Ensure that Microsoft Defender for Cloud is enabled for all the cloud resources connected to the Azure Resource Manager (ARM).
By default, Microsoft Defender for Cloud is disabled for Azure Resource Manager (ARM). Defender for Cloud automatically monitors the resource management operations within your organization, regardless these operations are performed through the Azure Portal, Azure REST APIs, Azure Command Line Interface (CLI), or other Azure programmatic clients. The Microsoft Defender for Cloud service runs advanced security analytics to detect threats and alerts you when detects suspicious activity.
Audit
To determine if Microsoft Defender for Cloud is enabled for Azure Resource Manager (ARM), perform the following operations:
Remediation / Resolution
To enable Microsoft Defender for Cloud for resources managed with Azure Resource Manager (ARM), perform the following operations:
Turning on Microsoft Defender for Cloud for Azure Resource Manager incurs an additional cost per resource management operation.References
- Azure Official Documentation
- Microsoft Defender for Cloud documentation
- Microsoft Defender for Cloud overview
- Microsoft Defender for Cloud pricing
- Azure PowerShell Documentation
- az account list
- az account set
- az security pricing list
- az security pricing create