Skip to content

Commit 55d1dfe

Browse files
authored
Merge pull request #277425 from rayne-wiselman/rayne-azure-june6
updating solution article
2 parents 51d1241 + 9acd019 commit 55d1dfe

File tree

1 file changed

+25
-46
lines changed

1 file changed

+25
-46
lines changed

articles/defender-for-cloud/partner-integration.md

Lines changed: 25 additions & 46 deletions
Original file line numberDiff line numberDiff line change
@@ -3,84 +3,63 @@ title: Integrate security solutions in Defender for Cloud
33
description: Learn about how Microsoft Defender for Cloud integrates with partner solutions to enhance your security posture and protect your Azure resources.
44
ms.topic: concept-article
55
ms.date: 05/16/2024
6-
#customer intent: As a reader, I want to learn how to integrate security solutions in Defender for Cloud so that I can enhance my security posture and protect my Azure resources.
6+
#customer intent: As a reader, I want to learn how security solutions integrate into Defender for Cloud.
77
---
88

9-
# Integrate security solutions in Defender for Cloud
9+
# Integrated solutions in Defender for Cloud
1010

11-
This document helps you to manage security solutions already connected to Microsoft Defender for Cloud and add new ones.
11+
This article provides information about security solutions that integrate with Microsoft Defender for Cloud.
1212

13-
## Integrated Azure security solutions
13+
Defender for Cloud integrates with both Microsoft services and partner solutions. Integration with solutions helps you to:
1414

15-
Defender for Cloud makes it easy to enable integrated security solutions in Azure. Benefits include:
15+
- **Simplify deployment**: Defender for Cloud offers streamlined provisioning of integrated partner solutions. For solutions like antimalware and vulnerability assessment, Defender for Cloud can provision the agent on your virtual machines. For firewall appliances, Defender for Cloud can take care of much of the network configuration required.
16+
- **Integrate detection**: Security events from partner solutions are automatically collected, aggregated, and displayed as part of Defender for Cloud alerts and incidents. These events are also fused with detections from other sources to provide advanced threat-detection capabilities.
17+
- **Unify monitoring and management**: Integrated events in Defender for Cloud help you to monitor partner solutions at a glance. Basic management is available, with easy access to advanced setup by using the partner solution.
18+
- **Extend capabilities**: Some integrations extend Defender for Cloud capabilities. For example:
19+
- Defender for Cloud supports [third-party integrations](defender-partner-applications.md) to help enhance runtime security capabilities provided by Defender for APIs.
20+
- Defender for Cloud [integrates with ServiceNow](integration-servicenow.md) to help prioritize remediation of security recommendations, and to create and monitor tickets.
1621

17-
- **Simplified deployment**: Defender for Cloud offers streamlined provisioning of integrated partner solutions. For solutions like antimalware and vulnerability assessment, Defender for Cloud can provision the agent on your virtual machines. For firewall appliances, Defender for Cloud can take care of much of the network configuration required.
18-
- **Integrated detections**: Security events from partner solutions are automatically collected, aggregated, and displayed as part of Defender for Cloud alerts and incidents. These events are also fused with detections from other sources to provide advanced threat-detection capabilities.
19-
- **Unified health monitoring and management**: Customers can use integrated health events to monitor all partner solutions at a glance. Basic management is available, with easy access to advanced setup by using the partner solution.
2022

21-
Currently, integrated security solutions include vulnerability assessment by [Qualys](https://www.qualys.com/public-cloud/#azure) and [Rapid7](https://www.rapid7.com/products/insightvm/).
23+
## Integrations
2224

23-
> [!NOTE]
24-
> Defender for Cloud does not install the Log Analytics agent on partner virtual appliances because most security vendors prohibit external agents running on their appliances.
25-
26-
Learn more about the integration of [vulnerability scanning tools from Qualys](deploy-vulnerability-assessment-vm.md), including a built-in scanner available to customers that enable Microsoft Defender for Servers.
27-
28-
## How security solutions are integrated
25+
Integrated solutions appear in the Azure portal, in **Defender for Cloud** -> **Management** -> **Security solutions**.
2926

3027
Azure security solutions that are deployed from Defender for Cloud are automatically connected. You can also connect other security data sources, including computers running on-premises or in other clouds.
3128

3229
:::image type="content" source="./media/partner-integration/security-solutions-page-01-2023.png" alt-text="Screenshot showing security Solutions page." lightbox="./media/partner-integration/security-solutions-page-01-2023.png":::
3330

34-
## Manage integrated Azure security solutions and other data sources
35-
36-
1. From the [Azure portal](https://azure.microsoft.com/features/azure-portal/), open **Defender for Cloud**.
37-
38-
1. From Defender for Cloud's menu, select **Security solutions**.
39-
40-
The **Security solutions** page presents the health of the integrated Azure security solutions and runs basic management tasks.
41-
4231
### Connected solutions
4332

44-
The **Connected solutions** section includes security solutions that are currently connected to Defender for Cloud. It also shows the health status of each solution.
33+
The **Connected solutions** section includes security solutions that are currently connected to Defender for Cloud.
4534

4635
:::image type="content" source="media/partner-integration/connected-solutions.png" alt-text="Screenshot that shows the available connectable solutions.":::
4736

4837
The status of a security solution can be:
4938

50-
- **Healthy** (green) - no health issues.
51-
- **Unhealthy** (red) - there's a health issue that requires immediate attention.
52-
- **Stopped reporting** (orange) - the solution has stopped reporting its health.
53-
- **Not reported** (gray) - the solution hasn't reported anything yet and no health data is available. A solution's status might be unreported if it was connected recently and is still deploying.
39+
- **Healthy** (green): No health issues.
40+
- **Unhealthy** (red): There's a health issue that requires immediate attention. If no health data is available and no alerts were received within the last 14 days, Defender for Cloud indicates that the solution is unhealthy or not reporting.
41+
- **Stopped reporting** (orange): The solution stopped reporting health status.
42+
- **Not reported** (gray): No health data is available. The solution didn't report anything yet and no health data is available. A solution's status might be unreported if it was connected recently and is still deploying.
5443

55-
> [!NOTE]
56-
> If health status data is not available, Defender for Cloud shows the date and time of the last event received to indicate whether the solution is reporting or not. If no health data is available and no alerts were received within the last 14 days, Defender for Cloud indicates that the solution is unhealthy or not reporting.
44+
If health status isn't available, Defender for Cloud shows the date and time of the last event received to indicate whether the solution is reporting or not.
5745

58-
Select **VIEW** for additional information and options such as:
46+
You can drill down into each solution to manage it.
5947

60-
- **Solution console** - Opens the management experience for this solution.
61-
- **Link VM** - Opens the Link Applications page. Here you can connect resources to the partner solution.
62-
- **Delete solution**
63-
- **Configure**
48+
### Discovered solutions
6449

65-
:::image type="content" source="media/partner-integration/partner-solutions-detail.png" alt-text="Screenshot that shows the a sample partner soltion and the details of that solution.":::
50+
Defender for Cloud automatically discovers security solutions that are running in Azure but not connected to Defender for Cloud, and displays them in the **Discovered solutions** section. You can connect solutions as needed to integrate it with Defender for Cloud.
6651

67-
### Discovered solutions
52+
### Add data sources
6853

69-
Defender for Cloud automatically discovers security solutions running in Azure but not connected to Defender for Cloud and displays the solutions in the **Discovered solutions** section. These solutions include Azure solutions, like [Microsoft Entra ID Protection](../active-directory/identity-protection/overview-identity-protection.md), and partner solutions.
54+
The **Add data sources** section includes other available data sources that can be connected. For instructions on adding data from any of these sources, select **ADD**.
7055

71-
> [!NOTE]
72-
> Enable **advanced protections** at the subscription level for the discovered solutions feature. Learn more in [Quickstart: Enable enhanced security features](enable-enhanced-security.md).
56+
:::image type="content" source="media/partner-integration/add-data-sources.png" alt-text="Screenshot that shows the available additional data sources.":::
7357

74-
Select **CONNECT** under a solution to integrate with Defender for Cloud and be notified of security alerts.
7558

76-
### Add data sources
7759

78-
The **Add data sources** section includes other available data sources that can be connected. For instructions on adding data from any of these sources, select **ADD**.
7960

80-
:::image type="content" source="media/partner-integration/add-data-sources.png" alt-text="Screenshot that shows the available additonal data sources.":::
8161

82-
![Data sources.](./media/partner-integration/add-data-sources.png)
8362

8463
## Related content
8564

86-
- [Continuously export Defender for Cloud data](continuous-export.md).
65+
[Continuously export Defender for Cloud data](continuous-export.md).

0 commit comments

Comments
 (0)