-native tooling. However, there are subtle Windows biases: (1) Windows event sources (e.g., 'Microsoft-Windows-Sysmon') are used as primary examples before Linux sources; (2) PowerShell is referenced as a deployment tool for deleting functions, with no mention of Azure CLI or Linux-native alternatives; (3) Export instructions reference the 'Export to CSV' UI option without clarifying if this is available or behaves identically on Linux/macOS. No explicit Linux or macOS command-line examples are provided for deployment or testing, and Linux-specific log sources (e.g., Syslog) are mentioned but not exemplified in deployment/testing steps.
Recommendations
  • When providing event source examples, balance Windows (e.g., Sysmon) and Linux (e.g., Syslog, Auditd) sources, or alternate their order.
  • For deployment and management steps, include Azure CLI equivalents alongside PowerShell, and clarify which tools are cross-platform.
  • Explicitly state that all KQL and Azure Monitor Log features are available via browser on any OS, and clarify any UI differences for exporting data.
  • Provide at least one end-to-end example using a Linux-originating log source, including sample KQL and deployment/testing steps.
  • If PowerShell is mentioned, add a note or link to Azure CLI or Bash alternatives for Linux/macOS users.
Sentinel The Advanced Security Information Model (ASIM) DHCP normalization schema reference | Microsoft Docs ...ob/main/articles/sentinel/normalization-schema-dhcp.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation is generally source-agnostic and schema-focused, but there are several instances of Windows bias. Windows-specific terminology and examples are used before or instead of Linux equivalents (e.g., hostnames like 'DESKTOP-1282V4D', domain examples like 'Contoso', and references to Windows DHCP server logging quirks). The documentation mentions how the Windows DHCP server logs MAC addresses in a nonstandard way, but does not provide equivalent notes for Linux DHCP servers (such as ISC DHCP or Kea). Additionally, the 'SrcDomainType' field lists 'Windows' domains before FQDN, and examples are Windows-centric. There are no explicit Linux/Unix examples or references to Linux DHCP server behaviors.
Recommendations
  • Add Linux/Unix DHCP server examples (e.g., hostnames, domain formats, MAC address logging behaviors) alongside Windows examples.
  • Clarify which schema fields are relevant for Linux DHCP servers and note any differences in field population or logging formats.
  • Include notes or examples for popular Linux DHCP servers (such as ISC DHCP, Kea) where Windows-specific behaviors are discussed.
  • Present domain types (Windows, FQDN) in a neutral order and provide examples for both.
  • Where Windows quirks are mentioned (e.g., MAC address format), add a brief comparison to Linux/Unix server logging formats.
Sentinel The Advanced Security Information Model (ASIM) DNS normalization schema reference | Microsoft Docs ...lob/main/articles/sentinel/normalization-schema-dns.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Windows Examples Windows Terms
Summary
The documentation is generally source-agnostic and protocol-focused, but there are several instances of Windows-centric terminology and examples. Windows domain formats (domain\hostname), Windows-style hostnames, and Windows-specific user/process examples are presented first or exclusively. Linux equivalents (e.g., FQDN, process paths) are mentioned but often as secondary notes. No Linux/macOS-specific examples or terminology are provided, and the documentation does not offer parity in illustrating how Linux systems might represent or log DNS events.
Recommendations
  • Include Linux/macOS-specific examples for fields such as hostnames, process names, and user identifiers (e.g., /usr/bin/bash, UID formats, FQDN-only hostnames).
  • Present FQDN and Linux-style formats before or alongside Windows formats when describing fields that can have multiple representations.
  • Add explicit notes or examples for how Linux/macOS DNS servers (e.g., BIND, Unbound, dnsmasq) log or represent relevant schema fields.
  • Where Windows domain terminology is used, clarify how Linux systems would populate those fields or if they would be left blank.
  • Ensure that process and user field descriptions include Linux/macOS conventions (e.g., numeric UIDs, /proc paths, etc.).
Sentinel Sample Microsoft Sentinel workspace designs ...lob/main/articles/sentinel/sample-workspace-designs.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation repeatedly references 'Windows Security Events' and 'Windows Events' as key log sources, and provides example solutions using the Azure Monitoring Agent (AMA) for Windows VMs. There is no mention of Linux-specific log sources (e.g., Linux audit logs, syslog details) or explicit Linux collection patterns, even though Sentinel and Log Analytics support Linux VMs. The examples and recommendations focus on Windows event collection and do not provide parity for Linux VM scenarios.
Recommendations
  • Add explicit examples and guidance for collecting Linux security and audit logs (e.g., syslog, auditd) from both Azure and on-premises Linux VMs.
  • Include mention of Linux VM support in the resource types and collection requirements sections for each sample organization.
  • Provide example workspace designs that illustrate how Linux logs are ingested and segregated, similar to the Windows event examples.
  • Reference Linux agent documentation and connector options alongside Windows/AMA references.
  • Clarify that Sentinel supports both Windows and Linux VMs, and highlight any differences in configuration or log types.
Sentinel Deploy Microsoft Sentinel solution for SAP BTP .../main/articles/sentinel/sap/deploy-sap-btp-solution.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example
Summary
The documentation provides a PowerShell-only script for rotating the BTP client secret, with no equivalent example for Linux/macOS users (e.g., Bash, Azure CLI, or Python). The rest of the documentation is platform-neutral, focusing on SAP BTP and Azure portal UI steps, but the automation section assumes Windows/PowerShell usage.
Recommendations
  • Provide equivalent Bash or Azure CLI script examples for rotating the BTP client secret, suitable for Linux/macOS environments.
  • Explicitly mention that the automation can be performed on Linux/macOS and link to cross-platform Azure SDKs or CLI documentation.
  • Clarify any platform requirements for the provided scripts, and offer alternatives where possible.
Sentinel Scheduled analytics rules in Microsoft Sentinel | Microsoft Docs ...lob/main/articles/sentinel/scheduled-rules-overview.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Powershell Heavy
Summary
The documentation page for scheduled analytics rules in Microsoft Sentinel is generally platform-neutral, focusing on Kusto queries and Azure portal workflows. However, in the 'Next steps' section, PowerShell is mentioned as a primary method for automating rule enablement, with no equivalent Linux/macOS CLI (such as Azure CLI or Bash) examples or references. PowerShell is listed before API, and no Linux-native automation tools are discussed, which may create friction for non-Windows users.
Recommendations
  • Include Azure CLI examples for rule automation alongside PowerShell, or at least mention that Azure CLI can be used from Linux/macOS.
  • Provide references or links to documentation on using Bash scripts or Azure CLI for exporting/importing rules.
  • Clarify that PowerShell is cross-platform, but highlight any limitations or alternatives for Linux/macOS users.
  • When listing automation options, present API and CLI methods in a platform-neutral order (e.g., API, Azure CLI, PowerShell) or group them by OS compatibility.
Sentinel Create Playbooks for Microsoft Sentinel Solutions ...b/main/articles/sentinel/sentinel-playbook-creation.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation for creating and publishing playbooks for Microsoft Sentinel solutions demonstrates a notable Windows bias. The only provided automation tooling example for exporting/sanitizing ARM templates is a PowerShell script, with instructions focused on running it in Windows PowerShell, PowerShell Core, or Visual Studio Code. There are no equivalent examples or guidance for Linux/macOS users (e.g., Bash, Azure CLI, or cross-platform alternatives), and the script execution instructions (Set-ExecutionPolicy) are specific to Windows environments. This creates friction for users on non-Windows platforms.
Recommendations
  • Provide explicit instructions for running the PowerShell script on Linux/macOS using PowerShell Core, including prerequisites and any platform-specific considerations.
  • Offer alternative methods for exporting/sanitizing ARM templates, such as using Azure CLI, Bash scripts, or REST API calls, with examples for Linux/macOS.
  • Clarify whether the PowerShell script is cross-platform and, if so, provide usage notes for non-Windows environments.
  • Reorder or balance examples so that Linux/macOS usage is not always secondary to Windows.
  • Include troubleshooting tips for common issues encountered on Linux/macOS (e.g., permissions, module installation).
Sentinel Create Summary Rules for Microsoft Sentinel Solutions ...n/articles/sentinel/sentinel-summary-rules-creation.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page references the Windows PowerShell New-GUID cmdlet as a method to generate GUIDs, mentioning it before other platform-neutral or Linux/macOS alternatives. No Linux/macOS-specific example or tool is provided for GUID generation, and the PowerShell method is linked directly, which may create friction for non-Windows users.
Recommendations
  • List platform-neutral and cross-platform GUID generation methods first, such as online GUID generators or language-agnostic libraries (e.g., Python's uuid module, Linux 'uuidgen' command).
  • Provide explicit Linux/macOS command-line examples for GUID generation (e.g., 'uuidgen' in bash).
  • Avoid linking only to Windows/PowerShell documentation; include references to equivalent Linux/macOS tools.
  • Clarify that any tool or method capable of generating a GUID is acceptable, and provide a short list of options for different platforms.
Sentinel Import threat intelligence with the upload API ...e-docs/blob/main/articles/sentinel/stix-objects-api.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example
Summary
The documentation provides a detailed PowerShell sample for calling the upload API, including use of the MSAL.PS module and Windows certificate store paths, but does not offer equivalent examples for Linux/macOS environments (e.g., Bash, curl, Python, or OpenSSL usage). This may create friction for non-Windows users who need to authenticate and interact with the API.
Recommendations
  • Add a Linux/macOS example using Bash and curl, showing how to acquire an access token and make the API call.
  • Provide a cross-platform Python example using MSAL (Microsoft Authentication Library for Python) to demonstrate authentication and API usage.
  • Document how to handle certificates on Linux/macOS (e.g., using PEM files with MSAL or curl) instead of relying on Windows certificate store paths.
  • Clarify that the API is platform-agnostic and that any tool capable of making HTTP requests and handling OAuth2 tokens can be used.
Sentinel Microsoft Sentinel User and Entity Behavior Analytics (UEBA) reference ...ure-docs/blob/main/articles/sentinel/ueba-reference.md
Medium Priority View Details →
Scanned: 2026-01-14 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First 🔧 Windows Tools
Summary
The documentation references Windows Security Events as a primary data source and lists Windows-specific event codes and log tables before mentioning other platforms. Device-related enrichments and examples (e.g., DeviceFamily, OperatingSystem) use Windows as the sample value, with no mention of Linux or macOS equivalents. There are no Linux/macOS-specific log sources, event codes, or enrichment examples provided, and Windows terminology is used in several schema fields (e.g., SID, local admin). However, the documentation does include cloud and third-party sources (AWS, GCP, Okta), which broadens its scope beyond Windows.
Recommendations
  • Add examples of Linux/macOS device logon events and how they are ingested/analyzed by UEBA, if supported.
  • Include sample enrichment values for non-Windows operating systems (e.g., Linux, macOS) in tables and examples.
  • Clarify whether Linux/macOS security events are supported as UEBA data sources and, if so, provide equivalent event codes and log table references.
  • If Windows is the only supported OS for certain features, explicitly state this to avoid confusion.
  • Consider including a section on cross-platform support and limitations for UEBA data sources and enrichments.
Sentinel Audit log for Microsoft Sentinel data lake and graph in Microsoft Purview portal ...articles/sentinel/datalake/auditing-lake-activities.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation provides a PowerShell-only example for searching audit logs, which is a Windows-centric tool. There are no equivalent Linux/macOS CLI examples (e.g., Bash, curl, Python), nor is there mention of cross-platform alternatives. The use of PowerShell and references to Exchange Online roles further reinforce a Windows-first approach, potentially creating friction for Linux/macOS users.
Recommendations
  • Add examples using cross-platform tools such as Bash scripts, curl, or Python to query the Office 365 Management API.
  • Explicitly mention whether PowerShell Core (pwsh) is supported on Linux/macOS and provide instructions if so.
  • Provide guidance for Linux/macOS users on authenticating and accessing the audit log via REST API or SDKs.
  • Reorder or balance examples so that Windows and Linux/macOS approaches are presented equally.
Sentinel Advanced Security Information Model (ASIM) schemas | Microsoft Docs .../main/articles/sentinel/normalization-about-schemas.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation page provides a detailed overview of ASIM schemas but demonstrates bias by using only a Windows event (event 4624) as the sole normalization example. There are no Linux or macOS event examples, nor is there mention of how to normalize common Linux audit logs or syslog events. This 'Windows-first' approach may make it harder for Linux/macOS users to relate the guidance to their environments.
Recommendations
  • Add normalization examples using common Linux event sources, such as auditd, syslog, or SSH authentication logs.
  • Include a table or section mapping typical Linux/macOS event fields to ASIM schema fields, similar to the Windows event 4624 example.
  • When referencing event sources, ensure parity by alternating or including both Windows and Linux/macOS examples.
  • Explicitly mention that ASIM is designed for cross-platform data and provide links or references to Linux/macOS-specific normalization guides if available.
Sentinel Import threat intelligence with the upload API ...e-docs/blob/main/articles/sentinel/stix-objects-api.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example 🔧 Windows Tools
Summary
The documentation provides a detailed PowerShell example for interacting with the upload API, relying on the MSAL.PS PowerShell module and Windows certificate store. No equivalent examples are provided for Linux/macOS users (e.g., Bash, curl, Python, or OpenSSL usage), nor is there guidance for obtaining tokens or sending requests outside of the Windows ecosystem. This creates friction for non-Windows users and suggests a Windows-centric approach.
Recommendations
  • Add sample code for Linux/macOS environments, such as Bash/curl, Python (requests + MSAL), or other cross-platform tools.
  • Provide instructions for acquiring certificates and access tokens using OpenSSL and MSAL libraries on Linux/macOS.
  • Clarify that the API can be accessed from any OS and highlight cross-platform authentication and request methods.
  • Avoid referencing Windows-specific certificate stores (e.g., Cert:\CurrentUser\My) without Linux/macOS alternatives.
  • Include explicit notes or links to cross-platform MSAL usage and REST API invocation.
Sentinel Microsoft Sentinel skill-up training ...docs/blob/main/articles/sentinel/skill-up-resources.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Powershell Heavy Missing Linux Example
Summary
The documentation demonstrates a moderate Windows bias. Windows and Microsoft-centric tools (PowerShell, Windows Events, Defender, Azure Monitor Agent) are mentioned frequently and often before Linux alternatives. Some sections, such as monitoring agent health, explicitly call out Windows-only solutions, while Linux is referenced as an afterthought. PowerShell is presented as the default automation interface for APIs, with no mention of Bash, Python, or Linux-native CLI usage. Examples and references to Linux-specific patterns, tools, or troubleshooting are sparse or missing.
Recommendations
  • Provide Linux/macOS-specific examples alongside Windows ones, especially for automation (e.g., Bash, Python, or Azure CLI usage).
  • Mention Linux tools and connectors (Syslog, Sysmon for Linux, auditd, etc.) equally and early in relevant sections.
  • Clarify which features or monitoring solutions are cross-platform and which are Windows-only; offer Linux alternatives where possible.
  • Include troubleshooting and operational guidance for Linux/macOS environments, not just Windows.
  • Highlight Linux/macOS support in agent health, data collection, and log management sections.
  • Add parity in documentation for PowerShell-heavy sections by showing equivalent Linux-native command-line or scripting approaches.
Sentinel Onboard your Azure Stack Hub virtual machines to Microsoft Sentinel | Microsoft Docs ...ocs/blob/main/articles/sentinel/connect-azure-stack.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation page provides links to both Windows and Linux VM creation guides, but in the agent installation and troubleshooting section, it references Windows installation documentation first and only provides a troubleshooting link for Linux, omitting a direct Linux installation guide. There are no Linux-specific examples or step-by-step instructions, and Windows is mentioned before Linux in most cases.
Recommendations
  • Add a direct link to the Linux agent installation guide, not just troubleshooting.
  • Provide explicit step-by-step instructions or examples for both Windows and Linux agent installation and configuration.
  • Ensure that references to Windows and Linux are presented in parallel, rather than Windows-first.
  • Include screenshots or UI notes for Linux VMs where applicable.
Sentinel Manage custom content with repository connections ...cs/blob/main/articles/sentinel/ci-cd-custom-content.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias. While the core concepts are platform-agnostic, deployment customization is described as being available through a PowerShell deployment script, with no mention of Bash, shell, or cross-platform alternatives. There are no Linux/macOS-specific examples or explicit instructions for non-Windows environments. The use of PowerShell as the only referenced scripting tool may create friction for Linux/macOS users.
Recommendations
  • Provide equivalent Bash or shell script examples for deployment customization.
  • Clarify whether the PowerShell deployment script is cross-platform (e.g., compatible with PowerShell Core on Linux/macOS) and provide installation guidance if so.
  • Include explicit instructions or references for Linux/macOS users, such as using GitHub Actions or Azure DevOps pipelines with non-Windows runners.
  • Add examples or notes on how to run repository connection and deployment tasks from Linux/macOS environments.
Sentinel Anomalies detected by the Microsoft Sentinel machine learning engine ...ocs/blob/main/articles/sentinel/anomalies-reference.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example Powershell Heavy
Summary
The documentation page shows a notable Windows bias: anomaly detections and examples frequently reference Windows-specific logs (Windows Security logs, Event IDs 4624/4625), and PowerShell is mentioned as a sub-technique. There is a lack of parity for Linux/macOS environments—no Linux audit log, syslog, or equivalent examples are provided, and anomaly detection descriptions focus on Windows authentication and account events. Linux tools, log formats, and detection patterns are not discussed, making it unclear how Linux/macOS users can leverage these features.
Recommendations
  • Add equivalent Linux/macOS anomaly detection examples, referencing common log sources such as syslog, auditd, journald, or SSH authentication logs.
  • Include Linux-specific MITRE ATT&CK sub-techniques and activities (e.g., bash, sh, sudo, SSH brute force) alongside PowerShell.
  • Clarify which anomaly detections are supported for Linux/macOS endpoints and how to configure data ingestion from those platforms.
  • Provide sample queries or detection rules for Linux/macOS authentication and account manipulation events.
  • Reorder examples so that cross-platform or Linux/macOS scenarios are presented alongside or before Windows-specific ones where possible.
Sentinel Best practices for data collection in Microsoft Sentinel ...ocs/blob/main/articles/sentinel/best-practices-data.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Powershell Heavy Missing Linux Example
Summary
The documentation page demonstrates a moderate Windows bias. Windows-specific tools and patterns (e.g., Windows Event Forwarding, PowerShell) are mentioned more frequently and sometimes exclusively, especially in the 'On-premises Windows log collection' and 'Cloud platform data' sections. Windows solutions are often listed before Linux equivalents, and some examples (e.g., PowerShell for custom logs) lack Linux alternatives. Endpoint solutions focus on Windows Event Forwarding without Linux endpoint collection examples. While Linux solutions are present, they are less detailed and sometimes referenced after Windows options.
Recommendations
  • Ensure Linux and macOS examples are provided alongside Windows examples for all major scenarios, especially for custom log collection and endpoint solutions.
  • List Linux and Windows solutions in parallel, or alternate which is presented first, to avoid implicit prioritization.
  • Provide equivalent Linux command-line examples (e.g., Bash scripts) wherever PowerShell is referenced.
  • Expand endpoint solutions to include Linux EDR and Sysmon collection methods.
  • Clarify which agents and connectors support Linux/macOS, and provide links to relevant setup guides.
Sentinel Reduce costs for Microsoft Sentinel ...cs/blob/main/articles/sentinel/billing-reduce-costs.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation includes a dedicated section on optimizing data collection for Windows Security Events, with detailed instructions and links for Windows Server environments. There is no equivalent guidance or mention of Linux or macOS data collection optimization, nor are Linux-specific connectors or cost-saving strategies discussed. This creates a Windows-first bias and leaves Linux/macOS users without parity in cost optimization advice.
Recommendations
  • Add a section detailing cost optimization strategies for Linux and macOS data sources, including connectors, data collection rules, and filtering options.
  • Provide examples and links for configuring data collection rules for Linux agents (such as the Azure Monitor Agent on Linux) and how to filter or limit ingested events to reduce costs.
  • Ensure that references to data collection optimization are platform-neutral or include parallel guidance for non-Windows environments.
  • Mention any differences in cost management or data retention for Linux/macOS sources, if applicable.
Sentinel Connect Microsoft Sentinel to Amazon Web Services to ingest AWS service log data .../azure-docs/blob/main/articles/sentinel/connect-aws.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First
Summary
The documentation page exhibits a notable Windows bias, especially in the 'Automatic setup' section, which exclusively provides instructions for running the setup script using PowerShell and references PowerShell installation. There is no mention of Linux/macOS equivalents (e.g., Bash, Terminal), nor are alternative script invocation methods provided. The prerequisites and step-by-step instructions assume a Windows environment, and Windows tools (PowerShell) are referenced before any cross-platform alternatives. This creates friction for Linux/macOS users, who must adapt the instructions themselves.
Recommendations
  • Provide explicit instructions for running the setup script on Linux/macOS, including using Bash or Terminal.
  • Clarify whether the PowerShell script is compatible with PowerShell Core on Linux/macOS, and provide installation links for those platforms.
  • Offer alternative script invocation examples (e.g., Bash, zsh) and note any platform-specific requirements.
  • List prerequisites for Linux/macOS environments, such as required shell, Python, or other dependencies.
  • Reorder examples or provide parallel instructions so that Windows and Linux/macOS users are equally supported.
Sentinel Use Azure Functions to connect Microsoft Sentinel to your data source | Microsoft Docs .../articles/sentinel/connect-azure-functions-template.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy Windows First Missing Linux Example
Summary
The documentation provides three deployment options: ARM template, manual with PowerShell, and manual with Python. The PowerShell manual deployment is detailed and presented before the Python option, which is explicitly tied to Visual Studio Code (VS Code) for development. There are no examples or instructions for deploying with Bash, Linux shell, or other Linux-native tools. The PowerShell section is more prominent and assumes use of PowerShell Core, which, while cross-platform, is still more familiar to Windows users. The Python instructions require VS Code, which is available on Linux/macOS but is not the only editor Linux users might prefer. No Linux-specific deployment patterns or CLI examples (e.g., Azure CLI, Bash scripts) are provided.
Recommendations
  • Add manual deployment instructions using Azure CLI and Bash scripts, which are native to Linux/macOS environments.
  • Include examples or references for deploying from Linux/macOS terminals, not just PowerShell or VS Code.
  • Clarify that PowerShell Core is cross-platform and provide explicit instructions for Linux/macOS users (e.g., installation steps, command-line usage).
  • Offer parity in example order: alternate or randomize the order of PowerShell and Python instructions, or provide a Linux-first example.
  • Mention other editors (e.g., Vim, PyCharm) for Python development, or provide generic instructions not tied to VS Code.
Sentinel Collect logs from text files with the Azure Monitor Agent and ingest to Microsoft Sentinel - AMA ...blob/main/articles/sentinel/connect-custom-logs-ama.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First Powershell Heavy Missing Linux Example
Summary
The documentation is generally cross-platform and acknowledges both Windows and Linux scenarios, especially in the context of log forwarders and syslog. However, there are several areas where Windows bias is evident: Windows tools (PowerShell) are mentioned first when installing the Azure Monitor Agent, and explicit Linux command-line examples are missing for agent installation. The ARM template section references PowerShell before CLI, and there are no step-by-step Linux-specific installation instructions (e.g., apt/yum commands). The portal-based instructions are generic but the screenshots and flow are more aligned with Azure VM management, which is more familiar to Windows users.
Recommendations
  • Add explicit Linux installation instructions for the Azure Monitor Agent (e.g., apt/yum commands, systemctl usage).
  • Provide Linux CLI examples before or alongside PowerShell examples, or at least present them in parallel tabs.
  • Include screenshots or walkthroughs for Linux VM resource selection and agent association.
  • Clarify any differences in file path patterns or permissions for Linux vs. Windows.
  • Ensure that troubleshooting and configuration notes include Linux-specific guidance (e.g., SELinux, systemd).
Sentinel Create scheduled analytics rules from templates in Microsoft Sentinel | Microsoft Docs ...ticles/sentinel/create-analytics-rule-from-template.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation page references PowerShell as a method to push rules to Microsoft Sentinel, but does not mention or provide equivalent Linux/macOS CLI examples (such as Bash, Azure CLI, or REST API usage from non-Windows environments). The only automation tool explicitly named is PowerShell, which is Windows-centric, and no Linux/macOS alternatives are discussed or shown. This creates friction for users on non-Windows platforms who wish to automate rule management.
Recommendations
  • Provide examples using Azure CLI for rule management, including exporting and enabling rules via CLI commands.
  • Explicitly mention that the REST API can be used from any platform, and provide sample curl or HTTP request examples for Linux/macOS users.
  • Add a note or section clarifying cross-platform options for automation, including Bash scripting and other non-Windows tools.
  • Ensure parity in documentation by listing Linux/macOS-compatible methods before or alongside PowerShell.
Sentinel Create scheduled analytics rules in Microsoft Sentinel | Microsoft Docs .../blob/main/articles/sentinel/create-analytics-rules.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Powershell Heavy Windows First
Summary
The documentation page for creating scheduled analytics rules in Microsoft Sentinel demonstrates a moderate Windows bias. While the core workflow is portal-based and platform-agnostic, references to automation and rule management via PowerShell are present, and PowerShell is mentioned as the primary scripting tool for enabling rules via code. There are no Linux shell (bash/CLI) equivalents or examples provided, and the only automation tooling referenced outside the portal is Windows-centric. Additionally, the mention of exporting rules to ARM templates and enabling via API is followed by PowerShell, with no Linux or cross-platform alternatives suggested. The order of mention also places Windows tools before API usage.
Recommendations
  • Include examples for managing analytics rules using Azure CLI (az sentinel), which is cross-platform and works on Linux/macOS.
  • Provide bash or shell script snippets for exporting/importing rules, or reference relevant Linux tools.
  • Explicitly state that API-based management can be performed from any OS, and provide curl or Python examples for Linux/macOS users.
  • Mention that PowerShell Core is available on Linux/macOS, or clarify if only Windows PowerShell is supported.
  • Add a section or note on Linux/macOS automation options for rule management.