Skip to content

Commit 178f6b1

Browse files
author
David Curwin
committed
Improve Deploy section - Part 2
1 parent 2f8bbbd commit 178f6b1

8 files changed

+35
-8
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -550,7 +550,7 @@
550550
- name: How does Defender for Containers work?
551551
displayName: containers
552552
href: defender-for-containers-architecture.md
553-
- name: Enable Defender for Containers
553+
- name: How to enable Defender for Containers components
554554
displayName: kubernetes, aks, acr, registries, k8s, arc, hybrid, on-premises, azure arc, multicloud
555555
href: defender-for-containers-enable.md
556556
- name: Vulnerability assessment for Azure Container Registry

articles/defender-for-cloud/defender-for-containers-enable.md

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: How to enable Microsoft Defender for Containers in Microsoft Defender for Cloud
2+
title: How to enable Microsoft Defender for Containers components
33
description: Enable the container protections of Microsoft Defender for Containers
44
ms.topic: how-to
55
author: dcurwin
@@ -9,7 +9,7 @@ zone_pivot_groups: k8s-host
99
ms.date: 06/29/2023
1010
---
1111

12-
# Enable Microsoft Defender for Containers
12+
# How to enable Microsoft Defender for Containers components
1313

1414
Microsoft Defender for Containers is the cloud-native solution for securing your containers.
1515

@@ -25,7 +25,14 @@ Defender for Containers protects your clusters whether they're running in:
2525

2626
Learn about this plan in [Overview of Microsoft Defender for Containers](defender-for-containers-introduction.md).
2727

28-
You can learn more by watching these videos from the Defender for Cloud in the Field video series:
28+
You can first learn how to connect and protect your containers in these articles:
29+
30+
- [Protect your Azure containers with Defender for Containers](tutorial-enable-containers-azure.md)
31+
- [Protect your on-premises Kubernetes clusters with Defender for Containers](tutorial-enable-containers-arc.md)
32+
- [Protect your Amazon Web Service (AWS) accounts containers with Defender for Containers](tutorial-enable-container-aws.md)
33+
- [Protect your Google Cloud Platform (GCP) project containers with Defender for Containers](tutorial-enable-container-gcp.md)
34+
35+
You can also learn more by watching these videos from the Defender for Cloud in the Field video series:
2936

3037
- [Microsoft Defender for Containers in a multicloud environment](episode-nine.md)
3138
- [Protect Containers in GCP with Defender for Containers](episode-ten.md)

articles/defender-for-cloud/quickstart-onboard-aws.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,10 @@ To connect your AWS to Defender for Cloud by using a native connector:
114114

115115
Optionally, select **Management account** to create a connector to a management account. Connectors are created for each member account discovered under the provided management account. Auto-provisioning is enabled for all of the newly onboarded accounts.
116116

117+
## Select Defender plans
118+
119+
In this section of the wizard, you select the Defender for Cloud plans that you want to enable.
120+
117121
1. Select **Next: Select plans**.
118122

119123
The **Select plans** tab is where you choose which Defender for Cloud capabilities to enable for this AWS account. Each plan has its own [requirements for permissions](concept-aws-connector.md#native-connector-plan-requirements) and might incur [charges](https://azure.microsoft.com/pricing/details/defender-for-cloud/?v=17.23h).

articles/defender-for-cloud/quickstart-onboard-gcp.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,10 @@ To connect your GCP project to Defender for Cloud by using a native connector:
5353

5454
Optionally, if you select **Organization**, a management project and an organization custom role are created on your GCP project for the onboarding process. Auto-provisioning is enabled for the onboarding of new projects.
5555

56+
## Select Defender plans
57+
58+
In this section of the wizard, you select the Defender for Cloud plans that you want to enable.
59+
5660
1. Select **Next: Select plans**.
5761

5862
1. For the plans that you want to connect, turn the toggle to **On**. By default, all necessary prerequisites and components are provisioned. [Learn how to configure each plan](#optional-configure-selected-plans).

articles/defender-for-cloud/tutorial-enable-container-aws.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,9 +20,9 @@ You can learn more about Defender for Container's pricing on the [pricing page](
2020

2121
- You must [enable Microsoft Defender for Cloud](get-started.md#enable-defender-for-cloud-on-your-azure-subscription) on your Azure subscription.
2222

23-
- [Connect your AWS account to Microsoft Defender for Cloud](quickstart-onboard-aws.md)
23+
- [Connect your AWS account to Microsoft Defender for Cloud](quickstart-onboard-aws.md#connect-your-aws-account)
2424

25-
- Validate the following domains only if you're using a relevant OS. For example, if you have EKS clusters running in AWS, then you would only need to apply the `Amazon Linux 2 (Eks): Domain: "amazonlinux.*.amazonaws.com/2/extras/*"` domain.
25+
- Validate the following domains only if you're using a relevant OS.
2626

2727
| Domain | Port | Host operating systems |
2828
| -------------------------- | ---- |--|
@@ -63,6 +63,9 @@ To protect your EKS clusters, you need to enable the Containers plan on the rele
6363

6464
1. Select **Update**.
6565

66+
> [!NOTE]
67+
> To enable or disable individual Defender for Containers capabilities, either globally or for specific resources, see [How to enable Microsoft Defender for Containers components](defender-for-containers-enable.md).
68+
6669
## Deploy the Defender extension in Azure
6770

6871
Azure Arc-enabled Kubernetes, the Defender extension, and the Azure Policy extension should be installed and running on your EKS clusters. There's a dedicated Defender for Cloud recommendation that can be used to install these extensions (and Azure Arc if necessary):

articles/defender-for-cloud/tutorial-enable-container-gcp.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,9 +20,9 @@ You can learn more about Defender for Container's pricing on the [pricing page](
2020

2121
- You must [enable Microsoft Defender for Cloud](get-started.md#enable-defender-for-cloud-on-your-azure-subscription) on your Azure subscription.
2222

23-
- [Connect your GCP projects to Microsoft Defender for Cloud](quickstart-onboard-gcp.md).
23+
- [Connect your GCP projects to Microsoft Defender for Cloud](quickstart-onboard-gcp.md#connect-your-gcp-project).
2424

25-
- Validate the following domains only if you're using a relevant OS. For example, if you have EKS clusters running in AWS, then you would only need to apply the `Amazon Linux 2 (Eks): Domain: "amazonlinux.*.amazonaws.com/2/extras/*"` domain.
25+
- Validate the following domains only if you're using a relevant OS.
2626

2727
| Domain | Port | Host operating systems |
2828
| -------------------------- | ---- |--|
@@ -66,6 +66,9 @@ You can learn more about Defender for Container's pricing on the [pricing page](
6666

6767
1. Select **Update**.
6868

69+
> [!NOTE]
70+
> To enable or disable individual Defender for Containers capabilities, either globally or for specific resources, see [How to enable Microsoft Defender for Containers components](defender-for-containers-enable.md).
71+
6972
## Deploy the solution to specific clusters
7073

7174
If you disabled any of the default auto provisioning configurations to Off, during the [GCP connector onboarding process](quickstart-onboard-gcp.md#configure-the-defender-for-containers-plan), or afterwards. You need to manually install Azure Arc-enabled Kubernetes, the Defender extension, and the Azure Policy extensions to each of your GKE clusters to get the full security value out of Defender for Containers.

articles/defender-for-cloud/tutorial-enable-containers-arc.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,9 @@ If you would prefer to [assign a custom workspace](defender-for-containers-enabl
5454

5555
1. Select **Save**.
5656

57+
> [!NOTE]
58+
> To enable or disable individual Defender for Containers capabilities, either globally or for specific resources, see [How to enable Microsoft Defender for Containers components](defender-for-containers-enable.md).
59+
5760
## Deploy the Defender extension on Arc-enabled Kubernetes clusters that were onboarded to an Azure subscription
5861

5962
You can enable the Defender for Containers plan and deploy all of the relevant components in different ways. We walk you through the steps to accomplish this using the Azure portal. Learn how to [deploy the Defender extension](/azure/defender-for-cloud/defender-for-containers-enable?pivots=defender-for-container-arc&tabs=aks-deploy-portal%2Ck8s-deploy-asc%2Ck8s-verify-asc%2Ck8s-remove-arc%2Caks-removeprofile-api#deploy-the-defender-extension) with REST API, Azure CLI or with a Resource Manager template.

articles/defender-for-cloud/tutorial-enable-containers-azure.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,9 @@ If you would prefer to [assign a custom workspace](/azure/defender-for-cloud/def
4747

4848
1. Select **Save**.
4949

50+
> [!NOTE]
51+
> To enable or disable individual Defender for Containers capabilities, either globally or for specific resources, see [How to enable Microsoft Defender for Containers components](defender-for-containers-enable.md).
52+
5053
## Deploy the Defender profile in Azure
5154

5255
You can enable the Defender for Containers plan and deploy all of the relevant components in different ways. We walk you through the steps to accomplish this using the Azure portal. Learn how to [deploy the Defender profile](defender-for-containers-enable.md#deploy-the-defender-profile) with REST API, Azure CLI or with a Resource Manager template.

0 commit comments

Comments
 (0)