Skip to content

Commit 61d5e00

Browse files
authored
Merge pull request #267550 from AlizaBernstein/WI-196377-resource-type-foundational-cspm
WI-196377-resource-type-foundational-cspm
2 parents 41389f0 + dbd8ec3 commit 61d5e00

File tree

3 files changed

+286
-1
lines changed

3 files changed

+286
-1
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -210,6 +210,8 @@
210210
href: enable-permissions-management.md
211211
- name: Agentless machine scanning
212212
href: concept-agentless-data-collection.md
213+
- name: Supported resource types for multicloud in Foundational CSPM
214+
href: multicloud-resource-types-support-foundational-cspm.md
213215
- name: Integrations
214216
items:
215217
- name: ServiceNow integration

articles/defender-for-cloud/concept-cloud-security-posture-management.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Cloud Security Posture Management (CSPM)
33
description: Learn more about CSPM in Microsoft Defender for Cloud.
44
ms.topic: conceptual
55
ms.custom: build-2023
6-
ms.date: 02/11/2024
6+
ms.date: 02/28/2024
77
---
88

99
# Cloud security posture management (CSPM)
@@ -92,6 +92,10 @@ You can choose which ticketing system to integrate. For preview, only ServiceNow
9292

9393
For commercial and national cloud coverage, review the [features supported in Azure cloud environments](support-matrix-cloud-environment.md).
9494

95+
## Support for Resource type in AWS and GCP
96+
97+
For multicloud support of resource types (or services) in our foundational multicloud CSPM tier, see the [table of multicloud resource and service types for AWS and GCP](multicloud-resource-types-support-foundational-cspm.md).
98+
9599
## Next steps
96100

97101
- Watch [Predict future security incidents! Cloud Security Posture Management with Microsoft Defender](https://www.youtube.com/watch?v=jF3NSR_OepI).
Lines changed: 279 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,279 @@
1+
---
2+
title: Supported resource and service types for multicloud in Foundational CSPM
3+
description: Learn more about the supported resource and service types for multicloud in Microsoft Defender for Cloud's Foundational CSPM.
4+
ms.topic: conceptual
5+
ms.date: 02/29/2024
6+
---
7+
8+
# Supported resource and service types for multicloud in foundational CSPM
9+
10+
This page lists the resource and service types that are supported for Amazon Web Services (AWS) and Google Cloud Platform (GCP) in Defender for Cloud’s foundational Cloud Security Posture Management (CSPM) tier.
11+
12+
## Resource types supported in AWS
13+
14+
| Provider Namespace | Resource Type Name |
15+
|----|----|
16+
| AccessAnalyzer | AnalyzerSummary |
17+
| ApiGateway | Stage |
18+
| AppSync | GraphqlApi |
19+
| ApplicationAutoScaling | ScalableTarget |
20+
| AutoScaling | AutoScalingGroup |
21+
| AWS | Account |
22+
| AWS | AccountInRegion |
23+
| CertificateManager | CertificateTags |
24+
| CertificateManager | CertificateDetail |
25+
| CertificateManager | CertificateSummary |
26+
| CloudFormation | StackSummary |
27+
| CloudFormation | StackTemplate |
28+
| CloudFormation | StackInstanceSummary |
29+
| CloudFormation | Stack |
30+
| CloudFormation | StackResourceSummary |
31+
| CloudFront | DistributionConfig |
32+
| CloudFront | DistributionSummary |
33+
| CloudFront | DistributionTags |
34+
| CloudTrail | EventSelector |
35+
| CloudTrail | Trail |
36+
| CloudTrail | TrailStatus |
37+
| CloudTrail | TrailTags |
38+
| CloudWatch | MetricAlarm |
39+
| CloudWatch | MetricAlarmTags |
40+
| CloudWatchLogs | LogGroup |
41+
| CloudWatchLogs | MetricFilter |
42+
| CodeBuild | Project |
43+
| CodeBuild | ProjectName |
44+
| CodeBuild | SourceCredentialsInfo |
45+
| ConfigService | ConfigurationRecorder |
46+
| ConfigService | ConfigurationRecorderStatus |
47+
| ConfigService | DeliveryChannel |
48+
| DAX | Cluster |
49+
| DAX | ClusterTags |
50+
| DatabaseMigrationService | ReplicationInstance |
51+
| DynamoDB | ContinuousBackupsDescription |
52+
| DynamoDB | TableDescription |
53+
| DynamoDB | TableTags |
54+
| DynamoDB | TableName |
55+
| EC2 | Snapshot |
56+
| EC2 | Subnet |
57+
| EC2 | Volume |
58+
| EC2 | VPC |
59+
| EC2 | VpcEndpoint |
60+
| EC2 | VpcPeeringConnection |
61+
| EC2 | Instance |
62+
| EC2 | AccountAttribute |
63+
| EC2 | Address |
64+
| EC2 | CreateVolumePermission |
65+
| EC2 | EbsEncryptionByDefault |
66+
| EC2 | FlowLog |
67+
| EC2 | Image |
68+
| EC2 | InstanceStatus |
69+
| EC2 | InstanceTypeInfo |
70+
| EC2 | NetworkAcl |
71+
| EC2 | NetworkInterface |
72+
| EC2 | Region |
73+
| EC2 | Reservation |
74+
| EC2 | RouteTable |
75+
| EC2 | SecurityGroup |
76+
| ECR | Image |
77+
| ECR | Repository |
78+
| ECR | RepositoryPolicy |
79+
| ECS | TaskDefinition |
80+
| ECS | ServiceArn |
81+
| ECS | Service |
82+
| ECS | ClusterArn |
83+
| ECS | TaskDefinitionTags |
84+
| ECS | TaskDefinitionArn |
85+
| EFS | FileSystemDescription |
86+
| EFS | MountTargetDescription |
87+
| EKS | Cluster |
88+
| EKS | Nodegroup |
89+
| EKS | NodegroupName |
90+
| EKS | ClusterName |
91+
| EMR | Cluster |
92+
| ElasticBeanstalk | ConfigurationSettingsDescription |
93+
| ElasticBeanstalk | EnvironmentDescription |
94+
| ElasticLoadBalancing | LoadBalancerTags |
95+
| ElasticLoadBalancing | LoadBalancer |
96+
| ElasticLoadBalancing | LoadBalancerAttributes |
97+
| ElasticLoadBalancing | LoadBalancerPolicy |
98+
| ElasticLoadBalancingV2 | LoadBalancerTags |
99+
| ElasticLoadBalancingV2 | Rule |
100+
| ElasticLoadBalancingV2 | TargetGroup |
101+
| ElasticLoadBalancingV2 | TargetHealthDescription |
102+
| ElasticLoadBalancingV2 | LoadBalancer |
103+
| ElasticLoadBalancingV2 | Listener |
104+
| ElasticLoadBalancingV2 | LoadBalancerAttribute |
105+
| Elasticsearch | DomainInfo |
106+
| Elasticsearch | DomainStatus |
107+
| Elasticsearch | DomainTags |
108+
| GuardDuty | DetectorId |
109+
| Iam | AccountAlias |
110+
| Iam | AttachedPolicyType |
111+
| Iam | CredentialReport |
112+
| Iam | Group |
113+
| Iam | InstanceProfile |
114+
| Iam | MFADevice |
115+
| Iam | PasswordPolicy |
116+
| Iam | ServerCertificateMetadata |
117+
| Iam | SummaryMap |
118+
| Iam | User |
119+
| Iam | UserPolicies |
120+
| Iam | VirtualMFADevice |
121+
| Iam | ManagedPolicy |
122+
| Iam | ManagedPolicy |
123+
| Iam | AccessKeyLastUsed |
124+
| Iam | AccessKeyMetadata |
125+
| Iam | PolicyVersion |
126+
| Iam | PolicyVersion |
127+
| Internal | Iam_EntitiesForPolicy |
128+
| Internal | Iam_EntitiesForPolicy |
129+
| Internal | AwsSecurityConnector |
130+
| KMS | KeyPolicyName |
131+
| KMS | KeyRotationStatus |
132+
| KMS | KeyTags |
133+
| KMS | KeyPolicy |
134+
| KMS | KeyMetadata |
135+
| KMS | KeyListEntry |
136+
| KMS| AliasListEntry |
137+
| Lambda | FunctionCodeLocation |
138+
| Lambda | FunctionConfiguration|
139+
| Lambda | FunctionPolicy |
140+
| Lambda | FunctionTags |
141+
| Macie2 | JobSummary |
142+
| Macie2 | MacieStatus |
143+
| NetworkFirewall | Firewall |
144+
| NetworkFirewall | FirewallMetadata |
145+
| NetworkFirewall | FirewallPolicy |
146+
| NetworkFirewall | FirewallPolicyMetadata |
147+
| NetworkFirewall | RuleGroup |
148+
| NetworkFirewall | RuleGroupMetadata |
149+
| RDS | ExportTask |
150+
| RDS | DBClusterSnapshot |
151+
| RDS | DBSnapshot |
152+
| RDS | DBSnapshotAttributesResult |
153+
| RDS | EventSubscription |
154+
| RDS | DBCluster |
155+
| RDS | DBInstance |
156+
| RDS | DBClusterSnapshotAttributesResult |
157+
| RedShift | LoggingStatus |
158+
| RedShift | Parameter |
159+
| Redshift | Cluster |
160+
| Route53 | HostedZone |
161+
| Route53 | ResourceRecordSet |
162+
| Route53Domains | DomainSummary |
163+
| S3 | S3Region |
164+
| S3 | S3BucketTags |
165+
| S3 | S3Bucket |
166+
| S3 | BucketPolicy |
167+
| S3 | BucketEncryption |
168+
| S3 | BucketPublicAccessBlockConfiguration |
169+
| S3 | BucketVersioning |
170+
| S3 | LifecycleConfiguration |
171+
| S3 | PolicyStatus |
172+
| S3 | ReplicationConfiguration |
173+
| S3 | S3AccessControlList |
174+
| S3 | S3BucketLoggingConfig |
175+
| S3Control | PublicAccessBlockConfiguration |
176+
| SNS | Subscription |
177+
| SNS | Topic |
178+
| SNS | TopicAttributes |
179+
| SNS | TopicTags |
180+
| SQS | Queue |
181+
| SQS | QueueAttributes |
182+
| SQS | QueueTags |
183+
| SageMaker | NotebookInstanceSummary |
184+
| SageMaker | DescribeNotebookInstanceTags |
185+
| SageMaker | DescribeNotebookInstanceResponse |
186+
| SecretsManager | SecretResourcePolicy |
187+
| SecretsManager | SecretListEntry |
188+
| SecretsManager | DescribeSecretResponse |
189+
| SimpleSystemsManagement | ParameterMetadata |
190+
| SimpleSystemsManagement | ParameterTags |
191+
| SimpleSystemsManagement | ResourceComplianceSummary |
192+
| SimpleSystemsManagement | InstanceInformation |
193+
| WAF | LoggingConfiguration |
194+
| WAF | WebACL |
195+
| WAF | WebACLSummary |
196+
| WAFV2 | ApplicationLoadBalancerForWebACL |
197+
| WAFV2 | WebACLSummary |
198+
199+
## Resource types supported in GCP
200+
201+
| Provider Namespace | Resource Type Name |
202+
|----|----|
203+
| ApiKeys | Key |
204+
| ArtifactRegistry | Image |
205+
| ArtifactRegistry | Repository |
206+
| ArtifactRegistry | RepositoryPolicy |
207+
| Bigquery | Dataset |
208+
| Bigquery | DatasetData |
209+
| Bigquery | Table |
210+
| Bigquery | TablePolicy |
211+
| Bigquery | TablesData |
212+
| CloudKMS | CryptoKey |
213+
| CloudKMS | CryptoKeyPolicy |
214+
| CloudKMS | KeyRing |
215+
| CloudKMS | KeyRingPolicy |
216+
| CloudResourceManager | Project |
217+
| CloudResourceManager | Ancestor |
218+
| CloudResourceManager | AncestorPolicy |
219+
| CloudResourceManager | EffectiveOrgPolicy |
220+
| CloudResourceManager | Folder |
221+
| CloudResourceManager | FolderPolicy |
222+
| CloudResourceManager | Organization |
223+
| CloudResourceManager | OrganizationPolicy |
224+
| CloudResourceManager | Policy |
225+
| Compute | Instance |
226+
| Compute | BackendService |
227+
| Compute | BackendService |
228+
| Compute | Disk |
229+
| Compute | EffectiveFirewalls |
230+
| Compute | Firewall |
231+
| Compute | ForwardingRule |
232+
| Compute | GlobalForwardingRule |
233+
| Compute | InstanceGroup |
234+
| Compute | InstanceGroupInstance |
235+
| Compute | InstanceGroupManager |
236+
| Compute | InstanceGroupManager |
237+
| Compute | InstanceTemplate |
238+
| Compute | MachineType |
239+
| Compute | ManagedInstance |
240+
| Compute | ManagedInstance |
241+
| Compute | Network |
242+
| Compute | NetworkEffectiveFirewalls |
243+
| Compute | Project |
244+
| Compute | SslPolicy |
245+
| Compute | Subnetwork |
246+
| Compute | TargetHttpProxy |
247+
| Compute | TargetHttpsProxy |
248+
| Compute | TargetPool |
249+
| Compute | TargetSslProxy |
250+
| Compute | TargetTcpProxy |
251+
| Compute | UrlMap |
252+
| Container | Cluster |
253+
| Dns | ManagedZone |
254+
| Dns | Policy |
255+
| IAM | OrganizationRole |
256+
| IAM | ProjectRole |
257+
| IAM | Role |
258+
| IAM | ServiceAccount |
259+
| IAM | ServiceAccountKey |
260+
| Internal | GcpSecurityConnector |
261+
| Logging | AncestorLogSink |
262+
| Logging | LogEntry |
263+
| Logging | LogMetric |
264+
| Logging | LogSink |
265+
| Monitoring | AlertPolicy |
266+
| OsConfig | OSPolicyAssignment |
267+
| OsConfig | OSPolicyAssignmentReport |
268+
| SQLAdmin | DatabaseInstance |
269+
| SecretManager | Secret |
270+
| SecretManager | SecretPolicy |
271+
| Storage | Bucket |
272+
| Storage | BucketPolicy |
273+
274+
## Learn More
275+
276+
- Review the [features supported in Azure cloud environments](support-matrix-cloud-environment.md) for information on commercial and national cloud coverage.
277+
- Watch [Predict future security incidents! Cloud Security Posture Management with Microsoft Defender](https://www.youtube.com/watch?v=jF3NSR_OepI).
278+
- Learn about [security standards and recommendations](security-policy-concept.md).
279+
- Learn about [secure score](secure-score-security-controls.md).

0 commit comments

Comments
 (0)