Skip to content

Commit 0899675

Browse files
committed
Updated identity and access page
1 parent 24db255 commit 0899675

File tree

2 files changed

+21
-53
lines changed

2 files changed

+21
-53
lines changed
11.7 KB
Loading

articles/security-center/security-center-identity-access.md

Lines changed: 21 additions & 53 deletions
Original file line numberDiff line numberDiff line change
@@ -11,82 +11,50 @@ ms.devlang: na
1111
ms.topic: conceptual
1212
ms.tgt_pltfrm: na
1313
ms.workload: na
14-
ms.date: 12/19/2019
14+
ms.date: 03/06/2020
1515
ms.author: memildin
1616
---
17+
1718
# Monitor identity and access
18-
When Security Center identifies potential security vulnerabilities, it creates recommendations that guide you through the process of configuring the needed controls to harden and protect your resources.
1919

20-
This article explains the **Identity and Access** page of the resource security section of Azure Security Center.
20+
> [!TIP]
21+
> From March 2020, Azure Security Center's identity and access recommendations are included in all subscriptions on the free pricing tier. If you have subscriptions on the free tier, their Secure Score will be affected as they were not previously assessed for their identity and access security.
2122
22-
For a full list of the recommendations you might see on this page, see [Identity and Access recommendations](recommendations-reference.md#recs-identity).
23+
When Security Center identifies potential security vulnerabilities, it creates recommendations that guide you through the process of configuring the needed controls to harden and protect your resources.
2324

24-
Identity should be the control plane for your enterprise, and protecting identities should be your top priority. The security perimeter has evolved from a network perimeter to an identity perimeter. Security becomes less about defending your network and more about defending your data, as well as managing the security of your apps and users. Nowadays, with more data and more apps moving to the cloud, identity becomes the new perimeter.
25+
The security perimeter has evolved from a network perimeter to an identity perimeter. Security becomes less about defending your network and more about defending your data, as well as managing the security of your apps and users. Nowadays, with more data and more apps moving to the cloud, identity becomes the new perimeter.
2526

26-
By monitoring identity activities, you can take proactive actions before an incident takes place or reactive actions to stop an attack attempt. The Identity & Access dashboard provides you with recommendations such as:
27+
By monitoring identity activities, you can take proactive actions before an incident takes place or reactive actions to stop an attack attempt. Examples of recommendations you might see on the **Identity and access** resource security section of Azure Security Center include:
2728

28-
- Enable MFA for privileged accounts on your subscription
29-
- Remove external accounts with write permissions from your subscription
30-
- Remove privileged external accounts from your subscription
29+
- MFA should be enabled on accounts with owner permissions on your subscription
30+
- A maximum of 3 owners should be designated for your subscription
31+
- Deprecated accounts should be removed from your subscription
32+
- External accounts with read permissions should be removed from your subscription
33+
34+
For a full list of the recommendations you might see here, see [Identity and Access recommendations](recommendations-reference.md#recs-identity).
3135

3236
> [!NOTE]
3337
> If your subscription has more than 600 accounts, Security Center is unable to run the Identity recommendations against your subscription. Recommendations that are not run are listed under "unavailable assessments" below.
3438
Security Center is unable to run the Identity recommendations against a Cloud Solution Provider (CSP) partner's admin agents.
3539
>
3640
37-
## Monitor identity and access
38-
39-
Open the list of identified Identity and Access issues by selecting **Identity & access** from the Security Center sidebar (under **Resources**), or from the overview page.
40-
41-
Under **Identity & Access**, there are two tabs:
42-
43-
- **Overview**: recommendations identified by Security Center.
44-
- **Subscriptions**: list of your subscriptions and current security state of each.
45-
46-
[![Identity & Access](./media/security-center-identity-access/identity-dashboard.png)](./media/security-center-identity-access/identity-dashboard.png#lightbox)
47-
48-
### Overview section
49-
Under **Overview**, there is a list of recommendations. The first column lists the recommendation. The second column shows the total number of subscriptions that are affected by that recommendation. The third column shows the severity of the issue.
5041

51-
1. Select a recommendation. The recommendations window opens and displays:
42+
All of the identity and access recommendations are available within two security controls in the **Recommendations** page:
5243

53-
- Description of the recommendation
54-
- List of unhealthy and healthy subscriptions
55-
- List of resources that are unscanned due to a failed assessment or the resource is under a subscription running on the Free tier and is not assessed
44+
- Manage access and permissions
45+
- Enable MFA
5646

57-
[![Recommendations window](./media/security-center-identity-access/select-subscription.png)](./media/security-center-identity-access/select-subscription.png#lightbox)
47+
![The two security controls with the recommendations related to identity and access](media/security-center-identity-access/two-security-controls-for-identity-and-access.png)
5848

59-
1. Select a subscription in the list for additional detail.
6049

61-
### Subscriptions section
62-
Under **Subscriptions**, there is a list of subscriptions. The first column lists the subscriptions. The second column shows the total number of recommendations for each subscription. The third column shows the severities of the issues.
50+
## Enable multi-factor authentication (MFA)
6351

64-
[![Subscriptions tab](./media/security-center-identity-access/subscriptions.png)](./media/security-center-identity-access/subscriptions.png#lightbox)
52+
Enabling MFA requires [Azure Active Directory (AD) tenant permissions](https://docs.microsoft.com/azure/active-directory/users-groups-roles/directory-assign-admin-roles).
6553

66-
1. Select a subscription. A summary view opens with three tabs:
54+
- If you have a premium edition of AD, enable MFA using using [conditional access](https://docs.microsoft.com/azure/active-directory/conditional-access/overview).
6755

68-
- **Recommendations**: based on assessments performed by Security Center that failed.
69-
- **Passed assessments**: list of assessments performed by Security Center that passed.
70-
- **Unavailable assessments**: list of assessments that failed to run due to an error or because the subscription has more than 600 accounts.
56+
- Users of AD free edition can enable **security defaults** in Azure Active Directory as described in the [AD documentation](https://docs.microsoft.com/azure/active-directory/fundamentals/concept-fundamentals-security-defaults) but the Security Center recommendation to enable MFA will still appear.
7157

72-
Under **Recommendations** is a list of the recommendations for the selected subscription and severity of each recommendation.
73-
74-
[![Recommendations for select subscription](./media/security-center-identity-access/recommendations.png)](./media/security-center-identity-access/recommendations.png#lightbox)
75-
76-
1. Select a recommendation for a description of the recommendation, a list of unhealthy and healthy subscriptions, and a list of unscanned resources.
77-
78-
[![Description of recommendation](./media/security-center-identity-access/designate.png)](./media/security-center-identity-access/designate.png#lightbox)
79-
80-
Under **Passed assessments** is a list of passed assessments. Severity of these assessments is always green.
81-
82-
[![Passed assessments](./media/security-center-identity-access/passed-assessments.png)](./media/security-center-identity-access/passed-assessments.png#lightbox)
83-
84-
1. Select a passed assessment from the list for a description of the assessment and a list of healthy subscriptions. There is a tab for unhealthy subscriptions that lists all the subscriptions that failed.
85-
86-
[![Passed assessments](./media/security-center-identity-access/remove.png)](./media/security-center-identity-access/remove.png#lightbox)
87-
88-
> [!NOTE]
89-
> If you created a Conditional Access policy that necessitates MFA but has exclusions set, the Security Center MFA recommendation assessment considers the policy non-compliant, because it enables some users to sign in to Azure without MFA.
9058

9159
## Next steps
9260
To learn more about recommendations that apply to other Azure resource types, see the following articles:

0 commit comments

Comments
 (0)