Forum Discussion

spintov's avatar
spintov
Copper Contributor
Jun 16, 2022
Solved

Microsoft Azure Defender for Cloud Regulatory Compliance

Could you configure Microsoft Defender to monitor regulatory compliance by resource group (default) instead of by subscription level? Is this possible? All documentation on this points out that i...
  • Ash_Gardiner's avatar
    Ash_Gardiner
    Jun 22, 2022
    Hi spintov,
    You are correct that you can unassign the initiative at the Subscription level, which means at that point the assessments are happening at the RG level. If the initiative has not been assigned on RGs within the Subscription directly they should disappear from the compliance view because they are no longer in scope.
    My initial answer was black and white - saying that what you wanted could be done and how to do it. The more real world answer is that I don't have customers who managed compliance at the RG level directly as it does not scale well. I've seen exceptions where only a couple of RG need PCI-DSS compliance but if you want to apply an initiative to many RG's individually it's not very fun unless they cascade from a parent Subscription. If workloads need to be subject to PCI-DSS compliance for example, one solution is to place those workloads in a dedicated subscription, maintaining the initiative at the subscription level.
    Hopefully someone else in the community has another approach to recommend.
    Thanks, Ash

Resources