You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/enable-permissions-management.md
+17-18Lines changed: 17 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,16 +1,16 @@
1
1
---
2
-
title: Enable permissions management (CIEM)
2
+
title: Enable Permissions Management (CIEM)
3
3
author: Elazark
4
4
ms.author: elkrieger
5
-
description: Learn how to enable permissions management for better access control and security in your cloud infrastructure.
5
+
description: Learn how to enable Permissions Management for better access control and security in your cloud infrastructure.
6
6
ms.topic: how-to
7
7
ms.date: 05/07/2024
8
8
#customer intent: As a cloud administrator, I want to learn how to enable permissions (CIEM) in order to effectively manage user access and entitlements in my cloud infrastructure.
9
9
---
10
10
11
-
# Enable permissions management (CIEM)
11
+
# Enable Permissions Management (CIEM)
12
12
13
-
Microsoft Defender for Cloud's integration with Microsoft Entra Permissions Management provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
13
+
Microsoft Defender for Cloud's integration with Microsoft Entra Permissions Management (Permissions Management) provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
14
14
15
15
## Before you start
16
16
@@ -24,11 +24,11 @@ Microsoft Defender for Cloud's integration with Microsoft Entra Permissions Mana
24
24
25
25
-**GCP only**: [Connect your GCP project to Defender for Cloud](quickstart-onboard-gcp.md).
26
26
27
-
## Enable permissions management (CIEM) for Azure
27
+
## Enable Permissions Management (CIEM) for Azure
28
28
29
29
When you enabled the Defender CSPM plan on your Azure account, the **Azure CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The Azure CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
30
30
31
-
When Permission Management (CIEM) is disabled, the CIEM recommendations within the Azure CSPM standard won’t be calculated.
31
+
When Permissions Management (CIEM) is disabled, the CIEM recommendations within the Azure CSPM standard won’t be calculated.
32
32
33
33
1. Sign in to the [Azure portal](https://portal.azure.com).
34
34
@@ -48,17 +48,17 @@ When Permission Management (CIEM) is disabled, the CIEM recommendations within t
48
48
49
49
1. Select **Save**.
50
50
51
-
The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
51
+
The applicable Permissions Management (CIEM) recommendations appear on your subscription within a few hours.
52
52
53
53
List of Azure recommendations:
54
54
55
-
- Azure overprovisioned identities should have only the necessary permissions
55
+
- Azure over-provisioned identities should have only the necessary permissions
56
56
57
57
- Unused identities in your Azure environment should be revoked/removed
58
58
59
59
- Super identities in your Azure environment should be revoked/removed
60
60
61
-
## Enable permissions management (CIEM) for AWS
61
+
## Enable Permissions Management (CIEM) for AWS
62
62
63
63
When you enabled the Defender CSPM plan on your AWS account, the **AWS CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The AWS CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
64
64
When Permission Management is disabled, the CIEM recommendations within the AWS CSPM standard won’t be calculated.
@@ -93,19 +93,19 @@ When Permission Management is disabled, the CIEM recommendations within the AWS
93
93
94
94
1. Select **Update**.
95
95
96
-
The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
96
+
The applicable Permissions Management (CIEM) recommendations appear on your subscription within a few hours.
97
97
98
98
List of AWS recommendations:
99
99
100
-
- AWS overprovisioned identities should have only the necessary permissions
100
+
- AWS over-provisioned identities should have only the necessary permissions
101
101
102
102
- Unused identities in your Azure environment should be revoked/removed
103
103
104
-
## Enable permissions management (CIEM) for GCP
104
+
## Enable Permissions Management (CIEM) for GCP
105
105
106
106
When you enabled the Defender CSPM plan on your GCP project, the **GCP CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The GCP CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
107
107
108
-
When Permission Management (CIEM) is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated.
108
+
When Permissions Management (CIEM) is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated.
109
109
110
110
1. Sign in to the [Azure portal](https://portal.azure.com).
111
111
@@ -119,7 +119,7 @@ When Permission Management (CIEM) is disabled, the CIEM recommendations within t
119
119
120
120
:::image type="content" source="media/enable-permissions-management/settings-google.png" alt-text="Screenshot that shows where to select settings for the Defender CSPM plan for your GCP project." lightbox="media/enable-permissions-management/settings-google.png":::
121
121
122
-
1. Toggle permissions management**(CIEM)** to **On**.
122
+
1. Toggle Permissions Management**(CIEM)** to **On**.
123
123
124
124
1. Select **Save**.
125
125
@@ -139,17 +139,16 @@ When Permission Management (CIEM) is disabled, the CIEM recommendations within t
139
139
140
140
1. Select **Update**.
141
141
142
-
The applicable permissions management**(CIEM)** recommendations appear on your subscription within a few hours.
142
+
The applicable Permissions Management**(CIEM)** recommendations appear on your subscription within a few hours.
143
143
144
144
List of GCP recommendations:
145
145
146
-
- GCP overprovisioned identities should have only necessary permissions
146
+
- GCP over-provisioned identities should have only necessary permissions
147
147
148
148
- Unused identities in your GCP environment should be revoked/removed
149
149
150
150
- Super identities in your GCP environment should be revoked/removed
description: Learn about permissions (CIEM) in Microsoft Defender for Cloud and enhance the security of your cloud infrastructure.
4
4
ms.topic: concept-article
5
5
author: Elazark
6
6
ms.author: elkrieger
7
-
ms.date: 03/07/2024
7
+
ms.date: 05/08/2024
8
8
#customer intent: As a user, I want to understand how to manage permissions effectively so that I can enhance the security of my cloud infrastructure.
9
9
---
10
10
11
-
# Permissions management (CIEM)
11
+
# Permissions Management (CIEM)
12
12
13
-
Microsoft Defender for Cloud's integration with Microsoft [Microsoft Entra Permissions Management](/entra/permissions-management/overview) provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
13
+
Microsoft Defender for Cloud's integration with [Microsoft Entra Permissions Management](/entra/permissions-management/overview)(Permissions Management) provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. CIEM ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
14
14
15
-
Integrating Entra Permissions Management with Defender for Cloud (CNAPP) strengthens cloud security by preventing security breaches caused by excessive permissions or misconfigurations. Permissions management continuously monitors and manages cloud entitlements, helping to discover attack surfaces, detect threats, right-size access permissions, and maintain compliance. This integration enhances the capabilities of Defender for Cloud in securing cloud-native applications and protecting sensitive data.
15
+
Integrating Permissions Management with Defender for Cloud (CNAPP) strengthens cloud security by preventing security breaches caused by excessive permissions or misconfigurations. Permissions Management continuously monitors and manages cloud entitlements, helping to discover attack surfaces, detect threats, right-size access permissions, and maintain compliance. This integration enhances the capabilities of Defender for Cloud in securing cloud-native applications and protecting sensitive data.
16
16
17
17
This integration brings the following insights derived from the Microsoft Entra Permissions Management suite into the Microsoft Defender for Cloud portal. For more information, see the [feature matrix](#feature-matrix).
18
18
19
19
## Common use-cases and scenarios
20
20
21
-
Microsoft Entra Permissions Management capabilities integrate as a valuable component within the Defender [Cloud Security Posture Management (CSPM)](concept-cloud-security-posture-management.md) plan. The integrated capabilities are foundational, providing the essential functionalities within Microsoft Defender for Cloud. With these added capabilities, you can track permissions analytics, unused permissions for active identities, and over-permissioned identities and mitigate them to support the best practice of least privilege.
21
+
Permissions Management capabilities integrate as a valuable component within the Defender [Cloud Security Posture Management (CSPM)](concept-cloud-security-posture-management.md) plan. The integrated capabilities are foundational, providing the essential functionalities within Microsoft Defender for Cloud. With these added capabilities, you can track permissions analytics, unused permissions for active identities, and over-permissioned identities and mitigate them to support the best practice of least privilege.
22
22
23
23
The integration creates recommendations under the Manage Access and Permissions security control on the Recommendations page in Defender for Cloud.
24
24
25
25
## Known limitations
26
26
27
-
AWS and GCP accounts that were onboarded to Microsoft Entra Permissions Management before being onboarded to Defender for Cloud can't be integrated through Microsoft Defender for Cloud.
27
+
AWS and GCP accounts that were onboarded to Permissions Management before being onboarded to Defender for Cloud can't be integrated through Microsoft Defender for Cloud.
28
28
29
29
## Feature matrix
30
30
31
-
The integration feature comes as part of Defender CSPM plan and doesn't require a Microsoft Entra Permissions Management (MEPM) license. To learn more about other capabilities that you can receive from MEPM, refer to the feature matrix:
31
+
The integration feature comes as part of Defender CSPM plan and doesn't require a Permissions Management license. To learn more about other capabilities that you can receive from Permissions Management, refer to the feature matrix:
| Remediate | Remediate identities by attaching / detaching the permissions | ❌ | ✓ |
42
-
| Remediate | Custom role / AWS Policy generation based on activities of identities, groups, etc. | ❌ | ✓ |
42
+
| Remediate | Custom role / AWS Policy generation based on activities of identities, groups, etc. | ❌ | ✓ |
43
43
| Remediate | Permissions on demand (time-bound access) for human and workload identities via Microsoft Entra admin center, APIs, ServiceNow app. | ❌ | ✓ |
0 commit comments