You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/enable-permissions-management.md
+13-13Lines changed: 13 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ ms.date: 03/10/2024
8
8
#customer intent: As a cloud administrator, I want to learn how to enable permissions management in order to effectively manage user access and entitlements in my cloud infrastructure.
9
9
---
10
10
11
-
# Enable permissions management
11
+
# Enable permissions management (CIEM)
12
12
13
13
Microsoft Defender for Cloud's integration with Microsoft Entra Permissions Management provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
14
14
@@ -24,11 +24,11 @@ Microsoft Defender for Cloud's integration with Microsoft Entra Permissions Mana
24
24
25
25
-**GCP only**: [Connect your GCP project to Defender for Cloud](quickstart-onboard-gcp.md).
26
26
27
-
## Enable permissions management for Azure
27
+
## Enable permissions management (CIEM) for Azure
28
28
29
29
When you enabled the Defender CSPM plan on your Azure account, the **Azure CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The Azure CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
30
30
31
-
When Permission Management is disabled, the CIEM recommendations within the Azure CSPM standard won’t be calculated.
31
+
When Permission Management (CIEM) is disabled, the CIEM recommendations within the Azure CSPM standard won’t be calculated.
32
32
33
33
1. Sign in to the [Azure portal](https://portal.azure.com).
34
34
@@ -40,17 +40,17 @@ When Permission Management is disabled, the CIEM recommendations within the Azur
40
40
41
41
1. Locate the Defender CSPM plan and select **Settings**.
42
42
43
-
1. Enable **Permissions Management**.
43
+
1. Enable **Permissions Management (CIEM)**.
44
44
45
45
:::image type="content" source="media/enable-permissions-management/permissions-management-on.png" alt-text="Screenshot that shows you where the toggle is for the permissions management is located." lightbox="media/enable-permissions-management/permissions-management-on.png":::
46
46
47
47
1. Select **Continue**.
48
48
49
49
1. Select **Save**.
50
50
51
-
The applicable permissions management recommendations appear on your subscription within a few hours.
51
+
The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
52
52
53
-
## Enable permissions management for AWS
53
+
## Enable permissions management (CIEM) for AWS
54
54
55
55
When you enabled the Defender CSPM plan on your AWS account, the **AWS CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The AWS CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
56
56
When Permission Management is disabled, the CIEM recommendations within the AWS CSPM standard won’t be calculated.
@@ -67,7 +67,7 @@ When Permission Management is disabled, the CIEM recommendations within the AWS
67
67
68
68
:::image type="content" source="media/enable-permissions-management/settings.png" alt-text="Screenshot that shows an AWS account and the Defender CSPM plan enabled and where the settings button is located." lightbox="media/enable-permissions-management/settings.png":::
69
69
70
-
1. Enable **Permissions Management**.
70
+
1. Enable **Permissions Management (CIEM)**.
71
71
72
72
1. Select **Configure access**.
73
73
@@ -85,19 +85,19 @@ When Permission Management is disabled, the CIEM recommendations within the AWS
85
85
86
86
1. Select **Update**.
87
87
88
-
The applicable permissions management recommendations appear on your subscription within a few hours.
88
+
The applicable permissions management (CIEM) recommendations appear on your subscription within a few hours.
89
89
90
-
## Enable permissions management for GCP
90
+
## Enable permissions management (CIEM) for GCP
91
91
92
92
When you enabled the Defender CSPM plan on your GCP project, the **GCP CSPM**[standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The GCP CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
93
93
94
94
When Permission Management is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated.
1. Sign in to the [Azure portal](https://portal.azure.com).
99
99
100
-
1. Search for and select **Microsoft Defender for Cloud**.
100
+
1. Search for and select **Microsoft Defender for Cloud**.
101
101
102
102
1. Navigate to **Environment settings**.
103
103
@@ -107,7 +107,7 @@ When Permission Management is disabled, the CIEM recommendations within the GCP
107
107
108
108
:::image type="content" source="media/enable-permissions-management/settings-google.png" alt-text="Screenshot that shows where to select settings for the Defender CSPM plan for your GCP project." lightbox="media/enable-permissions-management/settings-google.png":::
0 commit comments