🛡️ Azure Subscription Microsoft Defender For Open-Source Relational Databases is not set to On🟢
- Contextual name: 🛡️ Microsoft Defender For Open-Source Relational Databases is not set to On🟢
- ID:
/ce/ca/azure/subscription/microsoft-defender-for-open-source-relational-databases - Tags:
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logic
Description
Description
Turning on Microsoft Defender for Open-source relational databases enables threat detection for Open-source relational databases, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.
Rationale
Enabling Microsoft Defender for Open-source relational databases allows for greater defense-in-depth, with threat detection provided by the Microsoft Security Response Center (MSRC).
Impact
Turning on Microsoft Defender for Open-source relational databases incurs an additional cost per resource.
Audit
This policy flags an Azure Subscription as
INCOMPLIANTif the relatedAzure Defender Planfor Open Source Relational Databases has itsPricing Tierset to Free.A Subscription is also marked as
INCOMPLIANTif theDefender Planfor Open Source Relational Databases does not exist in the CMDB.Default Value
By default, Microsoft Defender plan is
off.References
... see more
Remediation
Remediation
From Azure Portal
- Go to
Microsoft Defender for Cloud.- Under
Management, selectEnvironment Settings.- Click on the subscription name.
- Select the
Defender plansblade.- Click
Select types >in the row forDatabases.- Set the toggle switch next to
Open-source relational databasestoOn.- Select
Continue.- Select
Save.From Azure CLI
Run the following command:
az security pricing create -n 'OpenSourceRelationalDatabases' --tier 'standard'From PowerShell
Use the below command to enable Standard pricing tier for Open-source relational databases:
set-azsecuritypricing -name "OpenSourceRelationalDatabases" -pricingtier "Standard"
policy.yaml
Linked Framework Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 CIS Azure v2.1.0 → 💼 2.1.5 Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To 'On' - Level 2 (Automated) | 1 | no data | |||
| 💼 CIS Azure v3.0.0 → 💼 3.1.7.2 Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To 'On' (Automated) | 1 | no data | |||
| 💼 CIS Azure v4.0.0 → 💼 9.1.7.2 Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To 'On' (Automated) | 1 | no data | |||
| 💼 Cloudaware Framework → 💼 Microsoft Defender Configuration | 26 | no data |