🛡️ Azure Subscription Microsoft Defender For Azure Cosmos DB is not set to On🟢
- Contextual name: 🛡️ Microsoft Defender For Azure Cosmos DB is not set to On🟢
- ID:
/ce/ca/azure/subscription/microsoft-defender-for-cosmos-db - Tags:
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logic
Description
Description
Microsoft Defender for Azure Cosmos DB scans all incoming network requests for threats to your Azure Cosmos DB resources.
Rationale
In scanning Azure Cosmos DB requests within a subscription, requests are compared to a heuristic list of potential security threats. These threats could be a result of a security breach within your services, thus scanning for them could prevent a potential security threat from being introduced.
Impact
Enabling Microsoft Defender for Azure Cosmos DB requires enabling Microsoft Defender for your subscription. Both will incur additional charges.
Audit
This policy flags an Azure Subscription as
INCOMPLIANTif the relatedAzure Defender Planfor Cosmos DBs has itsPricing Tierset to Free.A Subscription is also marked as
INCOMPLIANTif theDefender Planfor Cosmos DBs does not exist in the CMDB.Default Value
By default, Microsoft Defender for Azure Cosmos DB is not enabled.
References
... see more
Remediation
Remediation
From Azure Portal
- Go to
Microsoft Defender for Cloud.- Under
Management, selectEnvironment Settings.- Click on the subscription name.
- Select the
Defender plansblade.- On the
Databaserow click onSelect types >.- Set the toggle switch next to
Azure Cosmos DBtoOn.- Click
Continue.- Click
Save.From Azure CLI
Run the following command:
az security pricing create -n 'CosmosDbs' --tier 'standard'From PowerShell
Use the below command to enable Standard pricing tier for Azure Cosmos DB:
Set-AzSecurityPricing -Name 'CosmosDbs' -PricingTier 'Standard
policy.yaml
Linked Framework Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 CIS Azure v2.1.0 → 💼 2.1.6 Ensure That Microsoft Defender for Azure Cosmos DB Is Set To 'On' - Level 2 (Automated) | 1 | no data | |||
| 💼 CIS Azure v3.0.0 → 💼 3.1.7.1 Ensure That Microsoft Defender for Azure Cosmos DB Is Set To 'On' (Automated) | 1 | no data | |||
| 💼 CIS Azure v4.0.0 → 💼 9.1.7.1 Ensure That Microsoft Defender for Azure Cosmos DB Is Set To 'On' (Automated) | 1 | no data | |||
| 💼 Cloudaware Framework → 💼 Microsoft Defender Configuration | 26 | no data |