Skip to content

Commit 3f80176

Browse files
authored
Merge pull request #94588 from MicrosoftDocs/master
Like a surgeon, hey Cuttin' for the very first time Like a surgeon Here's a waiver for you to sign
2 parents c223275 + a3ad3d4 commit 3f80176

File tree

63 files changed

+1065
-419
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

63 files changed

+1065
-419
lines changed

.openpublishing.redirection.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26604,6 +26604,11 @@
2660426604
"redirect_url": "/azure/security-center/security-center-features-retirement-july2019#custom-alert-rules-preview",
2660526605
"redirect_document_id": false
2660626606
},
26607+
{
26608+
"source_path": "articles/security-center/security-center-policies-overview.md",
26609+
"redirect_url": "/azure/security-center/tutorial-security-policy.md",
26610+
"redirect_document_id": false
26611+
},
2660726612
{
2660826613
"source_path": "articles/virtual-network/virtual-network-deploy-multinic-arm-cli.md",
2660926614
"redirect_url": "/azure/virtual-machines/linux/multiple-nics",

articles/index.md

Lines changed: 34 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1672,21 +1672,28 @@ featureFlags:
16721672
<p>Azure Private Link</p>
16731673
</a>
16741674
</li>
1675+
<li>
16751676
<a href="/azure/peering-service/">
16761677
<img src="media/index/peering-service.svg" alt="" />
16771678
<p>Peering Service</p>
16781679
</a>
16791680
</li>
1680-
</ul>
1681+
<li>
16811682
<a href="/azure/firewall-manager/">
1683+
<img src="media/index/icon-networking-361-azure-firewall-manager.svg" alt="" />
16821684
<p>Azure Firewall Manager</p>
1685+
</a>
1686+
</li>
16831687
<li>
1688+
<a href="/azure/internet-analyzer/">
16841689
<img src="media/index/internet-analyzer.svg" alt="" />
16851690
<p>Azure Internet Analyzer</p>
16861691
</a>
16871692
</li>
1693+
</ul>
16881694
<h3>Security</h3>
16891695
<ul>
1696+
<li>
16901697
<a href="/azure/security/">
16911698
<img src="media/index/SecurityCenter.svg" alt="" />
16921699
<p>Security Information</p>
@@ -1704,13 +1711,13 @@ featureFlags:
17041711
<p>Key Vault</p>
17051712
</a>
17061713
</li>
1707-
<li>
17081714
<li>
17091715
<a href="/azure/dedicated-hsm">
17101716
<img src="media/index/dedicated-hsm.svg" alt="" />
17111717
<p>Azure Dedicated HSM</p>
17121718
</a>
17131719
</li>
1720+
<li>
17141721
<a href="/azure/virtual-network/ddos-protection-overview">
17151722
<img src="media/index/ddos-protection.svg" alt="" />
17161723
<p>Azure DDoS protection</p>
@@ -5633,11 +5640,10 @@ featureFlags:
56335640
<div class="cardImage">
56345641
<img src="media/index/peering-service.svg" alt="" />
56355642
</div>
5636-
</div>
5637-
<div class="cardText">
5643+
</div>
5644+
<div class="cardText">
56385645
<h3>Peering Service</h3>
56395646
<p>Get optimal internet connectivity to access the Microsoft network</p>
5640-
</div>
56415647
</div>
56425648
</div>
56435649
</div>
@@ -5652,6 +5658,8 @@ featureFlags:
56525658
<a href="https://go.microsoft.com/fwlink/?linkid=2097091">
56535659
<div class="cardSize">
56545660
<div class="cardPadding">
5661+
<div class="card">
5662+
<div class="cardImageOuter">
56555663
<div class="cardImage">
56565664
<img src="media/index/private-link.svg" alt="" />
56575665
</div>
@@ -5666,17 +5674,38 @@ featureFlags:
56665674
</a>
56675675
</li>
56685676
<li>
5677+
<a href="/azure/firewall-manager/">
5678+
<div class="cardSize">
5679+
<div class="cardPadding">
5680+
<div class="card">
5681+
<div class="cardImageOuter">
5682+
<div class="cardImage">
56695683
<img src="media/index/icon-networking-361-azure-firewall-manager.svg" alt="" />
5684+
</div>
56705685
</div>
56715686
<div class="cardText">
56725687
<h3>Azure Firewall Manager</h3>
56735688
<p>A globally distributed security management service</p>
5689+
</div>
5690+
</div>
5691+
</div>
5692+
</div>
5693+
</a>
5694+
</li>
5695+
<li>
5696+
<a href="/azure/security-center/">
5697+
<div class="cardSize">
5698+
<div class="cardPadding">
5699+
<div class="card">
5700+
<div class="cardImageOuter">
5701+
<div class="cardImage">
56745702
<img src="media/index/SecurityCenter.svg" alt="" />
56755703
</div>
56765704
</div>
56775705
<div class="cardText">
56785706
<h3>Security Center</h3>
56795707
<p>Unify security management and enable advanced threat protection across hybrid cloud workloads</p>
5708+
</div>
56805709
</div>
56815710
</div>
56825711
</div>

articles/security-center/TOC.yml

Lines changed: 35 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,14 @@
4040
href: security-center-using-recommendations.md
4141
- name: Cross-tenant management
4242
href: security-center-cross-tenant-management.md
43+
- name: Container security
44+
items:
45+
- name: Container security overview
46+
href: container-security.md
47+
- name: Integration with Azure Container Registry
48+
href: azure-container-registry-integration.md
49+
- name: Integration with Azure Kubernetes Service
50+
href: azure-kubernetes-service-integration.md
4351
- name: Threat detection alerts and incidents
4452
items:
4553
- name: Security alerts overview
@@ -54,7 +62,7 @@
5462
href: security-center-alerts-compute.md
5563
- name: Threat detection for data services
5664
href: security-center-alerts-data-services.md
57-
- name: Threat detection for Azure service layer
65+
- name: Threat detection for Azure service layers
5866
href: security-center-alerts-service-layer.md
5967
- name: Integration with Azure Security Products
6068
href: security-center-alerts-integration.md
@@ -71,33 +79,47 @@
7179
href: security-center-secure-score.md
7280
- name: Upgrade to advanced security
7381
href: security-center-onboarding.md
74-
- name: Server protection with Microsoft Defender ATP
82+
- name: Protect your servers with Microsoft Defender ATP
7583
href: security-center-wdatp.md
76-
- name: Advanced data security for SQL on Azure VMs (Public Preview)
84+
- name: Use advanced data security for SQL on Azure VMs
7785
href: security-center-iaas-advanced-data.md
7886
- name: Use App Service to protect your applications
7987
href: security-center-app-services.md
80-
- name: Working with security policies
81-
href: tutorial-security-policy.md
88+
- name: Use security policies
89+
items:
90+
- name: Overview of security policies
91+
href: tutorial-security-policy.md
92+
- name: Use built-in security policies
93+
href: security-center-policy-definitions.md
94+
- name: Create custom security policies
95+
href: custom-security-policies.md
96+
- name: Manage policies with the Azure Policy REST API
97+
href: configure-security-policy-azure-policy.md
98+
- name: Add dynamic compliance packages
99+
href: update-regulatory-compliance-packages.md
82100
- name: Customize the information protection policy
83101
href: security-center-info-protection-policy.md
84102
- name: Manage security solutions
85103
href: security-center-partner-integration.md
86104
- name: Automate onboarding using PowerShell
87105
href: security-center-powershell-onboarding.md
88-
- name: Security Center settings
89-
href: security-center-policies-overview.md
106+
- name: Integrate with Windows Admin Center
107+
href: windows-admin-center-integration.md
90108
- name: Compare baselines using File Integrity Monitoring
91109
href: security-center-file-integrity-monitoring-baselines.md
92-
- name: Data collection
110+
- name: Automate responses to alerts and recommendations
111+
href: workflow-automation.md
112+
- name: Export alerts and recommendations
113+
href: continuous-export.md
114+
- name: Configure your data collection
93115
href: security-center-enable-data-collection.md
94-
- name: Built-in security policies
95-
href: security-center-policy-definitions.md
96-
- name: Email notifications
116+
- name: Set up advanced threat protection for Azure Key Vault
117+
href: advanced-threat-protection-key-vault.md
118+
- name: Set up email notifications
97119
href: security-center-provide-security-contact-details.md
98120
- name: Pricing
99121
href: security-center-pricing.md
100-
- name: Tenant-wide visibility
122+
- name: Gain tenant-wide visibility
101123
href: security-center-management-groups.md
102124
- name: Implement security recommendations
103125
items:
@@ -167,7 +189,7 @@
167189
- name: Manage user data
168190
href: security-center-privacy.md
169191
- name: Azure Security Center for IoT documentation
170-
href: https://docs.microsoft.com/en-us/azure/asc-for-iot/
192+
href: https://docs.microsoft.com/azure/asc-for-iot/
171193
- name: FAQ
172194
href: security-center-faq.md
173195
- name: Azure security documentation
Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,42 @@
1+
---
2+
title: How to set up advanced threat protection for Azure Key Vault | Microsoft Docs
3+
description: This article explains how to set up advanced threat protection for Azure Key Vault in Azure Security Center
4+
services: security-center
5+
author: memildin
6+
manager: rkarlin
7+
ms.service: security-center
8+
ms.topic: conceptual
9+
ms.date: 11/04/2019
10+
ms.author: memildin
11+
12+
---
13+
# How to set up advanced threat protection for Azure Key Vault (Preview)
14+
15+
Advanced threat protection for Azure Key Vault provides an additional layer of security intelligence. This tool detects potentially harmful attempts to access or exploit Key Vault accounts. Using Security Center's native advanced threat protection, you can address threats without being a security expert, and without learning additional security monitoring systems.
16+
17+
When Security Center detects anomalous activity, it displays alerts. It also emails the subscription administrator with details of the suspicious activity and recommendations for how to investigate and remediate the identified threats.
18+
19+
> [!NOTE]
20+
> Advanced threat protection for Azure Key Vault is currently only available in North America regions.
21+
22+
## To set up advanced threat protection from Azure Security Center
23+
24+
By default, advanced threat protection is enabled for all of your Key Vault accounts when you subscribe to Security Center's Standard tier (see [pricing](security-center-pricing.md)).
25+
26+
To enable or disable the protection for a specific subscription:
27+
28+
1. From Security Center's sidebar, click **Pricing & settings**.
29+
1. Select the subscription with the storage accounts for which you want to enable or disable threat protection.
30+
1. Click **Pricing tier**.
31+
1. From the **Select pricing tier by resource type** group, find the Key Vaults row and click **Enabled** or **Disabled**.
32+
[![Enabling or disabling the advanced threat protection for Key Vault in Azure Security Center](media/advanced-threat-protection-key-vault/atp-for-akv-enable-atp-for-akv.png)](media/advanced-threat-protection-key-vault/atp-for-akv-enable-atp-for-akv.png#lightbox)
33+
1. Click **Save**.
34+
35+
36+
## Next steps
37+
38+
In this article, you learned how to enable and disable advanced threat protection for Azure Key Vault.
39+
40+
For other related material, see the following article:
41+
42+
- [Threat detection for the Azure services layers in Security Center](security-center-alerts-service-layer.md) - This article describes the alerts related to advanced threat protection for Azure Key Vault
Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,44 @@
1+
---
2+
title: Azure Security Center and Azure Container Registry | Microsoft Docs
3+
description: "Learn about Azure Security Center's integration with Azure Container Registry"
4+
services: security-center
5+
documentationcenter: na
6+
author: memildin
7+
manager: rkarlin
8+
ms.service: security-center
9+
ms.devlang: na
10+
ms.topic: conceptual
11+
ms.tgt_pltfrm: na
12+
ms.workload: na
13+
ms.date: 11/04/2019
14+
ms.author: memildin
15+
16+
---
17+
18+
# Azure Container Registry integration with Security Center (Preview)
19+
20+
Azure Container Registry (ACR) is a managed, private Docker registry service that stores and manages your container images for Azure deployments in a central registry. It's based on the open-source Docker Registry 2.0.
21+
22+
When using ACR together with Azure Security Center's standard tier (see [pricing](security-center-pricing.md)), you gain deeper visibility into your registry and images' vulnerabilities.
23+
24+
[![Azure Container Registry (ACR) recommendations inside Azure Security Center](media/azure-container-registry-integration/container-security-acr-page.png)](media/azure-container-registry-integration/container-security-acr-page.png#lightbox)
25+
26+
## Benefits of integration
27+
28+
Security Center identifies ACR registries in your subscription and seamlessly provides:
29+
30+
* **Azure-native vulnerability scanning** for all pushed Linux images. Security Center scans the image using a scanner from the industry-leading vulnerability scanning vendor, Qualys. This native solution is seamlessly integrated by default.
31+
32+
* **Security recommendations** for Linux images with known vulnerabilities. Security Center provides details of each reported vulnerability and a severity classification. Additionally, it gives guidance for how to remediate the specific vulnerabilities found on each image pushed to registry.
33+
34+
![Azure Security Center and Azure Container Registry (ACR) high-level overview](./media/azure-container-registry-integration/aks-acr-integration-detailed.png)
35+
36+
## Next steps
37+
38+
To learn more about Security Center's container security features, see:
39+
40+
* [Azure Security Center and container security](container-security.md)
41+
42+
* [Integration with Azure Kubernetes Service](azure-kubernetes-service-integration.md)
43+
44+
* [Virtual Machine protection](security-center-virtual-machine-protection.md) - Describes Security Center's recommendations
Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
---
2+
title: Azure Security Center and Azure Kubernetes Service | Microsoft Docs
3+
description: "Learn about Azure Security Center's integration with Azure Kubernetes Services"
4+
services: security-center
5+
documentationcenter: na
6+
author: memildin
7+
manager: rkarlin
8+
ms.service: security-center
9+
ms.devlang: na
10+
ms.topic: conceptual
11+
ms.tgt_pltfrm: na
12+
ms.workload: na
13+
ms.date: 11/04/2019
14+
ms.author: memildin
15+
16+
---
17+
18+
# Azure Kubernetes Services integration with Security Center (Preview)
19+
Azure Kubernetes Service (AKS) is Microsoft’s managed service for developing, deploying, and managing containerized applications.
20+
21+
Use AKS together with Azure Security Center's standard tier (see [pricing](security-center-pricing.md)) to gain deeper visibility to your AKS nodes, cloud traffic, and security controls.
22+
23+
Security Center brings security benefits to your AKS clusters using data already gathered by the AKS master node.
24+
25+
![Azure Security Center and Azure Kubernetes Service (AKS) high-level overview](./media/azure-kubernetes-service-integration/aks-asc-integration-overview.png)
26+
27+
Together, these two tools form the best cloud-native Kubernetes security offering.
28+
29+
## Benefits of integration
30+
31+
Using the two services together provides:
32+
33+
* **Security recommendations** - Security Center identifies your AKS resources and categorizes them: from clusters to individual virtual machines. You can then view security recommendations per resource. For more information, see [How to implement security recommendations](security-center-recommendations.md).
34+
35+
> [!NOTE]
36+
> If the name of a Security Center recommendation ends with a "(Preview)" tag, it's referring to the preview nature of the recommendation; not the feature.
37+
38+
* **Environment hardening** - Security Center constantly monitors the configuration of your Kubernetes clusters, and generates security recommendations that reflect industry standards.
39+
40+
* **Run-time protection** - Through continuous analysis of the following AKS sources, Security Center alerts you to threats and malicious activity detected at the host *and* AKS cluster level (for more information, see [Azure container service](https://docs.microsoft.com/azure/security-center/security-center-alerts-compute#azure-container-service-)):
41+
* Raw security events, such as network data and process creation
42+
* The Kubernetes audit log
43+
44+
![Azure Security Center and Azure Kubernetes Service (AKS) in more detail](./media/azure-kubernetes-service-integration/aks-asc-integration-detailed.png)
45+
46+
> [!NOTE]
47+
> Some of the data scanned by Azure Security Center from your Kubernetes environment may contain sensitive information.
48+
49+
## Next steps
50+
51+
To learn more about Security Center's container security features, see:
52+
53+
* [Azure Security Center and container security](container-security.md)
54+
55+
* [Integration with Azure Container Registry](azure-container-registry-integration.md)
56+
57+
* [Virtual Machine protection](security-center-virtual-machine-protection.md) - Describes Security Center's recommendations
58+
59+
* [Data management at Microsoft](https://www.microsoft.com/trust-center/privacy/data-management) - Describes the data policies of Microsoft services (including Azure, Intune, and Office 365), details of Microsoft’s data management, and the retention policies that affect your data

0 commit comments

Comments
 (0)