Skip to content

Commit 72bb9f6

Browse files
authored
Merge pull request #274492 from ElazarK/wi252753-permission-management-ciem
added CIEM
2 parents 5485a14 + bcc0c19 commit 72bb9f6

File tree

4 files changed

+33
-13
lines changed

4 files changed

+33
-13
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -211,7 +211,7 @@
211211
href: concept-easm.md
212212
- name: Critical assets protection
213213
href: critical-assets-protection.md
214-
- name: Permissions management
214+
- name: Permissions management (CIEM)
215215
displayName: permissions, management, role-based access control, RBAC, azure, azure ad, active directory
216216
href: permissions-management.md
217217
- name: Agentless machine scanning
@@ -322,7 +322,7 @@
322322
- name: Integrate security solutions
323323
displayName: security, solutions, integrate, integrated, data sources
324324
href: partner-integration.md
325-
- name: Enable permissions management
325+
- name: Enable permissions management (CIEM)
326326
displayName: permissions, management, role-based access control, RBAC, azure, azure ad, active directory
327327
href: enable-permissions-management.md
328328
- name: AI security posture

articles/defender-for-cloud/concept-cloud-security-posture-management.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Cloud Security Posture Management (CSPM)
33
description: Learn more about Cloud Security Posture Management (CSPM) in Microsoft Defender for Cloud and how it helps improve your security posture.
44
ms.topic: concept-article
5-
ms.date: 05/06/2024
5+
ms.date: 05/07/2024
66
#customer intent: As a reader, I want to understand the concept of Cloud Security Posture Management (CSPM) in Microsoft Defender for Cloud.
77
---
88

articles/defender-for-cloud/enable-permissions-management.md

Lines changed: 26 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
---
2-
title: Enable permissions management
2+
title: Enable permissions management (CIEM)
33
author: Elazark
44
ms.author: elkrieger
55
description: Learn how to enable permissions management for better access control and security in your cloud infrastructure.
66
ms.topic: how-to
7-
ms.date: 03/10/2024
8-
#customer intent: As a cloud administrator, I want to learn how to enable permissions management in order to effectively manage user access and entitlements in my cloud infrastructure.
7+
ms.date: 05/07/2024
8+
#customer intent: As a cloud administrator, I want to learn how to enable permissions (CIEM) in order to effectively manage user access and entitlements in my cloud infrastructure.
99
---
1010

1111
# Enable permissions management (CIEM)
@@ -50,6 +50,14 @@ When Permission Management (CIEM) is disabled, the CIEM recommendations within t
5050

5151
The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
5252

53+
List of Azure recommendations:
54+
55+
- Azure overprovisioned identities should have only the necessary permissions
56+
57+
- Unused identities in your Azure environment should be revoked/removed
58+
59+
- Super identities in your Azure environment should be revoked/removed
60+
5361
## Enable permissions management (CIEM) for AWS
5462

5563
When you enabled the Defender CSPM plan on your AWS account, the **AWS CSPM** [standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The AWS CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
@@ -87,13 +95,17 @@ When Permission Management is disabled, the CIEM recommendations within the AWS
8795

8896
The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
8997

98+
List of AWS recommendations:
99+
100+
- AWS overprovisioned identities should have only the necessary permissions
101+
102+
- Unused identities in your Azure environment should be revoked/removed
103+
90104
## Enable permissions management (CIEM) for GCP
91105

92106
When you enabled the Defender CSPM plan on your GCP project, the **GCP CSPM** [standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The GCP CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
93107

94-
When Permission Management is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated.
95-
96-
**To enable permissions management** **(CIEM)** **for GCP**:
108+
When Permission Management (CIEM) is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated.
97109

98110
1. Sign in to the [Azure portal](https://portal.azure.com).
99111

@@ -129,6 +141,14 @@ When Permission Management is disabled, the CIEM recommendations within the GCP
129141

130142
The applicable permissions management **(CIEM)** recommendations appear on your subscription within a few hours.
131143

144+
List of GCP recommendations:
145+
146+
- GCP overprovisioned identities should have only necessary permissions
147+
148+
- Unused identities in your GCP environment should be revoked/removed
149+
150+
- Super identities in your GCP environment should be revoked/removed
151+
132152
## Next step
133153

134154
> [!div class="nextstepaction"]

articles/defender-for-cloud/permissions-management.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
2-
title: Permissions management
3-
description: Learn about permissions management in Microsoft Defender for Cloud and enhance the security of your cloud infrastructure.
2+
title: Permissions management (CIEM)
3+
description: Learn about permissions (CIEM) in Microsoft Defender for Cloud and enhance the security of your cloud infrastructure.
44
ms.topic: concept-article
55
author: Elazark
66
ms.author: elkrieger
@@ -10,9 +10,9 @@ ms.date: 03/07/2024
1010

1111
# Permissions management (CIEM)
1212

13-
Microsoft Defender for Cloud's integration with Microsoft [Microsoft Entra Permissions Management (CIEM)](/entra/permissions-management/overview) provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
13+
Microsoft Defender for Cloud's integration with Microsoft [Microsoft Entra Permissions Management](/entra/permissions-management/overview) provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
1414

15-
Integrating Entra Permissions Management (CIEM) with Defender for Cloud (CNAPP) strengthens cloud security by preventing security breaches caused by excessive permissions or misconfigurations. Permissions management (CIEM) continuously monitors and manages cloud entitlements, helping to discover attack surfaces, detect threats, right-size access permissions, and maintain compliance. This integration enhances the capabilities of Defender for Cloud in securing cloud-native applications and protecting sensitive data.
15+
Integrating Entra Permissions Management with Defender for Cloud (CNAPP) strengthens cloud security by preventing security breaches caused by excessive permissions or misconfigurations. Permissions management continuously monitors and manages cloud entitlements, helping to discover attack surfaces, detect threats, right-size access permissions, and maintain compliance. This integration enhances the capabilities of Defender for Cloud in securing cloud-native applications and protecting sensitive data.
1616

1717
This integration brings the following insights derived from the Microsoft Entra Permissions Management suite into the Microsoft Defender for Cloud portal. For more information, see the [feature matrix](#feature-matrix).
1818

0 commit comments

Comments
 (0)