Continuously Export Microsoft Defender for Cloud Alerts and Recommendations via Policy
Published Jun 04 2020 08:48 AM 9,293 Views
Microsoft

The Continuous Export feature in Microsoft Defender for Cloud helps you to centralize the location (Event Hub or Log Analytics Workspace) to where the logs will be streamed. By default, the configuration for this feature is done on the subscription level, and this can be challenge for organizations that have multiple subscriptions and want to keep the same configuration across multiple subscriptions.

 

Implementation

There are two new Azure Policy definitions that you can leverage to deploy the Continuous Export. Follow the steps below to configure it:

 

1. Open Azure Policy dashboard in Azure.

2. Click Definitions in the left navigation pane

3. In the Search box, type export. Figure below has an example of those definitions:

 

Fig1.JPG

 

4. Let’s say you want to configure your Continuous Export for Alerts and Recommendations to be stored in a Log Analytics Workspace. Click Deploy export to Log Analytics workspace for Azure Security Center alerts and recommendations definition and the page below appears:

 

Fig2.JPG

 

5. Click Assign button.

6. In the Basics tab, select the Scope that you want to assign. If you want to use centralized management, make sure to assign this policy to the Management Group that has all subscriptions that you want to have the configuration. 

7 Click Parameters tab, and the options below will be available for you to customize:

Note: for the detail explanation on each parameter, you can also click on the tooltips (i) besides the parameter name.

 

Fig3.JPG

 

8. The Parameters here are the same ones that you configure in the Continuous Export UI. All parameters are mandatory, except Recommendation ID, which can be blank in case you want to export all recommendations.

9. Click Remediation tab and select the option to create a remediation task for existing subscriptions.

10. Review the summary page and click Create button.

 

To deploy this policy on newly created subscriptions, open the Compliance tab, select the relevant non-compliant assignment, and create a remediation task.

 

Make sure to take advantage of this policy to control the configuration of your Microsoft Defender for Cloud continuous export feature across different subscriptions.

 

Reviewers

Or Serok-Jeppa, Program Manager – Microsoft Defender for Cloud Engineering Team

Keren Shani, Software Engineer – Microsoft Defender for Cloud Engineering Team

 

Co-Authors
Version history
Last update:
‎Oct 28 2021 12:13 AM
Updated by: