Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
You can enable data security posture management in Microsoft Defender for Cloud. Data security posture management helps you discover and classify sensitive data, identify risks, and prioritize remediation.
When you enable Microsoft Defender Cloud Security Posture Management or Defender for Storage plans, the sensitive data discovery extension is automatically enabled. You can disable this setting if you don't want to use data security posture management. We recommend that you use the feature to get the most value from Defender for Cloud.
Defender for Cloud identifies sensitive data based on the data sensitivity settings. You can customize the data sensitivity settings to identify the data that your organization considers sensitive.
It takes up to 24 hours to see the results of a first discovery after enabling the feature.
Prerequisites
Review the following prerequisites before you enable data security posture management:
- Before you enable data security posture management, review support and prerequisites.
Enable in Defender CSPM (Azure)
Follow these steps to enable data security posture management.
Go to Microsoft Defender for Cloud > Environment settings.
Select the relevant Azure subscription.
For the Defender CSPM plan, select the On status.
If Defender CSPM is already on, select Settings in the Monitoring coverage column of the Defender CSPM plan and make sure that the Sensitive data discovery component is set to On.
After sensitive data discovery is turned On in Defender CSPM, it automatically incorporates support for additional resource types as the range of supported resource types expands.
Enable in Defender CSPM (AWS)
Follow these steps to enable data security posture management for your AWS resources. Review the prerequisites and then configure scanning for your S3 buckets and RDS instances.
Before you start in AWS
Complete the following checks before you enable data security posture management for Amazon Web Services (AWS):
- Review AWS discovery requirements and required permissions for S3 and RDS scanning.
- Check that there's no policy that blocks the connection to your Amazon S3 buckets.
- For Amazon Relational Database Service (RDS) instances, cross-account AWS Key Management Service (KMS) encryption is supported, but additional KMS access policies might prevent access.
Enable for AWS resources
After you complete the prerequisites, configure scanning for your AWS resources.
Configure S3 buckets and RDS instances
To enable scanning for S3 buckets and RDS instances:
- In Defender for Cloud, go to Environment settings and select your AWS connector.
- Turn on Defender CSPM with Sensitive data discovery.
- Follow the instructions to download the CloudFormation template and run it in AWS.
Discovery of S3 buckets in the AWS account starts automatically.
For S3 buckets, the Defender for Cloud scanner runs in your AWS account and connects to your S3 buckets.
For RDS instances, when Sensitive Data Discovery is turned on, discovery begins. The scanner takes the latest automated snapshot for an instance, creates a manual snapshot in the source account, and copies it to an isolated Microsoft-owned environment in the same region.
The scanner uses the snapshot to create a live instance that it spins up, scans, and then immediately destroys, along with the copied snapshot.
The scanning platform reports only scan findings.
Check for S3 blocking policies
If enabling scanning for S3 buckets and RDS instances didn't work because of a blocked policy, check the following conditions:
- Ensure that the S3 bucket policy doesn't block the connection. In the AWS S3 bucket, select the Permissions tab, then Bucket policy. Check the policy details to ensure the Defender for Cloud scanner service running in the Microsoft account in AWS isn't blocked.
- Ensure that there's no SCP policy that blocks the connection to the S3 bucket. For example, your SCP policy might block read API calls to the AWS Region where your S3 bucket is hosted.
- Check that your SCP policy allows these required API calls: AssumeRole, GetBucketLocation, GetObject, ListBucket, and GetBucketPublicAccessBlock.
- Check that your SCP policy allows calls to the
us-east-1AWS Region, which is the default region for API calls.
Enable data-aware monitoring in Defender for Storage
Sensitive data threat detection is enabled by default when the sensitive data discovery component is enabled in the Defender for Storage plan. For more information, see Sensitive data threat detection in Defender for Storage.
Note
If you turn off Defender CSPM, only Azure Storage resources are scanned.