You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/enable-permissions-management.md
+16-14Lines changed: 16 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,14 +1,14 @@
1
1
---
2
-
title: Enable Permissions Management
2
+
title: Enable permissions management
3
3
author: Elazark
4
4
ms.author: elkrieger
5
-
description: Learn how to enable Permissions Management for better access control and security in your cloud infrastructure.
5
+
description: Learn how to enable permissions management for better access control and security in your cloud infrastructure.
6
6
ms.topic: how-to
7
7
ms.date: 03/10/2024
8
-
#customer intent: As a cloud administrator, I want to learn how to enable Permissions Management in order to effectively manage user access and entitlements in my cloud infrastructure.
8
+
#customer intent: As a cloud administrator, I want to learn how to enable permissions management in order to effectively manage user access and entitlements in my cloud infrastructure.
9
9
---
10
10
11
-
# Enable Permissions Management
11
+
# Enable permissions management
12
12
13
13
Microsoft Defender for Cloud's integration with Microsoft Entra Permissions Management provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
14
14
@@ -24,9 +24,10 @@ Microsoft Defender for Cloud's integration with Microsoft Entra Permissions Mana
24
24
25
25
-**GCP only**: [Connect your GCP project to Defender for Cloud](quickstart-onboard-gcp.md).
26
26
27
-
## Enable Permissions Management for Azure
27
+
## Enable permissions management for Azure
28
28
29
-
When you enabled the Defender CSPM plan on your Azure account, the **Azure CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The Azure CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
29
+
When you enabled the Defender CSPM plan on your Azure account, the **Azure CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The Azure CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
30
+
30
31
When Permission Management is disabled, the CIEM recommendations within the Azure CSPM standard won’t be calculated.
31
32
32
33
1. Sign in to the [Azure portal](https://portal.azure.com).
@@ -41,15 +42,15 @@ When Permission Management is disabled, the CIEM recommendations within the Azur
41
42
42
43
1. Enable **Permissions Management**.
43
44
44
-
:::image type="content" source="media/enable-permissions-management/permissions-management-on.png" alt-text="Screenshot that shows you where the toggle is for the permissions management is located and that it is turned to on." lightbox="media/enable-permissions-management/permissions-management-on.png":::
45
+
:::image type="content" source="media/enable-permissions-management/permissions-management-on.png" alt-text="Screenshot that shows you where the toggle is for the permissions management is located." lightbox="media/enable-permissions-management/permissions-management-on.png":::
45
46
46
47
1. Select **Continue**.
47
48
48
49
1. Select **Save**.
49
50
50
-
The applicable Permissions Management recommendations appear on your subscription within a few hours.
51
+
The applicable permissions management recommendations appear on your subscription within a few hours.
51
52
52
-
## Enable Permissions Management for AWS
53
+
## Enable permissions management for AWS
53
54
54
55
When you enabled the Defender CSPM plan on your AWS account, the **AWS CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The AWS CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
55
56
When Permission Management is disabled, the CIEM recommendations within the AWS CSPM standard won’t be calculated.
@@ -84,14 +85,15 @@ When Permission Management is disabled, the CIEM recommendations within the AWS
84
85
85
86
1. Select **Update**.
86
87
87
-
The applicable Permissions Management recommendations appear on your subscription within a few hours.
88
+
The applicable permissions management recommendations appear on your subscription within a few hours.
88
89
89
-
## Enable Permissions Management for GCP
90
+
## Enable permissions management for GCP
90
91
91
92
When you enabled the Defender CSPM plan on your GCP project, the **GCP CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The GCP CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
93
+
92
94
When Permission Management is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated.
93
95
94
-
**To enable Permissions Management for GCP**:
96
+
**To enable permissions management for GCP**:
95
97
96
98
1. Sign in to the [Azure portal](https://portal.azure.com).
97
99
@@ -105,7 +107,7 @@ When Permission Management is disabled, the CIEM recommendations within the GCP
105
107
106
108
:::image type="content" source="media/enable-permissions-management/settings-google.png" alt-text="Screenshot that shows where to select settings for the Defender CSPM plan for your GCP project." lightbox="media/enable-permissions-management/settings-google.png":::
107
109
108
-
1. Toggle Permissions Management to **On**.
110
+
1. Toggle permissions management to **On**.
109
111
110
112
1. Select **Save**.
111
113
@@ -125,7 +127,7 @@ When Permission Management is disabled, the CIEM recommendations within the GCP
125
127
126
128
1. Select **Update**.
127
129
128
-
The applicable Permissions Management recommendations appear on your subscription within a few hours.
130
+
The applicable permissions management recommendations appear on your subscription within a few hours.
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/permissions-management.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,18 +1,18 @@
1
1
---
2
-
title: Permissions Management
3
-
description: Learn about Permissions Management in Microsoft Defender for Cloud and enhance the security of your cloud infrastructure.
2
+
title: Permissions management
3
+
description: Learn about permissions management in Microsoft Defender for Cloud and enhance the security of your cloud infrastructure.
4
4
ms.topic: concept-article
5
5
author: Elazark
6
6
ms.author: elkrieger
7
7
ms.date: 03/07/2024
8
8
#customer intent: As a user, I want to understand how to manage permissions effectively so that I can enhance the security of my cloud infrastructure.
9
9
---
10
10
11
-
# Permissions Management
11
+
# Permissions management
12
12
13
13
Microsoft Defender for Cloud's integration with Microsoft [Microsoft Entra Permissions Management (CIEM)](/entra/permissions-management/overview) provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
14
14
15
-
Integrating Entra Permissions Management (CIEM) with Defender for Cloud (CNAPP) strengthens cloud security by preventing security breaches caused by excessive permissions or misconfigurations. Permissions Management continuously monitors and manages cloud entitlements, helping to discover attack surfaces, detect threats, right-size access permissions, and maintain compliance. This integration enhances the capabilities of Defender for Cloud in securing cloud-native applications and protecting sensitive data.
15
+
Integrating Entra Permissions Management (CIEM) with Defender for Cloud (CNAPP) strengthens cloud security by preventing security breaches caused by excessive permissions or misconfigurations. Permissions management continuously monitors and manages cloud entitlements, helping to discover attack surfaces, detect threats, right-size access permissions, and maintain compliance. This integration enhances the capabilities of Defender for Cloud in securing cloud-native applications and protecting sensitive data.
16
16
17
17
This integration brings the following insights derived from the Microsoft Entra Permissions Management suite into the Microsoft Defender for Cloud portal. For more information, see the [feature matrix](#feature-matrix).
18
18
@@ -30,7 +30,7 @@ AWS and GCP accounts that were onboarded to Microsoft Entra Permissions Manageme
30
30
31
31
The integration feature comes as part of Defender CSPM plan and doesn't require a Microsoft Entra Permissions Management (MEPM) license. To learn more about other capabilities that you can receive from MEPM, refer to the feature matrix:
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/release-notes.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -24,14 +24,14 @@ If you're looking for items older than six months, you can find them in the [Arc
24
24
25
25
|Date | Update |
26
26
|--|--|
27
-
| May 7 |[General availability of Permissions Management in Defender for Cloud](#general-availability-of-permissions-management-in-defender-for-cloud)|
27
+
| May 7 |[General availability of permissions management in Defender for Cloud](#general-availability-of-permissions-management-in-defender-for-cloud)|
28
28
| May 1 |[Defender for open-source databases is now available on AWS for Amazon instances (Preview)](#defender-for-open-source-databases-is-now-available-on-aws-for-amazon-instances-preview)|
29
29
30
-
### General availability of Permissions Management in Defender for Cloud
30
+
### General availability of permissions management in Defender for Cloud
31
31
32
32
May 7, 2024
33
33
34
-
We're announcing the general availability (GA) of [Permissions Management](permissions-management.md) in Defender for Cloud.
34
+
We're announcing the general availability (GA) of [permissions management](permissions-management.md) in Defender for Cloud.
35
35
36
36
### Defender for open-source databases is now available on AWS for Amazon instances (Preview)
37
37
@@ -673,13 +673,13 @@ Learn how to [manage secrets with agentless secrets scanning](secret-scanning.md
673
673
674
674
November 22, 2023
675
675
676
-
Microsoft now offers both Cloud-Native Application Protection Platforms (CNAPP) and Cloud Infrastructure Entitlement Management (CIEM) solutions with [Microsoft Defender for Cloud (CNAPP)](defender-for-cloud-introduction.md) and [Microsoft Entra Permissions Management](/entra/permissions-management/) (CIEM).
676
+
Microsoft now offers both Cloud-Native Application Protection Platforms (CNAPP) and Cloud Infrastructure Entitlement Management (CIEM) solutions with [Microsoft Defender for Cloud (CNAPP)](defender-for-cloud-introduction.md) and [Microsoft Entra permissions management](/entra/permissions-management/) (CIEM).
677
677
678
678
Security administrators can get a centralized view of their unused or excessive access permissions within Defender for Cloud.
679
679
680
680
Security teams can drive the least privilege access controls for cloud resources and receive actionable recommendations for resolving permissions risks across Azure, AWS, and GCP cloud environments as part of their Defender Cloud Security Posture Management (CSPM), without any extra licensing requirements.
681
681
682
-
Learn how to [Enable Permissions Management in Microsoft Defender for Cloud (Preview)](enable-permissions-management.md).
682
+
Learn how to [Enable permissions management in Microsoft Defender for Cloud (Preview)](enable-permissions-management.md).
683
683
684
684
### Defender for Cloud integration with ServiceNow
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/tutorial-enable-cspm-plan.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -64,7 +64,7 @@ Once the Defender CSPM plan is enabled on your subscription, you have the abilit
64
64
65
65
-**Sensitive data discovery**: Sensitive data discovery automatically discovers managed cloud data resources containing sensitive data at scale. This feature accesses your data, it is agentless, uses smart sampling scanning, and integrates with Microsoft Purview sensitive information types and labels.
66
66
67
-
-**Permissions Management** - Insights into Cloud Infrastructure Entitlement Management (CIEM). CIEM ensures appropriate and secure identities and access rights in cloud environments. It helps understand access permissions to cloud resources and associated risks. Setup and data collection may take up to 24 hours.
67
+
-**Permissions management** - Insights into Cloud Infrastructure Entitlement Management (CIEM). CIEM ensures appropriate and secure identities and access rights in cloud environments. It helps understand access permissions to cloud resources and associated risks. Setup and data collection may take up to 24 hours.
68
68
69
69
**To enable the components of the Defender CSPM plan**:
0 commit comments