Skip to content

Commit bcc0c19

Browse files
committed
Merge branch 'wi252753-permission-management-ciem' of https://github.com/ElazarK/azure-docs-pr into wi252753-permission-management-ciem
2 parents 4853d71 + 72a972f commit bcc0c19

File tree

1 file changed

+22
-0
lines changed

1 file changed

+22
-0
lines changed

articles/defender-for-cloud/enable-permissions-management.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,14 @@ When Permission Management (CIEM) is disabled, the CIEM recommendations within t
5050

5151
The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
5252

53+
List of Azure recommendations:
54+
55+
- Azure overprovisioned identities should have only the necessary permissions
56+
57+
- Unused identities in your Azure environment should be revoked/removed
58+
59+
- Super identities in your Azure environment should be revoked/removed
60+
5361
## Enable permissions management (CIEM) for AWS
5462

5563
When you enabled the Defender CSPM plan on your AWS account, the **AWS CSPM** [standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The AWS CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
@@ -87,6 +95,12 @@ When Permission Management is disabled, the CIEM recommendations within the AWS
8795

8896
The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
8997

98+
List of AWS recommendations:
99+
100+
- AWS overprovisioned identities should have only the necessary permissions
101+
102+
- Unused identities in your Azure environment should be revoked/removed
103+
90104
## Enable permissions management (CIEM) for GCP
91105

92106
When you enabled the Defender CSPM plan on your GCP project, the **GCP CSPM** [standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The GCP CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
@@ -127,6 +141,14 @@ When Permission Management (CIEM) is disabled, the CIEM recommendations within t
127141

128142
The applicable permissions management **(CIEM)** recommendations appear on your subscription within a few hours.
129143

144+
List of GCP recommendations:
145+
146+
- GCP overprovisioned identities should have only necessary permissions
147+
148+
- Unused identities in your GCP environment should be revoked/removed
149+
150+
- Super identities in your GCP environment should be revoked/removed
151+
130152
## Next step
131153

132154
> [!div class="nextstepaction"]

0 commit comments

Comments
 (0)