Blog Post

Microsoft Entra Blog
3 MIN READ

CloudKnox Permissions Management is now in Public Preview

Alex_Simons's avatar
Alex_Simons
Icon for Microsoft rankMicrosoft
Feb 23, 2022

Last July we announced the acquisition of CloudKnox Security, a leader in Cloud Infrastructure Entitlement Management (CIEM). As an important move in our multicloud security vision, we have made tremendous progress integrating CloudKnox into our technology stack. Today, I’m excited to announce the public preview of CloudKnox Permissions Management, a unified CIEM solution that manages permissions of any identity across any cloud.

 

As I’m sure you’ve experienced, the explosion of identities and permissions across clouds has created new security challenges. IT teams lack visibility into identities and their permissions and struggle with ever increasing permission creep. These challenges require a comprehensive, unified solution for full visibility and risk remediation.  

 

Below is a rundown of how CloudKnox Permissions Management continuously monitors and remediates your permission risks to secure your critical cloud resources. If you'd like to learn more about CloudKnox Permissions Management, please visit our documentation.

 

Get a comprehensive view of your permission risk

CloudKnox Permissions Management offers detailed visibility into all identities and their permissions granted and permissions used, across your cloud infrastructure, so you can uncover any action performed by any identity on any resource. This is not limited to just user identities, but also includes workload identities such as virtual machines, access keys, containers, and scripts, across the three key cloud providers – Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. The dashboard gives you an overview of your organization’s permission profile to locate where the riskiest identities and resources are across your infrastructure. It leverages the Permission Creep Index, which is a single metric ranging from zero to 100 that calculates the gap between permissions granted and permissions used. The more unused actions and untouched resources, the higher the gap and the index.

 

You can easily pinpoint specific identities with a high Permission Creep Index and look at what permissions they are granted versus what they used, and what resources they can get to. This level of visibility is needed to identify where the highest risks are and remediate them.

 

Automate least privilege access

Once you identify the most critical permission risks across your infrastructure, CloudKnox Permissions Management allows you to right-size excessive permissions and automate least privilege policy enforcement. The solution continuously analyzes historical permission usage data for each identity and you can right-size permissions of that identity to only the permissions that are being used for day-to-day operations. All unused and other risky permissions can also be removed.

 

For any break glass or one-off scenarios where an identity needs to perform a certain set of actions on a set of specific resources, the identity can request those permissions on-demand for a limited period with a self-service workflow. The user experience is the same for any identity type (human or non-human), identity source (local, enterprise directory, or federated), and any cloud.

 

Streamline anomaly detection to accelerate incident response

To prevent privilege misuse and a potential data breach, machine learning-powered anomaly and outlier detection alerts will notify you in case of suspicious activity. You can also set up custom alert triggers for a specific set of actions or resources or any combination to automate your monitoring and perform incident response.

 

Another way you can monitor your infrastructure to support rapid remediation is by generating custom forensic reports. For example, the Permissions Analytics Report will generate a summary of key permission risks across your cloud environments. These reports can be customized to a target set of cloud accounts and delivered via email at pre-configured intervals.

 

 

CloudKnox Permissions Management is now available for Public Preview! To try CloudKnox Permissions Management, log into Azure AD and click on our tile. If you’d like to learn more, don’t miss Balaji Parimi and Joseph Dadzie’s speaking session with one of our customers at the “What’s Next in Security” event on February 24th.

 

Best regards,

Alex Simons (Twitter: @Alex_A_Simons)

Corporate Vice President

Microsoft Identity and Network Access Division

 

 

Learn more about Microsoft identity:

Updated Mar 23, 2022
Version 3.0

19 Comments

  • Nasos Kladakis we are actively searching for a tool and really need to get better information. It seems we cannot even get someone at the company that was acquired. 

    While I get the need for time, we also have the need for speed. [Sorry for the Top Gun reference] Any assistance in how we get someone is helpful. 

  • FarmKorn's avatar
    FarmKorn
    Copper Contributor

    Any third party integrations e.g. Jira, as most companies can't directly automated workflows without it first going through a ticketing approval process. This process can be automated as long as its approved through some pipeline. 

  • MWilliamsEnvision  we will be able to share pricing and our plans to expand to additional clouds soon. Give us some time and this information will become publicly available! Thank you for your patience and the feedback. 

    Nasos

  • It would be great to understand pricing and options to extend beyond Azure, AWS, and Google cloud services. I'd love a reporting tool that shows me into 365 and on prem. I could elaborate and say even tools beyond this. But for now, these would be hot issues for our team. 

    It seems we are not able to get the pricing easily... Preview is nice but who do we have good conversations about the future?

  •  
     "Is there any ability (or intent) to use this to extend into on-premises infrastructure, at least for Active Directory permissions and Windows local accounts?"
     Not currently nor in the short term. But we are always open to feedback and thank you for your comment. 

     

  • TJBanasik's avatar
    TJBanasik
    Former Employee

    Outstanding work team! How can we onboard this data to Microsoft Sentinel?

  • arnavarr175's avatar
    arnavarr175
    Copper Contributor

    Thanks!!!!

    Will Azure ARC bring at least part of those capabilities to on-premises?

      

    BR

  • NadeemAkh's avatar
    NadeemAkh
    Copper Contributor

    Great to see this announcement, really pleased. It will be interesting to see how integration will work with existing MS IAM Product set and CloudKnox capabilities, specifically in AWS context. One more interesting observation is that we are not calling it a "PAM" product which is a right step forward 🙂 

  • Graham_Gold's avatar
    Graham_Gold
    Copper Contributor

    Is there any ability (or intent) to use this to extend into on-premises infrastructure, at least for Active Directory permissions and Windows local accounts?