Skip to content

Commit e15c204

Browse files
committed
added CIEM
1 parent e4bfa71 commit e15c204

File tree

4 files changed

+13
-15
lines changed

4 files changed

+13
-15
lines changed

articles/defender-for-cloud/TOC.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -211,7 +211,7 @@
211211
href: concept-easm.md
212212
- name: Critical assets protection
213213
href: critical-assets-protection.md
214-
- name: Permissions management
214+
- name: Permissions management (CIEM)
215215
displayName: permissions, management, role-based access control, RBAC, azure, azure ad, active directory
216216
href: permissions-management.md
217217
- name: Agentless machine scanning
@@ -322,7 +322,7 @@
322322
- name: Integrate security solutions
323323
displayName: security, solutions, integrate, integrated, data sources
324324
href: partner-integration.md
325-
- name: Enable permissions management
325+
- name: Enable permissions management (CIEM)
326326
displayName: permissions, management, role-based access control, RBAC, azure, azure ad, active directory
327327
href: enable-permissions-management.md
328328
- name: AI security posture

articles/defender-for-cloud/concept-cloud-security-posture-management.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Cloud Security Posture Management (CSPM)
33
description: Learn more about Cloud Security Posture Management (CSPM) in Microsoft Defender for Cloud and how it helps improve your security posture.
44
ms.topic: concept-article
5-
ms.date: 04/15/2024
5+
ms.date: 05/07/2024
66
#customer intent: As a reader, I want to understand the concept of Cloud Security Posture Management (CSPM) in Microsoft Defender for Cloud.
77
---
88

@@ -48,7 +48,7 @@ The following table summarizes each plan and their cloud availability.
4848
| [Container registries vulnerability assessment](concept-agentless-containers.md), including registry scanning | - | :::image type="icon" source="./media/icons/yes-icon.png"::: | Azure, AWS, GCP |
4949
| [Data aware security posture](concept-data-security-posture.md) | - | :::image type="icon" source="./media/icons/yes-icon.png"::: | Azure, AWS, GCP |
5050
| EASM insights in network exposure | - | :::image type="icon" source="./media/icons/yes-icon.png"::: | Azure, AWS, GCP |
51-
| [Permissions management (Preview)](enable-permissions-management.md) | - | :::image type="icon" source="./media/icons/yes-icon.png"::: | Azure, AWS, GCP |
51+
| [Permissions management (CIEM)](enable-permissions-management.md) | - | :::image type="icon" source="./media/icons/yes-icon.png"::: | Azure, AWS, GCP |
5252

5353
> [!NOTE]
5454
> Starting March 7, 2024, Defender CSPM must be enabled to have premium DevOps security capabilities that include code-to-cloud contextualization powering security explorer and attack paths and pull request annotations for Infrastructure-as-Code security findings. See DevOps security [support and prerequisites](devops-support.md) to learn more.

articles/defender-for-cloud/enable-permissions-management.md

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
---
2-
title: Enable permissions management
2+
title: Enable permissions management (CIEM)
33
author: Elazark
44
ms.author: elkrieger
55
description: Learn how to enable permissions management for better access control and security in your cloud infrastructure.
66
ms.topic: how-to
7-
ms.date: 03/10/2024
8-
#customer intent: As a cloud administrator, I want to learn how to enable permissions management in order to effectively manage user access and entitlements in my cloud infrastructure.
7+
ms.date: 05/07/2024
8+
#customer intent: As a cloud administrator, I want to learn how to enable permissions (CIEM) in order to effectively manage user access and entitlements in my cloud infrastructure.
99
---
1010

1111
# Enable permissions management (CIEM)
@@ -91,9 +91,7 @@ The applicable permissions management (CIEM) recommendations appear on your subs
9191

9292
When you enabled the Defender CSPM plan on your GCP project, the **GCP CSPM** [standard is automatically assigned to your subscription](concept-regulatory-compliance-standards.md). The GCP CSPM standard provides Cloud Infrastructure Entitlement Management (CIEM) recommendations.
9393

94-
When Permission Management is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated.
95-
96-
**To enable permissions management** **(CIEM)** **for GCP**:
94+
When Permission Management (CIEM) is disabled, the CIEM recommendations within the GCP CSPM standard won’t be calculated.
9795

9896
1. Sign in to the [Azure portal](https://portal.azure.com).
9997

articles/defender-for-cloud/permissions-management.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,18 @@
11
---
2-
title: Permissions management
3-
description: Learn about permissions management in Microsoft Defender for Cloud and enhance the security of your cloud infrastructure.
2+
title: Permissions management (CIEM)
3+
description: Learn about permissions (CIEM) in Microsoft Defender for Cloud and enhance the security of your cloud infrastructure.
44
ms.topic: concept-article
55
author: Elazark
66
ms.author: elkrieger
77
ms.date: 03/07/2024
88
#customer intent: As a user, I want to understand how to manage permissions effectively so that I can enhance the security of my cloud infrastructure.
99
---
1010

11-
# Permissions management
11+
# Permissions management (CIEM)
1212

13-
Microsoft Defender for Cloud's integration with Microsoft [Microsoft Entra Permissions Management (CIEM)](/entra/permissions-management/overview) provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
13+
Microsoft Defender for Cloud's integration with Microsoft [Microsoft Entra Permissions Management](/entra/permissions-management/overview) provides a Cloud Infrastructure Entitlement Management (CIEM) security model that helps organizations manage and control user access and entitlements in their cloud infrastructure. CIEM is a critical component of the Cloud Native Application Protection Platform (CNAPP) solution that provides visibility into who or what has access to specific resources. It ensures that access rights adhere to the principle of least privilege (PoLP), where users or workload identities, such as apps and services, receive only the minimum levels of access necessary to perform their tasks. CIEM also helps organizations to monitor and manage permissions across multiple cloud environments, including Azure, AWS, and GCP.
1414

15-
Integrating Entra Permissions Management (CIEM) with Defender for Cloud (CNAPP) strengthens cloud security by preventing security breaches caused by excessive permissions or misconfigurations. Permissions management continuously monitors and manages cloud entitlements, helping to discover attack surfaces, detect threats, right-size access permissions, and maintain compliance. This integration enhances the capabilities of Defender for Cloud in securing cloud-native applications and protecting sensitive data.
15+
Integrating Entra Permissions Management with Defender for Cloud (CNAPP) strengthens cloud security by preventing security breaches caused by excessive permissions or misconfigurations. Permissions management continuously monitors and manages cloud entitlements, helping to discover attack surfaces, detect threats, right-size access permissions, and maintain compliance. This integration enhances the capabilities of Defender for Cloud in securing cloud-native applications and protecting sensitive data.
1616

1717
This integration brings the following insights derived from the Microsoft Entra Permissions Management suite into the Microsoft Defender for Cloud portal. For more information, see the [feature matrix](#feature-matrix).
1818

0 commit comments

Comments
 (0)