You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/concept-gcp-connector.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -26,7 +26,7 @@ When you onboard to Defender for Cloud, the GCloud template is used to create th
26
26
27
27
The authentication process works as follows:
28
28
29
-
:::image type="content" source="media/concept-gcp-connector/authentication-process.png" alt-text="A diagram of the Defender for Cloud GCP connector authentication process.":::
29
+
:::image type="content" source="media/concept-gcp-connector/authentication-process.png" alt-text="A diagram of the Defender for Cloud GCP connector authentication process." lightbox="media/concept-gcp-connector/authentication-process.png":::
30
30
31
31
(1) - Microsoft Defender for Cloud's CSPM service acquires an Azure AD token. The token is signed by Azure AD using the RS256 algorithm and is valid for 1 hour.
32
32
@@ -44,7 +44,7 @@ There are four parts to the onboarding process that take place when you create t
44
44
45
45
In the first section, you'll need to add the basic properties of the connection between your GCP project and Defender for Cloud.
46
46
47
-
:::image type="content" source="media/concept-gcp-connector/single-project-details.png" alt-text="Screenshot of the organization details page of the GCP project onboarding process.":::
47
+
:::image type="content" source="media/concept-gcp-connector/single-project-details.png" alt-text="Screenshot of the organization details page of the GCP project onboarding process." lightbox="media/concept-gcp-connector/single-project-details.png":::
48
48
49
49
Here you'll name your connector, select a subscription and resource group, which will be used to create an ARM template resource that is called security connector. The security connector represents a configuration resource that holds the projects settings.
50
50
@@ -54,15 +54,15 @@ You'll also select a location and add the organization ID for your project.
54
54
55
55
After entering your organization's details, you'll then be able to select which plans to enable.
56
56
57
-
:::image type="content" source="media/concept-gcp-connector/select-plans-gcp-project.png" alt-text="Screenshot of the available plans you can enable for your GCP project.":::
57
+
:::image type="content" source="media/concept-gcp-connector/select-plans-gcp-project.png" alt-text="Screenshot of the available plans you can enable for your GCP project." lightbox="media/concept-gcp-connector/select-plans-gcp-project.png":::
58
58
59
59
From here, you can decide which resources you want to protect based on the security value you want to receive.
60
60
61
61
### Configure access
62
62
63
63
Once you've selected the plans, you want to enable and the resources you want to protect you'll then have to configure access between Defender for Cloud and your GCP project.
64
64
65
-
:::image type="content" source="media/concept-gcp-connector/configure-access-gcp-connector.png" alt-text="Screenshot of the configure access screen between Defender for Cloud and your GCP project.":::
65
+
:::image type="content" source="media/concept-gcp-connector/configure-access-gcp-connector.png" alt-text="Screenshot of the configure access screen between Defender for Cloud and your GCP project." lightbox="media/concept-gcp-connector/configure-access-gcp-connector.png":::
66
66
67
67
In this step, you'll find the GCloud script that needs to be run on the GCP project that is going to onboarded. The GCloud script is generated based on the plans you selected to onboard.
68
68
@@ -77,7 +77,7 @@ The GCloud script creates all of the required resources on your GCP environment
77
77
78
78
The final step for onboarding is to review all of your selections and to create the connector.
79
79
80
-
:::image type="content" source="media/concept-gcp-connector/review-and-generate.png" alt-text="Screenshot of the review and generate screen with all of your selections listed.":::
80
+
:::image type="content" source="media/concept-gcp-connector/review-and-generate.png" alt-text="Screenshot of the review and generate screen with all of your selections listed." lightbox="media/concept-gcp-connector/review-and-generate.png":::
81
81
82
82
## What happens when you onboard an organization
83
83
@@ -87,7 +87,7 @@ Similar to onboarding a single project, When onboarding a GCP organization, Defe
87
87
88
88
In the first section, you'll need to add the basic properties of the connection between your GCP organization and Defender for Cloud.
89
89
90
-
:::image type="content" source="media/concept-gcp-connector/organization-details.png" alt-text="Screenshot of the organization details page of the GCP project onboarding process.":::
90
+
:::image type="content" source="media/concept-gcp-connector/organization-details.png" alt-text="Screenshot of the organization details page of the GCP project onboarding process." lightbox="media/concept-gcp-connector/organization-details.png":::
91
91
92
92
Here you'll name your connector, select a subscription and resource group that will be used to create an ARM template resource that is called security connector. The security connector represents a configuration resource that holds the projects settings.
93
93
@@ -99,15 +99,15 @@ When you onboard an organization, you can also choose to exclude project numbers
99
99
100
100
After entering your organization's details, you'll then be able to select which plans to enable.
101
101
102
-
:::image type="content" source="media/concept-gcp-connector/select-plans-gcp-project.png" alt-text="Screenshot of the available plans you can enable for your GCP project.":::
102
+
:::image type="content" source="media/concept-gcp-connector/select-plans-gcp-project.png" alt-text="Screenshot of the available plans you can enable for your GCP project." lightbox="media/concept-gcp-connector/select-plans-gcp-project.png":::
103
103
104
104
From here, you can decide which resources you want to protect based on the security value you want to receive.
105
105
106
106
### Configure access
107
107
108
108
Once you've selected the plans, you want to enable and the resources you want to protect you'll then have to configure access between Defender for Cloud and your GCP project.
109
109
110
-
:::image type="content" source="media/concept-gcp-connector/configure-access-organization.png" alt-text="Screenshot of the configure access screen between Defender for Cloud and your GCP project.":::
110
+
:::image type="content" source="media/concept-gcp-connector/configure-access-organization.png" alt-text="Screenshot of the configure access screen between Defender for Cloud and your GCP project." lightbox="media/concept-gcp-connector/configure-access-organization.png":::
111
111
112
112
When you onboard an organization, there's a section to include management project details. Similar to other GCP projects, the organization is also considered a project and will be utilized by Defender for Cloud to create all of the required resources needed to connect the organization to Defender for Cloud.
113
113
@@ -134,7 +134,7 @@ Some of the APIs won't be in direct use with the management project. Instead the
134
134
135
135
The final step for onboarding is to review all of your selections and to create the connector.
136
136
137
-
:::image type="content" source="media/concept-gcp-connector/review-and-generate.png" alt-text="Screenshot of the review and generate screen with all of your selections listed.":::
137
+
:::image type="content" source="media/concept-gcp-connector/review-and-generate-organization.png" alt-text="Screenshot of the review and generate screen with all of your selections listed." lightbox="media/concept-gcp-connector/review-and-generate-organization.png":::
0 commit comments