391
Total Pages
285
Linux-Friendly Pages
106
Pages with Bias
27.1%
Bias Rate

Bias Trend Over Time

Pages with Bias Issues

488 issues found
Showing 351-375 of 488 flagged pages
Sentinel Notebook examples for querying the Microsoft Sentinel data lake ...b/main/articles/sentinel/datalake/notebook-examples.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page demonstrates a notable Windows bias by referencing Visual Studio Code (VS Code) and the Microsoft Sentinel extension as the primary environment for running Jupyter notebooks, without mentioning Linux/macOS alternatives or confirming cross-platform compatibility. There are no explicit PowerShell examples, but the setup instructions and context assume a Windows-centric workflow. The code samples themselves are Python and Spark-based, which are cross-platform, but the lack of guidance for Linux/macOS users on installation, environment setup, or troubleshooting creates friction.
Recommendations
  • Explicitly state that the examples and the Microsoft Sentinel extension for VS Code are supported on Linux and macOS, or provide alternative instructions if not.
  • Add setup instructions for Linux/macOS users, including installation of VS Code, Python, Spark, and the Sentinel extension.
  • Mention other Jupyter notebook environments (e.g., JupyterLab, classic Jupyter Notebook) and clarify compatibility.
  • Provide troubleshooting tips for common Linux/macOS issues (e.g., permissions, package installation, Spark configuration).
  • If any features are Windows-only, clearly call this out and suggest alternatives or workarounds for Linux/macOS.
Sentinel This file is auto-generated . Do not edit manually. Changes will be overwritten. ...in/articles/sentinel/includes/deprecated-connectors.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Powershell Heavy
Summary
The documentation page exhibits a notable Windows bias. Several connectors (Exchange Logs, Security Events) explicitly mention Windows machines and agents, with instructions and prerequisites focused on Windows environments. Windows agents and tools are referenced before Linux equivalents, and links to installation procedures prioritize PowerShell and Windows tabs. Linux is only directly addressed in the Syslog connector, which is presented after multiple Windows-centric sections.
Recommendations
  • Provide Linux/macOS examples and instructions for all connectors where applicable, not just for Syslog.
  • Ensure installation guides and prerequisites include parity for Linux environments (e.g., Bash, Linux agents, CLI instructions).
  • Present Windows and Linux options side-by-side, or in a neutral order, rather than Windows-first.
  • Reference cross-platform tools and procedures where possible, and avoid PowerShell/Windows-only links.
  • Clarify which connectors are cross-platform and which are Windows-only, with explicit notes for Linux/macOS users.
Sentinel Scenarios detected by the Microsoft Sentinel Fusion engine ...ob/main/articles/sentinel/fusion-scenario-reference.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First
Summary
The documentation page demonstrates a moderate Windows bias, particularly in the 'Malicious execution with legitimate process' section, which focuses on Windows-specific tools and techniques such as PowerShell and WMI. These examples are given without Linux/macOS equivalents or mention of cross-platform alternatives. The overall page is heavily oriented toward Microsoft cloud and security products, but the specific technical scenarios for detection and response reference Windows-centric attack patterns and tools first, with little to no coverage of Linux/macOS-specific threats or command-line tools.
Recommendations
  • Add equivalent examples for Linux/macOS, such as detection of suspicious Bash or Python command execution, or remote SSH activity.
  • Include references to Linux/macOS credential theft tools (e.g., 'LaZagne', 'John the Ripper') alongside Windows tools like Mimikatz.
  • Expand coverage of attack techniques to include Linux/macOS-specific management and scripting interpreters (e.g., shell scripts, cron jobs, systemd abuse).
  • Where PowerShell or WMI is mentioned, also discuss how similar malicious activity might be detected on non-Windows endpoints.
  • Add scenarios for cloud resource abuse or data exfiltration that are relevant to Linux-based workloads.
Sentinel This file is auto-generated . Do not edit manually. Changes will be overwritten. ...b/main/articles/sentinel/includes/connector-details.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation for Microsoft Sentinel data connectors exhibits a Windows bias in several areas. Many connectors, especially those related to on-premises log collection (e.g., Exchange, Active Directory, IIS, Windows Firewall), explicitly reference Windows machines, Windows Event Logs, and the use of Windows agents. Instructions and examples for collecting logs from Windows systems are provided, while equivalent Linux/macOS instructions are often absent or less detailed. Windows tools and patterns (such as Windows Event Forwarding, Windows Firewall, and references to Windows-specific agents) are mentioned prominently, sometimes without Linux alternatives or with Linux options listed after Windows. In some cases, connectors are only described in the context of Windows environments, leaving Linux/macOS users with unclear guidance or no path to implementation.
Recommendations
  • For each connector or log type that references Windows-specific tools or agents, provide equivalent instructions and examples for Linux (and, where possible, macOS).
  • Where Windows Event Logs or Windows-specific agents are mentioned, also describe how to collect analogous logs from Linux systems (e.g., using Syslog, auditd, or other native Linux logging mechanisms).
  • Avoid listing Windows tools or patterns first by default; instead, present cross-platform options side-by-side or in parallel sections.
  • Clearly indicate platform support and limitations for each connector, and provide explicit guidance for non-Windows environments.
  • Where a connector is Windows-only, state this explicitly and, if possible, suggest workarounds or alternative solutions for Linux/macOS users.
Sentinel SAP agentless data connector prerequisites checker ...icles/sentinel/includes/sap-agentless-prerequisites.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy Missing Linux Example 🔧 Windows Tools Windows First
Summary
The documentation provides only a PowerShell script as the sample for triggering the SAP prerequisites checker iflow, with no equivalent example for Linux/macOS users (e.g., Bash/cURL). PowerShell is a Windows-centric tool, and its exclusive use and mention creates friction for users on other platforms. The documentation does not mention or prioritize Linux/macOS alternatives.
Recommendations
  • Add a Bash/cURL example for triggering the iflow, demonstrating how Linux/macOS users can perform the same task.
  • Explicitly state that any REST client can be used, and list popular cross-platform options (e.g., curl, httpie, Postman).
  • If scripting is required, provide both Windows (PowerShell) and Linux/macOS (Bash/cURL) scripts side by side.
  • Avoid implying PowerShell is the default or only method; present platform-neutral instructions first.
Sentinel Microsoft Sentinel migration: Select a data ingestion tool | Microsoft Docs ...lob/main/articles/sentinel/migration-ingestion-tool.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows First
Summary
The documentation page exhibits a moderate Windows bias. Several key ingestion tools and workflows are described as PowerShell scripts, and the SIEM data migration accelerator is designed to deploy a Windows VM and install Windows-centric tools. While some tools (AzCopy, Logstash) are cross-platform, Windows and PowerShell are frequently mentioned first or exclusively, and Linux/macOS alternatives are not equally highlighted or exemplified.
Recommendations
  • Provide explicit Linux/macOS usage examples for all ingestion tools, especially for the Azure Monitor custom log ingestion tool and direct API methods.
  • Clarify whether the custom log ingestion tool (PowerShell script) can be run on Linux/macOS with PowerShell Core, or provide equivalent Bash/Python scripts.
  • Offer instructions for deploying the SIEM data migration accelerator on Linux VMs, or provide a cross-platform alternative.
  • In sections where PowerShell is mentioned, also include CLI, Bash, or Python examples.
  • Ensure that cross-platform tools (AzCopy, Logstash) have parity in documentation, with equal emphasis on Linux/macOS usage.
  • Avoid language that assumes Windows as the default environment (e.g., 'deploys a Windows VM') unless strictly necessary.
Sentinel Develop Microsoft Sentinel Advanced Security Information Model (ASIM) parsers | Microsoft Docs ...ain/articles/sentinel/normalization-develop-parsers.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Powershell Heavy Windows First
Summary
The documentation page exhibits moderate Windows bias, primarily in the deployment section where PowerShell and Windows-centric tools are referenced for deleting and deploying parser functions. The use of the Azure portal and PowerShell is mentioned before alternatives, and the function delete tool is specifically a PowerShell script. There are no explicit Linux/macOS examples or instructions for equivalent CLI tools (e.g., Azure CLI, Bash). The rest of the documentation is platform-neutral, focusing on KQL and Azure services.
Recommendations
  • Add explicit instructions and examples for deploying and deleting parser functions using Azure CLI, which is cross-platform.
  • Mention Bash or shell scripting alternatives for automation steps, especially for Linux/macOS users.
  • Clarify that the Azure portal and ARM templates are accessible from any OS, and provide links to platform-agnostic documentation.
  • If PowerShell scripts are referenced, provide equivalent Bash or Python scripts for Linux/macOS users.
  • Ensure that any tool or script referenced is available or has alternatives for all major platforms.
Sentinel Microsoft Purview Information Protection connector reference - audit log record types and activities support in Microsoft Sentinel .../sentinel/microsoft-purview-record-types-activities.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Missing Linux Example
Summary
The documentation references the Unlock-SPOSensitivityLabelEncryptedFile PowerShell cmdlet as a method for removing sensitivity labels from files, but does not mention any Linux/macOS equivalent or alternative. No Linux/macOS-specific tools, commands, or examples are provided, and the only actionable tool mentioned is Windows/PowerShell-centric.
Recommendations
  • Provide information on whether the Unlock-SPOSensitivityLabelEncryptedFile cmdlet can be run from Linux/macOS using PowerShell Core, or suggest alternative methods for non-Windows platforms.
  • Include examples or guidance for Linux/macOS users on how to perform sensitivity label operations, if supported.
  • Clarify platform requirements and limitations for all referenced tools and commands.
  • If no Linux/macOS alternatives exist, explicitly state this to inform users.
Sentinel Advanced Security Information Model (ASIM) security content | Microsoft Docs ...s/blob/main/articles/sentinel/normalization-content.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Windows Examples Missing Linux Example
Summary
The documentation page demonstrates a notable Windows bias, especially in the Process Activity section, where many hunting queries and analytics rules focus on Windows-specific tools (PowerShell, rundll32.exe, certutil, etc.) and attack patterns. There is a lack of Linux/macOS-specific examples, tools, or queries, and no parity for Linux process, file, or session activity is provided. The registry activity section is inherently Windows-centric, and most examples reference Windows-centric threats and utilities. No Linux-specific content, such as bash scripts, Linux process monitoring, or Linux-specific threat detection, is present.
Recommendations
  • Add Linux/macOS-specific analytics rules and hunting queries, e.g., detection of suspicious bash scripts, cron jobs, or Linux persistence techniques.
  • Include examples for Linux process activity (e.g., monitoring suspicious use of systemd, bash, python, or SSH).
  • Provide parity for file activity and session monitoring on Linux/macOS, such as detection of suspicious file changes or network connections.
  • Explicitly mention Linux/macOS equivalents for Windows tools (e.g., use of curl/wget instead of PowerShell for downloads, Linux system logs instead of Windows Event Logs).
  • Balance examples between Windows and Linux/macOS, or clearly indicate platform applicability for each rule/query.
Sentinel The Advanced Security Information Model (ASIM) Application Entity reference .../articles/sentinel/normalization-entity-application.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Missing Linux Example
Summary
The documentation page displays a Windows bias in its examples and terminology. Process-related fields consistently use Windows-style paths (e.g., 'C:\Windows\explorer.exe') and Windows tools (e.g., 'rundll32.exe') as examples, with no Linux or macOS equivalents shown. The guidance on process IDs mentions Windows and Linux together, but examples and terminology are Windows-centric, and Linux/macOS process naming conventions are not represented.
Recommendations
  • Include Linux/macOS process examples (e.g., '/usr/bin/bash', '/usr/sbin/sshd') alongside Windows examples for fields like ProcessName and Process.
  • Provide sample process IDs and paths for Linux/macOS in addition to Windows.
  • Clarify that process paths and names are OS-dependent, and offer guidance for Linux/macOS users.
  • Avoid using only Windows-specific tools (e.g., 'rundll32.exe') in examples; balance with cross-platform or Linux/macOS-specific processes.
Sentinel The Advanced Security Information Model (ASIM) Audit Events normalization schema reference | Microsoft Docs ...b/main/articles/sentinel/normalization-schema-audit.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows Examples Windows Terms Windows First
Summary
The documentation page is largely platform-neutral in its schema descriptions, but there are several subtle signs of Windows bias. Examples of hostnames and usernames use Windows-style formats (e.g., 'DESKTOP-1282V4D', domain\hostname, 'Windows' as UsernameType), and fields like 'Scheduled Task', 'Service', and 'Directory Service Object' are more common in Windows environments. The only concrete example of an acting application is a Windows path ('C:\Windows\System32\svchost.exe'). Linux/macOS equivalents are not mentioned, and Windows terminology appears first or exclusively in some field descriptions.
Recommendations
  • Add Linux/macOS-specific examples for hostnames, usernames, and application paths (e.g., '/usr/bin/sshd', 'ubuntu-server', 'user@domain').
  • Include Linux/macOS object types in the ObjectType field (e.g., 'Cron Job', 'Systemd Service', 'Unix Group').
  • When describing FQDN and domain formats, mention Linux/macOS conventions (e.g., 'hostname.domain.tld').
  • Provide examples of audit events from Linux/macOS systems alongside Windows examples.
  • Clarify that the schema is intended to be cross-platform and provide guidance for mapping Linux/macOS audit concepts to the schema fields.
Sentinel The Advanced Security Information Model (ASIM) DHCP normalization schema reference | Microsoft Docs ...ob/main/articles/sentinel/normalization-schema-dhcp.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Windows Heavy Examples
Summary
The documentation page exhibits a moderate Windows bias. Several field descriptions and examples reference Windows-specific formats, tools, or behaviors (e.g., Windows DHCP server, domain\hostname format, SIDs, and MAC address logging quirks). Windows terminology and examples are presented first or exclusively, with little to no mention of Linux or other DHCP server implementations. There are no Linux/macOS-specific examples, notes, or guidance for users of non-Windows platforms.
Recommendations
  • Include examples and notes for Linux-based DHCP servers (e.g., ISC DHCP, Kea), such as how session IDs or MAC addresses are logged and parsed.
  • Clarify how fields like SrcDomainType, SrcFQDN, and SrcUserIdType should be populated for non-Windows environments.
  • Add explicit guidance on handling differences in log formats and field values between Windows and Linux/macOS DHCP servers.
  • Provide Linux/macOS-specific sample values and edge cases alongside Windows examples.
  • Reference open-source DHCP server documentation or community best practices for non-Windows platforms.
Sentinel The Advanced Security Information Model (ASIM) Process Event normalization schema reference | Microsoft Docs ...rticles/sentinel/normalization-schema-process-event.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Windows First 🔧 Windows Tools Windows Examples Windows Terms
Summary
The documentation page exhibits a moderate Windows bias. Many field examples use Windows paths (e.g., C:\Windows\explorer.exe), Windows-specific concepts (e.g., integrity levels, UAC, session IDs), and references to Windows documentation. Linux/macOS equivalents are not provided, and terminology is often Windows-centric, though some notes acknowledge Linux. No Linux-specific examples, tools, or terminology are present.
Recommendations
  • Add Linux/macOS process path examples (e.g., /usr/bin/bash) alongside Windows examples.
  • Document Linux/macOS equivalents for concepts like integrity levels, session IDs, and privilege elevation.
  • Reference Linux/macOS documentation for process security concepts where appropriate.
  • Clarify which fields and values are OS-specific, and provide guidance for Linux/macOS normalization.
  • Include notes or tables comparing Windows, Linux, and macOS process event fields and behaviors.
Sentinel The Advanced Security Information Model (ASIM) Network Session normalization schema reference | Microsoft Docs ...main/articles/sentinel/normalization-schema-network.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Windows Examples Windows Terms Windows First
Summary
The documentation contains several Windows-centric examples and terminology, such as Windows-style hostnames (e.g., 'DESKTOP-1282V4D'), Windows domain formats (e.g., 'Contoso\DESKTOP-1282V4D'), and process paths (e.g., 'C:\Windows\explorer.exe'). Windows terms and formats are mentioned first or exclusively in many field descriptions, while Linux/macOS equivalents are not provided or are only briefly referenced. This may create friction for Linux/macOS users trying to map their data to the schema.
Recommendations
  • Add Linux/macOS-specific examples alongside Windows examples for fields like hostnames, FQDNs, and process names (e.g., 'ubuntu-server', '/usr/bin/sshd').
  • Explicitly mention Linux/macOS formats for fields that currently only show Windows formats (e.g., show both 'Contoso\DESKTOP-1282V4D' and 'ubuntu-server.example.com').
  • Clarify that fields such as process IDs, hostnames, and FQDNs are OS-agnostic and provide normalization guidance for non-Windows systems.
  • Where Windows terminology is used (e.g., 'Windows domain'), add equivalent Linux/macOS terminology or note differences.
  • Ensure that examples and field descriptions do not imply Windows as the default or only supported platform.
Sentinel Deploy Microsoft Sentinel solution for SAP BTP .../main/articles/sentinel/sap/deploy-sap-btp-solution.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example
Summary
The documentation provides a sample script for rotating the BTP client secret using PowerShell and Azure PowerShell modules, which are primarily Windows-centric tools. There are no equivalent examples or instructions for Linux/macOS users (e.g., Bash, Azure CLI, or Python). The exclusive use of PowerShell and lack of cross-platform scripting guidance creates friction for non-Windows users.
Recommendations
  • Provide equivalent sample scripts using Bash and Azure CLI for Linux/macOS users.
  • Explicitly mention cross-platform alternatives and clarify which steps/tools work on all platforms.
  • Add a note about PowerShell Core compatibility on Linux/macOS, if applicable.
  • Ensure all automation and onboarding instructions include both Windows and Linux/macOS options.
Sentinel Prerequisites for deploying Microsoft Sentinel solution for SAP applications ...uisites-for-deploying-sap-continuous-threat-monitoring.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation page generally focuses on cross-platform deployment, with clear support for Linux container hosts and SAP systems. However, there is a notable Windows bias in the 'connection-agentless' prerequisites section, where the only example for installing the Log Analytics agent refers to Windows computers, with no equivalent Linux instructions or links. Additionally, the reference to workspace keys is linked to a Windows-specific page before any Linux alternative is mentioned.
Recommendations
  • Add explicit instructions and links for installing the Log Analytics agent on Linux hosts, alongside the Windows example.
  • Ensure that references to workspace keys and agent installation include both Windows and Linux documentation, or use neutral phrasing.
  • Review all examples and tool references to confirm Linux parity and avoid Windows-first ordering.
  • Consider adding a table or section that lists supported platforms for each prerequisite, making it clear that Linux is fully supported.
Sentinel Create Analytics Rules for Microsoft Sentinel Solutions .../articles/sentinel/sentinel-analytic-rules-creation.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page exhibits Windows bias primarily in the 'ID' section, where PowerShell's New-GUID cmdlet is mentioned as a method to generate GUIDs, with no mention of Linux/macOS alternatives. This places Windows tooling first and may cause friction for non-Windows users. No Linux or cross-platform command-line tools (such as uuidgen) are referenced. The rest of the documentation is platform-neutral.
Recommendations
  • Include Linux/macOS alternatives for GUID generation, such as the uuidgen command.
  • Present cross-platform methods (e.g., Python's uuid module) for generating GUIDs.
  • List Windows, Linux, and web-based options together or in parallel, rather than mentioning Windows tools first.
  • Review other sections for similar tool references and ensure parity.
Sentinel Create Playbooks for Microsoft Sentinel Solutions ...b/main/articles/sentinel/sentinel-playbook-creation.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 4 bias types
Detected Bias Types
Powershell Heavy 🔧 Windows Tools Missing Linux Example Windows First
Summary
The documentation repeatedly instructs users to download and run a PowerShell script for ARM template sanitization, specifying usage in Windows PowerShell, PowerShell Core, or Visual Studio Code. There are no equivalent instructions or examples for Linux/macOS users, nor are alternative methods (such as Azure CLI, Bash, or cross-platform scripting) mentioned. The only script execution guidance provided is for PowerShell, and the prerequisite command (Set-ExecutionPolicy) is Windows-specific. This creates friction for users on Linux or macOS, who may not have PowerShell installed or may prefer native tools.
Recommendations
  • Provide explicit instructions for running the PowerShell script on Linux/macOS using PowerShell Core (pwsh), including installation steps if needed.
  • Offer alternative methods for ARM template sanitization, such as using Azure CLI, Bash scripts, or manual steps that do not require PowerShell.
  • Include cross-platform notes and examples, ensuring Linux/macOS users are not excluded from critical steps.
  • Reorder or parallelize instructions so that Windows and Linux/macOS approaches are presented together, rather than Windows-first.
Sentinel Create Summary Rules for Microsoft Sentinel Solutions ...n/articles/sentinel/sentinel-summary-rules-creation.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 3 bias types
Detected Bias Types
🔧 Windows Tools Windows First Missing Linux Example
Summary
The documentation page displays Windows bias in the 'ID' section, where the PowerShell 'New-GUID' cmdlet is mentioned as a method for generating GUIDs, with no mention of Linux/macOS alternatives. The Windows tool is referenced first and exclusively, and no cross-platform or Linux/macOS command-line examples (such as 'uuidgen') are provided. This may cause friction for non-Windows users who need to generate GUIDs for summary rules.
Recommendations
  • Include Linux/macOS alternatives for GUID generation, such as the 'uuidgen' command.
  • Present cross-platform options together, e.g., 'You can generate a GUID using PowerShell (New-GUID), Linux/macOS (uuidgen), or an online generator.'
  • Avoid referencing Windows tools exclusively or first; provide parity in examples and tooling.
  • Consider adding a table or section listing equivalent commands for common tasks across platforms.
Sentinel Microsoft Sentinel User and Entity Behavior Analytics (UEBA) reference ...ure-docs/blob/main/articles/sentinel/ueba-reference.md
Medium Priority View Details →
Scanned: 2026-01-13 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Windows First
Summary
The documentation page displays a moderate Windows bias, primarily through its focus on Windows-centric data sources (e.g., Windows Security Events, Windows Forwarded Events, Microsoft Defender XDR, Active Directory). Device-related enrichments and examples frequently reference Windows-specific concepts (such as SIDs, local admin status, Windows 10 OS, and device families labeled 'Windows'), with little mention of Linux or macOS equivalents. While some cloud and third-party sources (AWS, GCP, Okta) are included, there is a lack of parity in describing Linux/macOS device logon events, enrichments, or schema fields. The documentation does not provide Linux/macOS-specific examples, nor does it clarify how non-Windows endpoints are represented or analyzed in UEBA.
Recommendations
  • Add explicit documentation and examples for Linux and macOS device logon events, including how these are ingested, analyzed, and enriched in UEBA.
  • Expand the 'Device family' and 'Operating system' enrichments to include Linux and macOS, with sample values and descriptions.
  • Clarify whether fields such as SID, local admin status, and device type are applicable to non-Windows platforms, and document platform-specific differences.
  • Provide guidance or references for integrating Linux/macOS endpoints with Microsoft Sentinel UEBA, including supported connectors and schema mappings.
  • Ensure that examples and tables do not default to Windows terminology, and present cross-platform information in a balanced manner.
Sentinel Authenticate playbooks to Microsoft Sentinel | Microsoft Docs ...tinel/automation/authenticate-playbooks-to-sentinel.md
Medium Priority View Details →
Scanned: 2026-01-11 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
🔧 Windows Tools Missing Linux Example
Summary
The documentation exclusively references Azure portal GUI steps and Microsoft-specific tools (Logic Apps, Microsoft Entra, Azure portal) for authentication and configuration. There are no command-line examples, nor any mention of Linux-native tools, CLI (az), or cross-platform automation methods. All instructions assume use of the Azure portal, which is most commonly accessed from Windows environments, and do not provide parity for Linux users who may prefer CLI or scripting approaches.
Recommendations
  • Add equivalent Azure CLI (az) command examples for all authentication and role assignment steps, enabling Linux and cross-platform users to follow along without relying on the Azure portal GUI.
  • Explicitly mention that all steps can be performed from any OS, and provide links to CLI documentation.
  • Include PowerShell and Bash script examples side-by-side where applicable.
  • Reference automation options (such as Terraform, ARM templates) that are platform-agnostic.
  • Clarify that Logic Apps and Sentinel are cloud services accessible from any OS, and avoid implying a Windows-centric workflow.
Sentinel Microsoft Sentinel Solution for MS Business Apps ...es/sentinel/business-applications/solution-overview.md
Medium Priority View Details →
Scanned: 2026-01-11 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Missing Linux Example 🔧 Windows Tools
Summary
The documentation focuses exclusively on Microsoft cloud products and their integration with Microsoft Sentinel, with no mention of Linux-specific tools, patterns, or examples. All referenced technologies (Power Platform, Dynamics 365, Sentinel) are Microsoft-centric, and there is no discussion of how to use or integrate these solutions in Linux environments, nor are there examples using Linux command-line tools or shell scripting. The documentation implicitly assumes a Windows/Microsoft ecosystem, which may disadvantage Linux users or those seeking cross-platform guidance.
Recommendations
  • Add examples or guidance for integrating Microsoft Sentinel with Linux-based SIEM tools or log sources.
  • Include instructions for accessing and processing logs using Linux command-line tools (e.g., curl, jq, bash) in addition to Microsoft-centric tools.
  • Provide parity in automation examples, such as showing how to trigger playbooks or hunting queries using Linux shell scripts or open-source orchestration tools.
  • Mention compatibility or integration steps for organizations using Linux servers or endpoints alongside Microsoft Business Apps.
  • Clarify whether the solution supports log ingestion from Linux-based services and how to configure such sources.
Sentinel Onboard your Azure Stack Hub virtual machines to Microsoft Sentinel | Microsoft Docs ...ocs/blob/main/articles/sentinel/connect-azure-stack.md
Medium Priority View Details →
Scanned: 2026-01-11 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation demonstrates a Windows-first bias by referencing Windows VM creation instructions before Linux, and by providing a direct link to detailed Windows agent installation guidance, while only offering a troubleshooting link for Linux. There are no explicit Linux onboarding or installation examples, and Linux guidance is less prominent.
Recommendations
  • Provide explicit, step-by-step onboarding instructions for both Windows and Linux VMs, ensuring parity in detail and clarity.
  • List Linux and Windows VM creation links together or alternate their order to avoid implicit prioritization.
  • Include a direct link to the Linux agent installation documentation, not just troubleshooting.
  • Where agent installation is referenced, offer both Windows and Linux links side-by-side.
  • Add Linux-specific screenshots or examples where appropriate.
Sentinel Stream data from Microsoft Purview Information Protection to Microsoft Sentinel ...ob/main/articles/sentinel/connect-microsoft-purview.md
Medium Priority View Details →
Scanned: 2026-01-11 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Missing Linux Example
Summary
The documentation assumes use of the Azure portal and Microsoft Sentinel, which are primarily accessed via web interfaces but are most commonly associated with Windows environments. There are no references to Linux-specific tools, CLI commands, or cross-platform setup instructions. All examples and instructions are generic or GUI-based, but they implicitly favor Windows-centric workflows and do not mention Linux alternatives or considerations.
Recommendations
  • Add instructions for setting up and managing the connector using cross-platform tools such as Azure CLI or PowerShell Core, which run on Linux and macOS as well as Windows.
  • Include explicit notes or examples for Linux users, such as how to access the Azure portal from Linux, or how to perform relevant operations using command-line tools available on Linux.
  • Mention any platform-specific limitations or considerations (e.g., if certain features are only available on Windows, state this clearly).
  • Provide parity in troubleshooting and known issues sections by noting any differences in experience between Windows and Linux environments.
  • Where Kusto queries are shown, clarify that they are platform-agnostic and can be run from any supported environment.
Sentinel Create a codeless connector for Microsoft Sentinel ...ob/main/articles/sentinel/create-codeless-connector.md
Medium Priority View Details →
Scanned: 2026-01-11 00:00
Reviewed by: LLM Analysis
Issues: 2 bias types
Detected Bias Types
Windows First Powershell Heavy
Summary
The documentation page demonstrates a Windows bias in its API testing tool recommendations, listing Visual Studio Code, PowerShell Invoke-RestMethod, and Microsoft Edge Network Console before mentioning Bruno and curl. PowerShell is specifically called out as an example, and no Linux-specific tools (such as httpie, wget, or Linux-native shell commands) are mentioned. The examples and instructions do not provide parity for Linux users, and the ordering suggests a preference for Windows tools.
Recommendations
  • Include Linux-native API testing tools (e.g., httpie, wget) in the recommended list alongside curl.
  • Provide example commands for API testing using bash, curl, or httpie, not just PowerShell.
  • Ensure that tool recommendations are ordered in a platform-neutral way (e.g., alphabetical or by popularity across platforms).
  • Explicitly mention that all steps can be performed on Linux, macOS, and Windows, and provide guidance for cross-platform compatibility.
  • Add notes or links for installing and using recommended tools on Linux and macOS.