Failing to configure Defender for Servers File Integrity Monitoring

Mika Pitkänen 60 Reputation points
2024-09-04T06:02:06.65+00:00

I don't have Owner role (and cannot have in the tenant I'm working) but I have Security Admin role and also custom role which allows me to enable for example all features of Defender for Storage and also all features of Defender for Servers.

Except that configuring Defender for Servers File Integrity Monitoring fails.

I get an error on Azure portal notifications which says:

Failed to save 'Servers' plan for subscription 'xxx'.

and when I go to see the activity log of the subscription where the log analytics workspace is deployed into (which I'm choosing when configuring FIM) I see error:

Resource: /subscriptions/xxx/providers/Microsoft.Security/pricings/VirtualMachines

Message: User does not have owner role on the subscription of the given workspace!

According to documentation https://learn.microsoft.com/en-us/azure/defender-for-cloud/file-integrity-monitoring-enable-defender-endpoint

Required roles and permissions: Workspace owner or Security admin can enable and disable FIM.

Defender for Servers has been enabled on the log analytics workspace.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments
{count} votes

Accepted answer
  1. Givary-MSFT 35,621 Reputation points Microsoft Employee Moderator
    2024-09-09T04:57:45.9433333+00:00

    @Mika Pitkänen Apologies for the delayed response, with the above error it seems it needs owner privilege to make changes to the log analytics workspace - https://learn.microsoft.com/en-us/services-hub/unified/health/azure-roles#azure-roles:~:text=Roles%20that%20can%20Add/Remove%20solutions%20from%20Services%20Hub%20workspace

    User's image

    Let me know by making the above changes helps to resolve this issue, accordingly, will work review the doc and get it rectified by our team.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.