Skip to content

Commit 2589a52

Browse files
authored
Merge pull request #265961 from ElazarK/WI198244-security-data
data aware security
2 parents 98e8b21 + d58b726 commit 2589a52

File tree

5 files changed

+35
-41
lines changed

5 files changed

+35
-41
lines changed

articles/defender-for-cloud/data-aware-security-dashboard-overview.md

Lines changed: 33 additions & 41 deletions
Original file line numberDiff line numberDiff line change
@@ -1,85 +1,77 @@
11
---
22
title: The data-aware security dashboard
3-
description: Learn about the capabilities and functions of the data-aware security view in Microsoft Defender for Cloud
3+
description: Learn about the capabilities and functions of the data-aware security view in Microsoft Defender for Cloud.
44
author: AlizaBernstein
55
ms.author: v-bernsteina
66
ms.topic: conceptual
7-
ms.date: 12/18/2023
7+
ms.date: 02/11/2024
88
---
99

10-
# Data security dashboard
10+
# Data security dashboard (Preview)
1111

12-
The data security dashboard addresses the need for an interactive, data-centric security dashboard that illuminates significant risks to customers' sensitive data. This tool effectively prioritizes alerts and potential attack paths for data across multicloud data resources, making data protection management less overwhelming and more effective.
12+
Microsoft Defender for Cloud's data security dashboard provides an interactive view of significant risks to sensitive data. It prioritizes alerts and potential attack paths across multicloud data resources, making data protection management more effective.
1313

14-
## Capabilities
14+
With the data security dashboard you can:
1515

16-
- You can view a centralized summary of your cloud data estate that identifies the location of sensitive data, so that you can discover the most critical data resources affected.
17-
- You can identify the data resources that are at risk and that require attention, so that you can prioritize actions that explore, prevent and respond to sensitive data breaches.
18-
- Investigate active high severity threats that lead to sensitive data
16+
- Easily locate and summarize sensitive data resources in your cloud data estate.
17+
- Identify and prioritize data resources at risk to prevent and respond to sensitive data breaches.
18+
- Investigate active high severity threats that lead to sensitive data.
1919
- Explore potential threats data by highlighting [attack paths](concept-attack-path.md) that lead to sensitive data.
2020
- Explore useful data insights by highlighting useful data queries in the [security explorer](how-to-manage-cloud-security-explorer.md).
2121

22-
You can select any element on the page to get more detailed information.
22+
To access the data security dashboard in Defender for Cloud, select **Data Security**.
2323

24-
| Aspect | Details |
25-
|---------|---------|
26-
|Release state: | Public Preview |
27-
| Prerequisites: | Defender for CSPM fully enabled, including sensitive data discovery <br/> Workload protection for database and storage to explore active risks |
28-
| Required roles and permissions: | No other roles needed on top of what is required for the security explorer. |
29-
| Clouds: | :::image type="icon" source="./media/icons/yes-icon.png"::: Commercial clouds <br/> :::image type="icon" source="./media/icons/no-icon.png"::: Azure Government <br/> :::image type="icon" source="./media/icons/no-icon.png"::: Azure China 21Vianet |
24+
:::image type="content" source="media/data-aware-security-dashboard/data-security.png" alt-text="Screenshot that shows you how to navigate to the data security dashboard." lightbox="media/data-aware-security-dashboard/data-security.png":::
3025

3126
## Prerequisites
3227

33-
In order to view the dashboard, you must enable Defender CSPM and also enable the sensitive data discovery extensions button underneath. In addition, to receive the alerts for data sensitivity, you must also enable the Defender for Storage plan.
28+
**To view the dashboard**:
3429

35-
:::image type="content" source="media/data-aware-security-dashboard/select-sensitive-data-discovery.png" alt-text="Screenshot that shows where to turn on the sensitive data discovery extension." lightbox="media/data-aware-security-dashboard/select-sensitive-data-discovery.png":::
30+
- You must [enable Defender CSPM](tutorial-enable-cspm-plan.md).
31+
- [Enable sensitive data discovery](tutorial-enable-cspm-plan.md#enable-the-components-of-the-defender-cspm-plan) within the Defender CSPM plan.
3632

37-
The feature is turned on at the subscription level.
33+
**To receive the alerts for data sensitivity**:
34+
- You must [enable Defender for Storage](tutorial-enable-storage-plan.md).
3835

3936
## Required permissions and roles
4037

41-
- To view the dashboard you must have either one of the following:
38+
**Permissions**:
4239

43-
- permissions:
40+
- Microsoft.Security/assessments/read
41+
- Microsoft.Security/assessments/subassessments/read
42+
- Microsoft.Security/alerts/read
4443

45-
- Microsoft.Security/assessments/read
46-
- Microsoft.Security/assessments/subassessments/read
47-
- Microsoft.Security/alerts/read
44+
**Role** - the minimum required privileged role-based access control role of **Security explorer**.
4845

49-
- the minimum required privileged RBAC role of **Security Reader**.
46+
- Register each relevant Azure subscription to the [Microsoft.Security resource provider](/azure/azure-resource-manager/management/resource-providers-and-types#register-resource-provider).
5047

51-
- Each Azure subscription must be registered for the **Microsoft.Security** resource provider:
52-
53-
1. Sign-in to the Azure portal.
54-
1. Select the affected subscription.
55-
1. In the left-side menu, select the resource provider.
56-
57-
:::image type="content" source="media/data-aware-security-dashboard/select-resource-provider.png" alt-text="Screenshot that shows where to select the resource provider." lightbox="media/data-aware-security-dashboard/select-resource-provider.png":::
58-
59-
1. Search for and select the **Microsoft.Security** resource provider from the list.
60-
1. Select **Register**.
61-
62-
Learn more about [how to register for Azure resource provider](/azure/azure-resource-manager/management/resource-providers-and-types#register-resource-provider).
48+
> [!NOTE]
49+
> The data security dashboard feature is turned on at the subscription level.
6350
6451
## Data security overview section
6552

6653
The data security overview section provides a general overview of your cloud data estate, per cloud, including all data resources, divided into storage assets, managed databases, and hosted databases (IaaS).
6754

6855
:::image type="content" source="media/data-aware-security-dashboard/data-security-overview.png" alt-text="Screenshot that shows the overview section of the data security view." lightbox="media/data-aware-security-dashboard/data-security-overview.png":::
6956

70-
**By coverage status** - displays the limited data coverage for resources without Defender CSPM workload protection:
57+
- **Coverage status** - displays the limited data coverage for resources without Defender CSPM workload protection:
58+
59+
- **Covered** – resources that have the necessary Defender CSPM, or Defender for Storage, or Defender for Databases enabled.
60+
- **Partially covered** – missing either the Defender CSPM, Defender for Storage, or Defender for Storage plan. Select the tooltip to present a detailed view of what is missing.
61+
- **Not covered** - resources that aren't covered by Defender CSPM, or Defender for Storage, or Defender for Databases.
7162

72-
- **Covered** – resources that have the necessary Defender CSPM, or Defender for Storage, or Defender for Databases enabled.
73-
- **Partially covered** – missing either the Defender CSPM, Defender for Storage, or Defender for Storage plan. Select the tooltip to present a detailed view of what is missing.
7463
- **Sensitive resources** – displays how many resources are sensitive.
75-
- **Sensitive resources requiring attention** - displays the number of sensitive resources that have either high severity security alerts or attack paths.
64+
65+
- **Sensitive resources requiring attention** - displays the number of sensitive resources that have either high severity security alerts or attack paths.
7666

7767
## Top issues
7868

7969
The **Top issues** section provides a highlighted view of top active and potential risks to sensitive data.
8070

8171
- **Sensitive data resources with high severity alerts** - summarizes the active threats to sensitive data resources and which data types are at risk.
72+
8273
- **Sensitive data resources in attack paths** - summarizes the potential threats to sensitive data resources by presenting attack paths leading to sensitive data resources and which data types are at potential risk.
74+
8375
- **Data queries in security explorer** - presents the top data-related queries in security explorer that helps focus on multicloud risks to sensitive data.
8476

8577
:::image type="content" source="media/data-aware-security-dashboard/top-issues.png" alt-text="Screenshot that shows the top issues section of the data security view." lightbox="media/data-aware-security-dashboard/top-issues.png":::
@@ -93,7 +85,7 @@ The **Closer look** section provides a more detailed view into the sensitive dat
9385

9486
:::image type="content" source="media/data-aware-security-dashboard/closer-look.png" alt-text="Screenshot that shows the closer look section of the data security dashboard." lightbox="media/data-aware-security-dashboard/closer-look.png":::
9587

96-
You can select the **Manage data sensitivity settings** to get to the **Data sensitivity** page. The **Data sensitivity** page allows you to manage the data sensitivity settings of cloud resources at the tenant level, based on selective info types and labels originating from the Purview compliance portal, and [customize sensitivity settings](data-sensitivity-settings.md) such as creating your own customized info types and labels, and setting sensitivity label thresholds.
88+
You can select the **Manage data sensitivity settings** to get to the **Data sensitivity** page. The **Data sensitivity** page allows you to manage the data sensitivity settings of cloud resources at the tenant level, based on selective info types and labels originating from the Purview compliance portal, and [customize sensitivity settings](data-sensitivity-settings.md) such as creating your own customized info types and labels, and setting sensitivity label thresholds.
9789

9890
:::image type="content" source="media/data-aware-security-dashboard/manage-security-sensitivity-settings.png" alt-text="Screenshot that shows where to access managing data sensitivity settings." lightbox="media/data-aware-security-dashboard/manage-security-sensitivity-settings.png":::
9991

216 KB
Loading
-4.41 KB
Loading

articles/defender-for-cloud/support-matrix-cloud-environment.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,8 @@ In the support table, **NA** indicates that the feature isn't available.
3131
|[Recommendation exemptions](exempt-resource.md) | Preview | NA | NA|
3232
|[Secure score](secure-score-security-controls.md) | GA | GA | GA|
3333
|[DevOps security posture](concept-devops-environment-posture-management-overview.md) | Preview | NA | NA|
34+
| **DEFENDER CSPM FEATURES** | | | |
35+
| [Data security dashboard](data-aware-security-dashboard-overview.md) | Preview | NA | NA |
3436
|**DEFENDER FOR CLOUD PLANS** | | ||
3537
|[Defender CSPM](concept-cloud-security-posture-management.md)| GA | NA | NA|
3638
|[Defender for APIs](defender-for-apis-introduction.md). | GA | NA | NA|

0 commit comments

Comments
 (0)