Planning your Multi-Cloud Adoption with Azure Defender

Published 04-27-2021 02:41 PM 1,832 Views
Microsoft

According to a recent study, cloud misconfigurations take an average 25 days to fix. This number can even be higher if you are managing the cloud security posture across multiple providers without having an aggregate visualization of the current security state of all cloud workloads. Not only it becomes a challenge to understand the current security state, but also to manage multiple dashboards and prioritize which issues should be resolved first.

When you upgrade Azure Security Center free tier to Azure Defender you will be able to connect to AWS and GCP using native Azure Defender connectors. Once you connect to each cloud provider, you will be able to use the Security Recommendations to quickly filter the environment and see only the recommendations that are relevant for the cloud provider that you want, as shown below:

 

Fig1.JPG

 

You can also quickly identify resources on each cloud provider by using the Inventory dashboard, by using the Cloud Environment filter as shown below:

 

Fig2.JPG

 

 

In addition to all that, you can also take advantage of centralized automation by leveraging the Workflow Automation feature to automate response for security recommendations generated in Azure, AWS or GCP.

 

Cloud security posture management and workload protection

The security recommendations are relevant for the cloud security posture management scenario, which means that you drive the enhancement of your security posture across multiple cloud providers by remediating those recommendations. However, this is not the only scenario available for multi-cloud, you can also use the following Azure Defender plans to enhance your workload protection. When planning cloud workload protection for workloads in AWS and GCP, make sure to first enable the VMs to use Azure Arc, once you do that, the following Azure Defender plans will be available across Azure, AWS and GCP:

The potential alerts generated by workloads protected by those plans is going to be surfaced in the Security Alerts dashboard in Azure Defender. Which means that you again will have a single dashboard to visualize alerts across different cloud providers. These alerts can be streamed to your SIEM platform using Continuous Export feature in Azure Security Center.

 

Design considerations

Prior to implementing your multi-cloud adoption using Azure Defender, it is important to consider the following aspects:

 

When connecting with AWS

  • An account is onboarded to a subscription, the subscription has to have Azure Defender for Servers enabled
  • The VMs under this account will automatically be onboarded to Azure using Azure Arc, and will be covered by Defender (list of supported OS)
  • Arc cost is inclusive with Defender (you won’t pay twice)
  • To receive the security recommendations,  you will need to enable AWS Security Hub on the accounts you want to onboard
  • Security Hub is a paid service that can vary depending on how many accounts and regions it’s enabled on (please refer to AWS official pricing)

 

When connecting with GCP

  • Same requirement for Defender enabled on the subscription
  • Servers are not onboarded automatically, and will need to be onboarded through Arc (Arc onboarding guide)
  • To receive security recommendations, you will need to enable GCP Security Command Center
  • Google Security Command Center have two pricing tiers: standard (free) and premium
  • Free tier includes ~12 recommendations, premium around 120
  • Premium tier costs 5% of annual spending in GCP, please refer to GCP official pricing)

 

Additional Resources

The resources below will be useful for you to implement this multi-cloud capability in Azure Defender:

 

 

Reviewer

Or Serok Jeppa, Program Manager

 

 

%3CLINGO-SUB%20id%3D%22lingo-sub-2299747%22%20slang%3D%22en-US%22%3EPlanning%20your%20Multi-Cloud%20Adoption%20with%20Azure%20Defender%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2299747%22%20slang%3D%22en-US%22%3E%3CP%3EAccording%20to%20a%20%3CA%20href%3D%22https%3A%2F%2Fbetanews.com%2F2021%2F02%2F22%2Fcloud-misconfigurations-25-days-fix%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Erecent%20study%3C%2FA%3E%2C%20cloud%20misconfigurations%20take%20an%20average%2025%20days%20to%20fix.%20This%20number%20can%20even%20be%20higher%20if%20you%20are%20managing%20the%20cloud%20security%20posture%20across%20multiple%20providers%20without%20having%20an%20aggregate%20visualization%20of%20the%20current%20security%20state%20of%20all%20cloud%20workloads.%20Not%20only%20it%20becomes%20a%20challenge%20to%20understand%20the%20current%20security%20state%2C%20but%20also%20to%20manage%20multiple%20dashboards%20and%20prioritize%20which%20issues%20should%20be%20resolved%20first.%3C%2FP%3E%0A%3CP%3EWhen%20you%20upgrade%20Azure%20Security%20Center%20free%20tier%20to%20Azure%20Defender%20you%20will%20be%20able%20to%20connect%20to%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fquickstart-onboard-aws%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAWS%3C%2FA%3E%20and%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fquickstart-onboard-gcp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EGCP%3C%2FA%3E%20using%20native%20Azure%20Defender%20connectors.%20Once%20you%20connect%20to%20each%20cloud%20provider%2C%20you%20will%20be%20able%20to%20use%20the%20%3CEM%3ESecurity%20Recommendations%3C%2FEM%3E%20to%20quickly%20filter%20the%20environment%20and%20see%20only%20the%20recommendations%20that%20are%20relevant%20for%20the%20cloud%20provider%20that%20you%20want%2C%20as%20shown%20below%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Fig1.JPG%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F276104i78AF6297D4A8AE5C%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Fig1.JPG%22%20alt%3D%22Fig1.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20can%20also%20quickly%20identify%20resources%20on%20each%20cloud%20provider%20by%20using%20the%20%3CEM%3EInventory%3C%2FEM%3E%20dashboard%2C%20by%20using%20the%20%3CEM%3ECloud%20Environment%3C%2FEM%3E%20filter%20as%20shown%20below%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Fig2.JPG%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F276105i30A5CFC0D07F8245%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Fig2.JPG%22%20alt%3D%22Fig2.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20addition%20to%20all%20that%2C%20you%20can%20also%20take%20advantage%20of%20centralized%20automation%20by%20leveraging%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fworkflow-automation%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EWorkflow%20Automation%3C%2FA%3E%20feature%20to%20automate%20response%20for%20security%20recommendations%20generated%20in%20Azure%2C%20AWS%20or%20GCP.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH1%20id%3D%22toc-hId-1305204502%22%20id%3D%22toc-hId-1305204473%22%3ECloud%20security%20posture%20management%20and%20workload%20protection%3C%2FH1%3E%0A%3CP%3EThe%20security%20recommendations%20are%20relevant%20for%20the%20cloud%20security%20posture%20management%20scenario%2C%20which%20means%20that%20you%20drive%20the%20enhancement%20of%20your%20security%20posture%20across%20multiple%20cloud%20providers%20by%20remediating%20those%20recommendations.%20However%2C%20this%20is%20not%20the%20only%20scenario%20available%20for%20multi-cloud%2C%20you%20can%20also%20use%20the%20following%20Azure%20Defender%20plans%20to%20enhance%20your%20workload%20protection.%20When%20planning%20cloud%20workload%20protection%20for%20workloads%20in%20AWS%20and%20GCP%2C%20make%20sure%20to%20first%20enable%20the%20VMs%20to%20use%20%3CA%20href%3D%22https%3A%2F%2Fazurearcjumpstart.io%2Fazure_arc_jumpstart%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EAzure%20Arc%3C%2FA%3E%2C%20once%20you%20do%20that%2C%20the%20following%20Azure%20Defender%20plans%20will%20be%20available%20across%20Azure%2C%20AWS%20and%20GCP%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-servers-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Defender%20for%20Servers%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-kubernetes-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Defender%20for%20Kubernetes%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-sql-usage%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAzure%20Defender%20for%20SQL%20on%20Machines%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EThe%20potential%20alerts%20generated%20by%20workloads%20protected%20by%20those%20plans%20is%20going%20to%20be%20surfaced%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-alerts-overview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ESecurity%20Alerts%3C%2FA%3E%20dashboard%20in%20Azure%20Defender.%20Which%20means%20that%20you%20again%20will%20have%20a%20single%20dashboard%20to%20visualize%20alerts%20across%20different%20cloud%20providers.%20These%20alerts%20can%20be%20streamed%20to%20your%20SIEM%20platform%20using%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fcontinuous-export%3Ftabs%3Dazure-portal%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EContinuous%20Export%3C%2FA%3E%20feature%20in%20Azure%20Security%20Center.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH1%20id%3D%22toc-hId--502249961%22%20id%3D%22toc-hId--502249990%22%3EDesign%20considerations%3C%2FH1%3E%0A%3CP%3EPrior%20to%20implementing%20your%20multi-cloud%20adoption%20using%20Azure%20Defender%2C%20it%20is%20important%20to%20consider%20the%20following%20aspects%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EWhen%20connecting%20with%20AWS%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EAn%20account%20is%20onboarded%20to%20a%20subscription%2C%20the%20subscription%20has%20to%20have%20Azure%20Defender%20for%20Servers%20enabled%3C%2FLI%3E%0A%3CLI%3EThe%20VMs%20under%20this%20account%20will%20automatically%20be%20onboarded%20to%20Azure%20using%20Azure%20Arc%2C%20and%20will%20be%20covered%20by%20Defender%20(%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fazure%252Fsecurity-center%252Fquickstart-onboard-aws%2523aws-in-security-center-faq%26amp%3Bdata%3D04%257C01%257Cyurid%2540microsoft.com%257Cc14140651e984a5336ca08d908d6785a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637550539502838028%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3DsHuUWj5lwk3LzxqYftRKNgRYiUiwHB%252Fkcx8CaB6af%252Bo%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Elist%20of%20supported%20OS%3C%2FA%3E)%3C%2FLI%3E%0A%3CLI%3EArc%20cost%20is%20inclusive%20with%20Defender%20(you%20won%E2%80%99t%20pay%20twice)%3C%2FLI%3E%0A%3CLI%3ETo%20receive%20the%20security%20recommendations%2C%20%26nbsp%3Byou%20will%20need%20to%20enable%20AWS%20Security%20Hub%20on%20the%20accounts%20you%20want%20to%20onboard%3C%2FLI%3E%0A%3CLI%3ESecurity%20Hub%20is%20a%20paid%20service%20that%20can%20vary%20depending%20on%20how%20many%20accounts%20and%20regions%20it%E2%80%99s%20enabled%20on%20(please%20refer%20to%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Faws.amazon.com%252Fsecurity-hub%252Fpricing%252F%26amp%3Bdata%3D04%257C01%257Cyurid%2540microsoft.com%257Cc14140651e984a5336ca08d908d6785a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637550539502847984%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3DgSiXLW91cg%252FPzb202%252FnSGW%252FPkKqniWRy9eQZkhgFXm0%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EAWS%20official%20pricing%3C%2FA%3E)%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EWhen%20connecting%20with%20GCP%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ESame%20requirement%20for%20Defender%20enabled%20on%20the%20subscription%3C%2FLI%3E%0A%3CLI%3EServers%20are%20not%20onboarded%20automatically%2C%20and%20will%20need%20to%20be%20onboarded%20through%20Arc%20(%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fdocs.microsoft.com%252Fen-us%252Fazure%252Fazure-arc%252Fservers%252Fonboard-service-principal%26amp%3Bdata%3D04%257C01%257Cyurid%2540microsoft.com%257Cc14140651e984a5336ca08d908d6785a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637550539502847984%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3DdkDiq%252BVtcQ4bZ%252B%252Fsrox96rdlqbqBNU5eQ%252FmkORkvFfw%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EArc%20onboarding%20guide%3C%2FA%3E)%3C%2FLI%3E%0A%3CLI%3ETo%20receive%20security%20recommendations%2C%20you%20will%20need%20to%20enable%20GCP%20Security%20Command%20Center%3C%2FLI%3E%0A%3CLI%3EGoogle%20Security%20Command%20Center%20have%20two%20pricing%20tiers%3A%20standard%20(free)%20and%20premium%3C%2FLI%3E%0A%3CLI%3EFree%20tier%20includes%20~12%20recommendations%2C%20premium%20around%20120%3C%2FLI%3E%0A%3CLI%3EPremium%20tier%20costs%205%25%20of%20annual%20spending%20in%20GCP%2C%20please%20refer%20to%20%3CA%20href%3D%22https%3A%2F%2Fnam06.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fcloud.google.com%252Fsecurity-command-center%252Fpricing%26amp%3Bdata%3D04%257C01%257Cyurid%2540microsoft.com%257Cc14140651e984a5336ca08d908d6785a%257C72f988bf86f141af91ab2d7cd011db47%257C1%257C0%257C637550539502857939%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C1000%26amp%3Bsdata%3Dccstgd0Q4OtbR1GQIZ62%252F1pV4ouXwyQwE6PYD%252Bbp%252Fhg%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EGCP%20official%20pricing%3C%2FA%3E)%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH1%20id%3D%22toc-hId-1985262872%22%20id%3D%22toc-hId-1985262843%22%3EAdditional%20Resources%3C%2FH1%3E%0A%3CP%3EThe%20resources%20below%20will%20be%20useful%20for%20you%20to%20implement%20this%20multi-cloud%20capability%20in%20Azure%20Defender%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fquickstart-onboard-aws%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAWS%20Connector%3C%2FA%3E%20(step-by-step%20guide%20to%20configure%20this%20integration)%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fquickstart-onboard-gcp%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EGCP%20Connector%3C%2FA%3E%20(step-by-step%20guide%20to%20configure%20this%20integration)%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FGJbE-SxNdcA%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EOverview%20of%20Azure%20Defender%20Multi-cloud%20solution%3C%2FA%3E%20(video)%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FyS0_TIfQd_Q%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EAzure%20Defender%20for%20SQL%3C%2FA%3E%20(video)%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FmeFiFb_66NU%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EAzure%20Defender%20for%20Kubernetes%3C%2FA%3E%20(video)%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fyoutu.be%2FFgzcoSsCspo%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EContinuous%20Export%3C%2FA%3E%20(video)%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EReviewer%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EOr%20Serok%20Jeppa%2C%20Program%20Manager%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Co-Authors
Version history
Last update:
‎Apr 27 2021 02:43 PM
Updated by: