Skip to content

Commit 8693290

Browse files
Merge pull request #244893 from dcurwin/wi2-123292-improve-deploy-july13-2023
Improve Deploy section - Part 2
2 parents ad829bb + 937a29f commit 8693290

8 files changed

+37
-10
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -79,6 +79,9 @@
7979
href: tutorial-enable-container-aws.md
8080
- name: Protect your Google Cloud Platform (GCP) project containers
8181
href: tutorial-enable-container-gcp.md
82+
- name: How to enable Defender for Containers components
83+
displayName: kubernetes, aks, acr, registries, k8s, arc, hybrid, on-premises, azure arc, multicloud
84+
href: defender-for-containers-enable.md
8285
- name: Protect your key vaults with Defender for Key Vault
8386
displayName: enable, key, vault, key vault
8487
href: tutorial-enable-key-vault-plan.md
@@ -544,9 +547,6 @@
544547
- name: How does Defender for Containers work?
545548
displayName: containers
546549
href: defender-for-containers-architecture.md
547-
- name: Enable Defender for Containers
548-
displayName: kubernetes, aks, acr, registries, k8s, arc, hybrid, on-premises, azure arc, multicloud
549-
href: defender-for-containers-enable.md
550550
- name: Vulnerability assessment for Azure powered by Qualys
551551
displayName: ACR, registry, images, qualys
552552
href: defender-for-containers-vulnerability-assessment-azure.md

articles/defender-for-cloud/defender-for-containers-enable.md

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
title: How to enable Microsoft Defender for Containers
2+
title: How to enable Microsoft Defender for Containers components
33
description: Enable the container protections of Microsoft Defender for Containers
44
ms.topic: how-to
55
author: dcurwin
@@ -9,7 +9,7 @@ zone_pivot_groups: k8s-host
99
ms.date: 06/29/2023
1010
---
1111

12-
# Enable Microsoft Defender for Containers
12+
# How to enable Microsoft Defender for Containers components
1313

1414
Microsoft Defender for Containers is the cloud-native solution for securing your containers.
1515

@@ -25,7 +25,14 @@ Defender for Containers protects your clusters whether they're running in:
2525

2626
Learn about this plan in [Overview of Microsoft Defender for Containers](defender-for-containers-introduction.md).
2727

28-
You can learn more by watching these videos from the Defender for Cloud in the Field video series:
28+
You can first learn how to connect and protect your containers in these articles:
29+
30+
- [Protect your Azure containers with Defender for Containers](tutorial-enable-containers-azure.md)
31+
- [Protect your on-premises Kubernetes clusters with Defender for Containers](tutorial-enable-containers-arc.md)
32+
- [Protect your Amazon Web Service (AWS) accounts containers with Defender for Containers](tutorial-enable-container-aws.md)
33+
- [Protect your Google Cloud Platform (GCP) project containers with Defender for Containers](tutorial-enable-container-gcp.md)
34+
35+
You can also learn more by watching these videos from the Defender for Cloud in the Field video series:
2936

3037
- [Microsoft Defender for Containers in a multicloud environment](episode-nine.md)
3138
- [Protect Containers in GCP with Defender for Containers](episode-ten.md)

articles/defender-for-cloud/quickstart-onboard-aws.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -115,6 +115,10 @@ To connect your AWS to Defender for Cloud by using a native connector:
115115

116116
Optionally, select **Management account** to create a connector to a management account. Connectors are created for each member account discovered under the provided management account. Auto-provisioning is enabled for all of the newly onboarded accounts.
117117

118+
## Select Defender plans
119+
120+
In this section of the wizard, you select the Defender for Cloud plans that you want to enable.
121+
118122
1. Select **Next: Select plans**.
119123

120124
The **Select plans** tab is where you choose which Defender for Cloud capabilities to enable for this AWS account. Each plan has its own [requirements for permissions](concept-aws-connector.md#native-connector-plan-requirements) and might incur [charges](https://azure.microsoft.com/pricing/details/defender-for-cloud/?v=17.23h).

articles/defender-for-cloud/quickstart-onboard-gcp.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,10 @@ To connect your GCP project to Defender for Cloud by using a native connector:
5353

5454
Optionally, if you select **Organization**, a management project and an organization custom role are created on your GCP project for the onboarding process. Autoprovisioning is enabled for the onboarding of new projects.
5555

56+
## Select Defender plans
57+
58+
In this section of the wizard, you select the Defender for Cloud plans that you want to enable.
59+
5660
1. Select **Next: Select plans**.
5761

5862
1. For the plans that you want to connect, turn the toggle to **On**. By default, all necessary prerequisites and components are provisioned. [Learn how to configure each plan](#optional-configure-selected-plans).

articles/defender-for-cloud/tutorial-enable-container-aws.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,9 @@ You can learn more about Defender for Container's pricing on the [pricing page](
1919

2020
- You must [enable Microsoft Defender for Cloud](get-started.md#enable-defender-for-cloud-on-your-azure-subscription) on your Azure subscription.
2121

22-
- [Connect your AWS account to Microsoft Defender for Cloud](quickstart-onboard-aws.md)
22+
- [Connect your AWS account to Microsoft Defender for Cloud](quickstart-onboard-aws.md#connect-your-aws-account)
2323

24-
- Validate the following domains only if you're using a relevant OS. For example, if you have EKS clusters running in AWS, then you would only need to apply the `Amazon Linux 2 (Eks): Domain: "amazonlinux.*.amazonaws.com/2/extras/*"` domain.
24+
- Validate the following domains only if you're using a relevant OS.
2525

2626
| Domain | Port | Host operating systems |
2727
| -------------------------- | ---- |--|
@@ -62,6 +62,9 @@ To protect your EKS clusters, you need to enable the Containers plan on the rele
6262

6363
1. Select **Update**.
6464

65+
> [!NOTE]
66+
> To enable or disable individual Defender for Containers capabilities, either globally or for specific resources, see [How to enable Microsoft Defender for Containers components](defender-for-containers-enable.md).
67+
6568
## Deploy the Defender extension in Azure
6669

6770
Azure Arc-enabled Kubernetes, the Defender extension, and the Azure Policy extension should be installed and running on your EKS clusters. There's a dedicated Defender for Cloud recommendation that can be used to install these extensions (and Azure Arc if necessary):

articles/defender-for-cloud/tutorial-enable-container-gcp.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,9 @@ You can learn more about Defender for Container's pricing on the [pricing page](
1919

2020
- You must [enable Microsoft Defender for Cloud](get-started.md#enable-defender-for-cloud-on-your-azure-subscription) on your Azure subscription.
2121

22-
- [Connect your GCP projects to Microsoft Defender for Cloud](quickstart-onboard-gcp.md).
22+
- [Connect your GCP projects to Microsoft Defender for Cloud](quickstart-onboard-gcp.md#connect-your-gcp-project).
2323

24-
- Validate the following domains only if you're using a relevant OS. For example, if you have EKS clusters running in AWS, then you would only need to apply the `Amazon Linux 2 (Eks): Domain: "amazonlinux.*.amazonaws.com/2/extras/*"` domain.
24+
- Validate the following domains only if you're using a relevant OS.
2525

2626
| Domain | Port | Host operating systems |
2727
| -------------------------- | ---- |--|
@@ -65,6 +65,9 @@ You can learn more about Defender for Container's pricing on the [pricing page](
6565

6666
1. Select **Update**.
6767

68+
> [!NOTE]
69+
> To enable or disable individual Defender for Containers capabilities, either globally or for specific resources, see [How to enable Microsoft Defender for Containers components](defender-for-containers-enable.md).
70+
6871
## Deploy the solution to specific clusters
6972

7073
If you disabled any of the default auto provisioning configurations to Off, during the [GCP connector onboarding process](quickstart-onboard-gcp.md#configure-the-defender-for-containers-plan), or afterwards. You need to manually install Azure Arc-enabled Kubernetes, the Defender extension, and the Azure Policy extensions to each of your GKE clusters to get the full security value out of Defender for Containers.

articles/defender-for-cloud/tutorial-enable-containers-arc.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,9 @@ If you would prefer to [assign a custom workspace](defender-for-containers-enabl
5353

5454
1. Select **Save**.
5555

56+
> [!NOTE]
57+
> To enable or disable individual Defender for Containers capabilities, either globally or for specific resources, see [How to enable Microsoft Defender for Containers components](defender-for-containers-enable.md).
58+
5659
## Deploy the Defender extension on Arc-enabled Kubernetes clusters that were onboarded to an Azure subscription
5760

5861
You can enable the Defender for Containers plan and deploy all of the relevant components in different ways. We walk you through the steps to accomplish this using the Azure portal. Learn how to [deploy the Defender extension](/azure/defender-for-cloud/defender-for-containers-enable?pivots=defender-for-container-arc&tabs=aks-deploy-portal%2Ck8s-deploy-asc%2Ck8s-verify-asc%2Ck8s-remove-arc%2Caks-removeprofile-api#deploy-the-defender-extension) with REST API, Azure CLI or with a Resource Manager template.

articles/defender-for-cloud/tutorial-enable-containers-azure.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,9 @@ If you would prefer to [assign a custom workspace](/azure/defender-for-cloud/def
4646

4747
1. Select **Save**.
4848

49+
> [!NOTE]
50+
> To enable or disable individual Defender for Containers capabilities, either globally or for specific resources, see [How to enable Microsoft Defender for Containers components](defender-for-containers-enable.md).
51+
4952
## Deploy the Defender profile in Azure
5053

5154
You can enable the Defender for Containers plan and deploy all of the relevant components in different ways. We walk you through the steps to accomplish this using the Azure portal. Learn how to [deploy the Defender profile](defender-for-containers-enable.md#deploy-the-defender-profile) with REST API, Azure CLI or with a Resource Manager template.

0 commit comments

Comments
 (0)