|
1 | 1 | ---
|
2 |
| -title: Enable permissions management |
| 2 | +title: Enable permissions management (CIEM) |
3 | 3 | author: Elazark
|
4 | 4 | ms.author: elkrieger
|
5 | 5 | description: Learn how to enable permissions management for better access control and security in your cloud infrastructure.
|
6 | 6 | ms.topic: how-to
|
7 |
| -ms.date: 03/10/2024 |
8 |
| -#customer intent: As a cloud administrator, I want to learn how to enable permissions management in order to effectively manage user access and entitlements in my cloud infrastructure. |
| 7 | +ms.date: 05/07/2024 |
| 8 | +#customer intent: As a cloud administrator, I want to learn how to enable permissions (CIEM) in order to effectively manage user access and entitlements in my cloud infrastructure. |
9 | 9 | ---
|
10 | 10 |
|
11 | 11 | # Enable permissions management (CIEM)
|
@@ -50,6 +50,14 @@ When Permission Management (CIEM) is disabled, the CIEM recommendations within t
|
50 | 50 |
|
51 | 51 | The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
|
52 | 52 |
|
| 53 | +List of Azure recommendations: |
| 54 | + |
| 55 | +- Azure overprovisioned identities should have only the necessary permissions |
| 56 | + |
| 57 | +- Unused identities in your Azure environment should be revoked/removed |
| 58 | + |
| 59 | +- Super identities in your Azure environment should be revoked/removed |
| 60 | + |
53 | 61 | ## Enable permissions management (CIEM) for AWS
|
54 | 62 |
|
55 | 63 | When you enabled the Defender CSPM plan on your AWS account, the **AWS CSPM** [standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The AWS CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
|
@@ -87,13 +95,17 @@ When Permission Management is disabled, the CIEM recommendations within the AWS
|
87 | 95 |
|
88 | 96 | The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
|
89 | 97 |
|
| 98 | +List of AWS recommendations: |
| 99 | + |
| 100 | +- AWS overprovisioned identities should have only the necessary permissions |
| 101 | + |
| 102 | +- Unused identities in your Azure environment should be revoked/removed |
| 103 | + |
90 | 104 | ## Enable permissions management (CIEM) for GCP
|
91 | 105 |
|
92 | 106 | When you enabled the Defender CSPM plan on your GCP project, the **GCP CSPM** [standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The GCP CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
|
93 | 107 |
|
94 |
| -When Permission Management is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated. |
95 |
| - |
96 |
| -**To enable permissions management** **(CIEM)** **for GCP**: |
| 108 | +When Permission Management (CIEM) is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated. |
97 | 109 |
|
98 | 110 | 1. Sign in to the [Azure portal](https://portal.azure.com).
|
99 | 111 |
|
@@ -129,6 +141,14 @@ When Permission Management is disabled, the CIEM recommendations within the GCP
|
129 | 141 |
|
130 | 142 | The applicable permissions management **(CIEM)** recommendations appear on your subscription within a few hours.
|
131 | 143 |
|
| 144 | +List of GCP recommendations: |
| 145 | + |
| 146 | +- GCP overprovisioned identities should have only necessary permissions |
| 147 | + |
| 148 | +- Unused identities in your GCP environment should be revoked/removed |
| 149 | + |
| 150 | +- Super identities in your GCP environment should be revoked/removed |
| 151 | + |
132 | 152 | ## Next step
|
133 | 153 |
|
134 | 154 | > [!div class="nextstepaction"]
|
|
0 commit comments