You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/tutorial-enable-storage-plan.md
+8-8Lines changed: 8 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ ms.date: 08/21/2023
7
7
8
8
# Deploy Microsoft Defender for Storage
9
9
10
-
Microsoft Defender for Storage is an Azure-native solution offering an advanced layer of intelligence for threat detection and mitigation in storage accounts, powered by [Microsoft Threat Intelligence](https://go.microsoft.com/fwlink/?linkid=2128684), Microsoft Defender Antimalware technologies, and Sensitive Data Discovery. With protection for Azure Blob Storage, Azure Files, and Azure Data Lake Storage services, it provides a comprehensive alert suite, near real-time Malware Scanning (add-on), and sensitive data threat detection (no extra cost), allowing quick detection, triage, and response to potential security threats with contextual information. It helps prevent the three major impacts on your data and workload: malicious file uploads, sensitive data exfiltration, and data corruption.
10
+
Microsoft Defender for Storage is an Azure-native solution offering an advanced layer of intelligence for threat detection and mitigation in storage accounts, powered by [Microsoft Threat Intelligence](https://go.microsoft.com/fwlink/?linkid=2128684), Microsoft Defender Antimalware technologies, and Sensitive Data Discovery. With protection for Azure Blob Storage, Azure Files, and Azure Data Lake Storage services, it provides a comprehensive alert suite, near real-time malware scanning (add-on), and sensitive data threat detection (no extra cost), allowing quick detection, triage, and response to potential security threats with contextual information. It helps prevent the three major impacts on your data and workload: malicious file uploads, sensitive data exfiltration, and data corruption.
11
11
12
12
With Microsoft Defender for Storage, organizations can customize their protection and enforce consistent security policies by enabling it on subscriptions and storage accounts with granular control and flexibility.
13
13
@@ -19,22 +19,22 @@ With Microsoft Defender for Storage, organizations can customize their protectio
19
19
| Aspect | Details |
20
20
|---------|---------|
21
21
|Release state: | General Availability (GA) |
22
-
| Feature availability: |- Activity monitoring (security alerts) – General Availability (GA)<br>- Malware Scanning – General Availability (GA)<br>- Sensitive data threat detection (Sensitive Data Discovery) – Preview<br><br>Visit the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud) to learn more. |
23
-
|Required roles and permissions: | For Malware Scanning and sensitive data threat detection at subscription and storage account levels, you need Owner roles (subscription owner/storage account owner) or specific roles with corresponding data actions. To enable Activity Monitoring, you need 'Security Admin' permissions. Read more about the required permissions. |
22
+
| Feature availability: |- Activity monitoring (security alerts) – General Availability (GA)<br>- Malware scanning – General Availability (GA)<br>- Sensitive data threat detection (Sensitive Data Discovery) – Preview<br><br>Visit the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud) to learn more. |
23
+
|Required roles and permissions: | For malware scanning and sensitive data threat detection at subscription and storage account levels, you need Owner roles (subscription owner/storage account owner) or specific roles with corresponding data actions. To enable Activity Monitoring, you need 'Security Admin' permissions. Read more about the required permissions. |
24
24
| Clouds: | :::image type="icon" source="./media/icons/yes-icon.png"::: Azure Commercial clouds*<br> :::image type="icon" source="./media/icons/no-icon.png"::: Azure Government (only activity monitoring support on the classic plan)<br>:::image type="icon" source="./media/icons/no-icon.png"::: Azure China 21Vianet<br>:::image type="icon" source="./media/icons/no-icon.png"::: Connected AWS accounts |
25
25
26
-
*Azure DNS Zone is not supported for Malware Scanning and sensitive data threat detection.
26
+
*Azure DNS Zone is not supported for malware scanning and sensitive data threat detection.
27
27
28
-
## Prerequisites for Malware scanning
29
-
To enable and configure Malware Scanning, you must have Owner roles (such as Subscription Owner or Storage Account Owner) or specific roles with the necessary data actions. Learn more about the [required permissions](support-matrix-defender-for-storage.md).
28
+
## Prerequisites for malware scanning
29
+
To enable and configure malware scanning, you must have Owner roles (such as Subscription Owner or Storage Account Owner) or specific roles with the necessary data actions. Learn more about the [required permissions](support-matrix-defender-for-storage.md).
30
30
31
31
## Set up and configure Microsoft Defender for Storage
32
32
33
33
To enable and configure Microsoft Defender for Storage and ensure maximum protection and cost optimization, the following configuration options are available:
34
34
35
35
- Enable/disable Microsoft Defender for Storage at the subscription and storage account levels.
36
-
- Enable/disable the Malware Scanning or sensitive data threat detection configurable features.
37
-
- Set a monthly cap ("capping") on the Malware Scanning per storage account per month to control costs (default value is 5,000GB).
36
+
- Enable/disable the malware scanning or sensitive data threat detection configurable features.
37
+
- Set a monthly cap ("capping") on the malware scanning per storage account per month to control costs (default value is 5,000GB).
38
38
- Configure methods to set up response to malware scanning results.
39
39
- Configure methods for saving malware scanning results logging.
0 commit comments