π Azure Subscription Microsoft Defender For Azure Cosmos DB is not set to On π’
- Contextual name: π Microsoft Defender For Azure Cosmos DB is not set to On π’
- ID:
/ce/ca/azure/subscription/microsoft-defender-for-cosmos-db
- Located in: π Azure Subscription
Flagsβ
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
Our Metadataβ
- Policy Type:
COMPLIANCE_POLICY
- Policy Category:
SECURITY
Logicβ
- π§ prod.logic.yaml π’
Descriptionβ
Descriptionβ
Microsoft Defender for Azure Cosmos DB scans all incoming network requests for threats to your Azure Cosmos DB resources.
Rationaleβ
In scanning Azure Cosmos DB requests within a subscription, requests are compared to a heuristic list of potential security threats. These threats could be a result of a security breach within your services, thus scanning for them could prevent a potential security threat from being introduced.
Impactβ
Enabling Microsoft Defender for Azure Cosmos DB requires enabling Microsoft Defender for your subscription. Both will incur additional charges.
Auditβ
From Azure Portalβ
- Go to
Microsoft Defender for Cloud
.- Under
Management
, selectEnvironment Settings
.- Click on the subscription name.
- Select the
Defender plans
blade.- On the
Database
row click onSelect types >
.- Ensure the toggle switch next to
Azure Cosmos DB
is set toOn
.From Azure CLIβ
Ensure the output of the below command is
Standard
:az security pricing show -n CosmosDbs --query pricingTier
... [see more](description.md)
Remediationβ
Remediationβ
From Azure Portalβ
- Go to
Microsoft Defender for Cloud
.- Under
Management
, selectEnvironment Settings
.- Click on the subscription name.
- Select the
Defender plans
blade.- On the
Database
row click onSelect types >
.- Set the toggle switch next to
Azure Cosmos DB
toOn
.- Click
Continue
.- Click
Save
.From Azure CLIβ
Run the following command:
az security pricing create -n 'CosmosDbs' --tier 'standard'
From PowerShellβ
Use the below command to enable Standard pricing tier for Azure Cosmos DB:
Set-AzSecurityPricing -Name 'CosmosDbs' -PricingTier 'Standard
policy.yamlβ
Linked Framework Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ CIS Azure v2.1.0 β πΌ 2.1.6 Ensure That Microsoft Defender for Azure Cosmos DB Is Set To 'On' - Level 2 (Automated) | 1 | |||
πΌ CIS Azure v3.0.0 β πΌ 3.1.7.1 Ensure That Microsoft Defender for Azure Cosmos DB Is Set To 'On' (Automated) | 1 | |||
πΌ Cloudaware Framework β πΌ Microsoft Defender Configuration | 26 |