You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/data-aware-security-dashboard-overview.md
+33-41Lines changed: 33 additions & 41 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,85 +1,77 @@
1
1
---
2
2
title: The data-aware security dashboard
3
-
description: Learn about the capabilities and functions of the data-aware security view in Microsoft Defender for Cloud
3
+
description: Learn about the capabilities and functions of the data-aware security view in Microsoft Defender for Cloud.
4
4
author: AlizaBernstein
5
5
ms.author: v-bernsteina
6
6
ms.topic: conceptual
7
-
ms.date: 12/18/2023
7
+
ms.date: 02/11/2024
8
8
---
9
9
10
-
# Data security dashboard
10
+
# Data security dashboard (Preview)
11
11
12
-
The data security dashboard addresses the need for an interactive, data-centric security dashboard that illuminates significant risks to customers' sensitive data. This tool effectively prioritizes alerts and potential attack paths for data across multicloud data resources, making data protection management less overwhelming and more effective.
12
+
Microsoft Defender for Cloud's data security dashboard provides an interactive view of significant risks to sensitive data. It prioritizes alerts and potential attack paths across multicloud data resources, making data protection management more effective.
13
13
14
-
## Capabilities
14
+
With the data security dashboard you can:
15
15
16
-
-You can view a centralized summary of your cloud data estate that identifies the location of sensitive data, so that you can discover the most critical data resources affected.
17
-
-You can identify the data resources that are at risk and that require attention, so that you can prioritize actions that explore, prevent and respond to sensitive data breaches.
18
-
- Investigate active high severity threats that lead to sensitive data
16
+
-Easily locate and summarize sensitive data resources in your cloud data estate.
17
+
-Identify and prioritize data resources at risk to prevent and respond to sensitive data breaches.
18
+
- Investigate active high severity threats that lead to sensitive data.
19
19
- Explore potential threats data by highlighting [attack paths](concept-attack-path.md) that lead to sensitive data.
20
20
- Explore useful data insights by highlighting useful data queries in the [security explorer](how-to-manage-cloud-security-explorer.md).
21
21
22
-
You can select any element on the page to get more detailed information.
22
+
To access the data security dashboard in Defender for Cloud, select **Data Security**.
23
23
24
-
| Aspect | Details |
25
-
|---------|---------|
26
-
|Release state: | Public Preview |
27
-
| Prerequisites: | Defender for CSPM fully enabled, including sensitive data discovery <br/> Workload protection for database and storage to explore active risks |
28
-
| Required roles and permissions: | No other roles needed on top of what is required for the security explorer. |
:::image type="content" source="media/data-aware-security-dashboard/data-security.png" alt-text="Screenshot that shows you how to navigate to the data security dashboard." lightbox="media/data-aware-security-dashboard/data-security.png":::
30
25
31
26
## Prerequisites
32
27
33
-
In order to view the dashboard, you must enable Defender CSPM and also enable the sensitive data discovery extensions button underneath. In addition, to receive the alerts for data sensitivity, you must also enable the Defender for Storage plan.
28
+
**To view the dashboard**:
34
29
35
-
:::image type="content" source="media/data-aware-security-dashboard/select-sensitive-data-discovery.png" alt-text="Screenshot that shows where to turn on the sensitive data discovery extension." lightbox="media/data-aware-security-dashboard/select-sensitive-data-discovery.png":::
30
+
- You must [enable Defender CSPM](tutorial-enable-cspm-plan.md).
31
+
-[Enable sensitive data discovery](tutorial-enable-cspm-plan.md#enable-the-components-of-the-defender-cspm-plan) within the Defender CSPM plan.
36
32
37
-
The feature is turned on at the subscription level.
33
+
**To receive the alerts for data sensitivity**:
34
+
- You must [enable Defender for Storage](tutorial-enable-storage-plan.md).
38
35
39
36
## Required permissions and roles
40
37
41
-
- To view the dashboard you must have either one of the following:
**Role** - the minimum required privileged role-based access control role of **Security explorer**.
48
45
49
-
- the minimum required privileged RBAC role of **Security Reader**.
46
+
- Register each relevant Azure subscription to the [Microsoft.Security resource provider](/azure/azure-resource-manager/management/resource-providers-and-types#register-resource-provider).
50
47
51
-
- Each Azure subscription must be registered for the **Microsoft.Security** resource provider:
52
-
53
-
1. Sign-in to the Azure portal.
54
-
1. Select the affected subscription.
55
-
1. In the left-side menu, select the resource provider.
56
-
57
-
:::image type="content" source="media/data-aware-security-dashboard/select-resource-provider.png" alt-text="Screenshot that shows where to select the resource provider." lightbox="media/data-aware-security-dashboard/select-resource-provider.png":::
58
-
59
-
1. Search for and select the **Microsoft.Security** resource provider from the list.
60
-
1. Select **Register**.
61
-
62
-
Learn more about [how to register for Azure resource provider](/azure/azure-resource-manager/management/resource-providers-and-types#register-resource-provider).
48
+
> [!NOTE]
49
+
> The data security dashboard feature is turned on at the subscription level.
63
50
64
51
## Data security overview section
65
52
66
53
The data security overview section provides a general overview of your cloud data estate, per cloud, including all data resources, divided into storage assets, managed databases, and hosted databases (IaaS).
67
54
68
55
:::image type="content" source="media/data-aware-security-dashboard/data-security-overview.png" alt-text="Screenshot that shows the overview section of the data security view." lightbox="media/data-aware-security-dashboard/data-security-overview.png":::
69
56
70
-
**By coverage status** - displays the limited data coverage for resources without Defender CSPM workload protection:
57
+
-**Coverage status** - displays the limited data coverage for resources without Defender CSPM workload protection:
58
+
59
+
-**Covered** – resources that have the necessary Defender CSPM, or Defender for Storage, or Defender for Databases enabled.
60
+
-**Partially covered** – missing either the Defender CSPM, Defender for Storage, or Defender for Storage plan. Select the tooltip to present a detailed view of what is missing.
61
+
-**Not covered** - resources that aren't covered by Defender CSPM, or Defender for Storage, or Defender for Databases.
71
62
72
-
-**Covered** – resources that have the necessary Defender CSPM, or Defender for Storage, or Defender for Databases enabled.
73
-
-**Partially covered** – missing either the Defender CSPM, Defender for Storage, or Defender for Storage plan. Select the tooltip to present a detailed view of what is missing.
74
63
-**Sensitive resources** – displays how many resources are sensitive.
75
-
-**Sensitive resources requiring attention** - displays the number of sensitive resources that have either high severity security alerts or attack paths.
64
+
65
+
-**Sensitive resources requiring attention** - displays the number of sensitive resources that have either high severity security alerts or attack paths.
76
66
77
67
## Top issues
78
68
79
69
The **Top issues** section provides a highlighted view of top active and potential risks to sensitive data.
80
70
81
71
-**Sensitive data resources with high severity alerts** - summarizes the active threats to sensitive data resources and which data types are at risk.
72
+
82
73
-**Sensitive data resources in attack paths** - summarizes the potential threats to sensitive data resources by presenting attack paths leading to sensitive data resources and which data types are at potential risk.
74
+
83
75
-**Data queries in security explorer** - presents the top data-related queries in security explorer that helps focus on multicloud risks to sensitive data.
84
76
85
77
:::image type="content" source="media/data-aware-security-dashboard/top-issues.png" alt-text="Screenshot that shows the top issues section of the data security view." lightbox="media/data-aware-security-dashboard/top-issues.png":::
@@ -93,7 +85,7 @@ The **Closer look** section provides a more detailed view into the sensitive dat
93
85
94
86
:::image type="content" source="media/data-aware-security-dashboard/closer-look.png" alt-text="Screenshot that shows the closer look section of the data security dashboard." lightbox="media/data-aware-security-dashboard/closer-look.png":::
95
87
96
-
You can select the **Manage data sensitivity settings** to get to the **Data sensitivity** page. The **Data sensitivity** page allows you to manage the data sensitivity settings of cloud resources at the tenant level, based on selective info types and labels originating from the Purview compliance portal, and [customize sensitivity settings](data-sensitivity-settings.md) such as creating your own customized info types and labels, and setting sensitivity label thresholds.
88
+
You can select the **Manage data sensitivity settings** to get to the **Data sensitivity** page. The **Data sensitivity** page allows you to manage the data sensitivity settings of cloud resources at the tenant level, based on selective info types and labels originating from the Purview compliance portal, and [customize sensitivity settings](data-sensitivity-settings.md) such as creating your own customized info types and labels, and setting sensitivity label thresholds.
97
89
98
90
:::image type="content" source="media/data-aware-security-dashboard/manage-security-sensitivity-settings.png" alt-text="Screenshot that shows where to access managing data sensitivity settings." lightbox="media/data-aware-security-dashboard/manage-security-sensitivity-settings.png":::
0 commit comments