You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/concept-defender-for-cosmos.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,11 +12,11 @@ APPLIES TO: :::image type="icon" source="media/icons/yes-icon.png" border="false
12
12
13
13
Microsoft Defender for Azure Cosmos DB detects potential SQL injections, known bad actors based on Microsoft Threat Intelligence, suspicious access patterns, and potential exploitation of your database through compromised identities, or malicious insiders.
14
14
15
-
Defender for Azure Cosmos DB uses advanced threat detection capabilities, and [Microsoft Threat Intelligence](https://www.microsoft.com/insidetrack/microsoft-uses-threat-intelligence-to-protect-detect-and-respond-to-threats) data to provide contextual security alerts. Those alerts also include steps to mitigate the detected threats and prevent future attacks.
15
+
Microsoft Defender for Azure Cosmos DB uses advanced threat detection capabilities, and [Microsoft Threat Intelligence](https://www.microsoft.com/insidetrack/microsoft-uses-threat-intelligence-to-protect-detect-and-respond-to-threats) data to provide contextual security alerts. Those alerts also include steps to mitigate the detected threats and prevent future attacks.
16
16
17
17
You can [enable protection for all your databases](quickstart-enable-database-protections.md) (recommended), or [enable Microsoft Defender for Azure Cosmos DB](quickstart-enable-defender-for-cosmos.md) at either the subscription level, or the resource level.
18
18
19
-
Defender for Azure Cosmos DB continually analyzes the telemetry stream generated by the Azure Cosmos DB services. When potentially malicious activities are detected, security alerts are generated. These alerts are displayed in Microsoft Defender for Cloud together with the details of the suspicious activity along with the relevant investigation steps, remediation actions, and security recommendations.
19
+
Microsoft Defender for Azure Cosmos DB continually analyzes the telemetry stream generated by the Azure Cosmos DB services. When potentially malicious activities are detected, security alerts are generated. These alerts are displayed in Microsoft Defender for Cloud together with the details of the suspicious activity along with the relevant investigation steps, remediation actions, and security recommendations.
20
20
21
21
Microsoft Defender for Azure Cosmos DB doesn't access the Azure Cosmos DB account data, and doesn't have any effect on its performance.
22
22
@@ -30,7 +30,7 @@ Microsoft Defender for Azure Cosmos DB doesn't access the Azure Cosmos DB accoun
30
30
31
31
## What are the benefits of Microsoft Defender for Azure Cosmos DB
32
32
33
-
Microsoft Defender for Azure Cosmos DB uses advanced threat detection capabilities and Microsoft Threat Intelligence data, Microsoft Defender for Azure Cosmos DB continuously monitors your Azure Cosmos DB accounts for threats such as SQL injection, compromised identities and data exfiltration.
33
+
Microsoft Defender for Azure Cosmos DB uses advanced threat detection capabilities and Microsoft Threat Intelligence data. Microsoft Defender for Azure Cosmos DB continuously monitors your Azure Cosmos DB accounts for threats such as SQL injection, compromised identities and data exfiltration.
34
34
35
35
This service provides action-oriented security alerts in Microsoft Defender for Cloud with details of the suspicious activity and guidance on how to mitigate the threats.
36
36
You can use this information to quickly remediate security issues and improve the security of your Azure Cosmos DB accounts.
@@ -44,13 +44,13 @@ Alerts include details of the incident that triggered them, and recommendations
44
44
45
45
Threat intelligence security alerts are triggered for:
46
46
47
-
-**Potential SQL injection attacks**: <br>
47
+
-**Potential SQL injection attacks**: <br>
48
48
Due to the structure and capabilities of Azure Cosmos DB queries, many known SQL injection attacks can’t work in Azure Cosmos DB. However, there are some variations of SQL injections that can succeed and may result in exfiltrating data from your Azure Cosmos DB accounts. Microsoft Defender for Azure Cosmos DB detects both successful and failed attempts, and helps you harden your environment to prevent these threats.
49
49
50
-
-**Anomalous database access patterns**:
50
+
-**Anomalous database access patterns**: <br>
51
51
For example, access from a TOR exit node, known suspicious IP addresses, unusual applications, and unusual locations.
52
52
53
-
-**Suspicious database activity**:
53
+
-**Suspicious database activity**: <br>
54
54
For example, suspicious key-listing patterns that resemble known malicious lateral movement techniques and suspicious data extraction patterns.
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/quickstart-enable-database-protections.md
+1-3Lines changed: 1 addition & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -58,9 +58,7 @@ You can enable database protection on your subscription, or exclude specific dat
58
58
59
59
In this article, you learned how to enable Microsoft Defender for Cloud for all database types on your subscription. Next, read more about each of the resource types.
60
60
61
-
> [!div class="nextstepaction"]
62
-
> [Microsoft Defender for Azure SQL](defender-for-sql-introduction.md)
63
-
61
+
-[Microsoft Defender for Azure SQL](defender-for-sql-introduction.md)
64
62
-[Microsoft Defender for open-source relational databases](defender-for-databases-introduction.md)
65
63
-[Microsoft Defender for Azure Cosmos](concept-defender-for-cosmos.md)
66
64
-[Microsoft Defender for servers](defender-for-sql-usage.md)
1. Navigate to **your Azure Cosmos DB account** > **Settings**.
64
64
65
-
1. Select **Enable Microsoft Defender for Storage**.
65
+
1. Select **Microsoft Defender for Cloud**.
66
66
67
-
:::image type="content" source="media/quickstart-enable-defender-for-cosmos/enable-storage.png" alt-text="Screenshot of the option to enable Microsoft Defender for Storage on your specified Azure Cosmos DB account.":::
67
+
1. Select **Enable Microsoft Defender for Azure Cosmos DB**.
68
+
69
+
:::image type="content" source="media/quickstart-enable-defender-for-cosmos/enable-storage.png" alt-text="Screenshot of the option to enable Microsoft Defender for Azure Cosmos DB on your specified Azure Cosmos DB account.":::
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/supported-machines-endpoint-solutions-clouds.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Microsoft Defender for Cloud's features according to OS, machine type, and cloud
3
3
description: Learn about the availability of Microsoft Defender for Cloud features according to OS, machine type, and cloud deployment.
4
4
ms.topic: overview
5
-
ms.date: 02/27/2022
5
+
ms.date: 02/28/2022
6
6
ms.custom: references_regions
7
7
---
8
8
@@ -145,7 +145,7 @@ For information about when recommendations are generated for each of these solut
145
145
| - [Microsoft Defender for Key Vault](./defender-for-key-vault-introduction.md)| GA | Not Available | Not Available |
146
146
| - [Microsoft Defender for Resource Manager](./defender-for-resource-manager-introduction.md)| GA | GA | GA |
147
147
| - [Microsoft Defender for Storage](./defender-for-storage-introduction.md) <sup>[6](#footnote6)</sup> | GA | GA | Not Available |
148
-
| - [Threat protection for Microsoft Defender for Azure Cosmos DB](./other-threat-protections.md#threat-protection-for-azure-cosmos-db-preview)| Public Preview | Not Available | Not Available |
148
+
| - [Microsoft Defender for Azure Cosmos DB](./other-threat-protections.md#threat-protection-for-azure-cosmos-db-preview)| Public Preview | Not Available | Not Available |
149
149
| - [Kubernetes workload protection](./kubernetes-workload-protections.md)| GA | GA | GA |
150
150
| - [Bi-directional alert synchronization with Sentinel](../sentinel/connect-azure-security-center.md)| Public Preview | Not Available | Not Available |
151
151
|**Microsoft Defender for servers features** <sup>[7](#footnote7)</sup> ||||
0 commit comments