Defender for Cloud - AWS onboarding

Paweł Haubus 20 Reputation points
2024-08-06T20:34:20.13+00:00

I am currently playing with DfC and decided to onboard single AWS account. My Azure subscription is set to forward DfC logs to custom LAW insted of using DfC default.

Now, when i onboard AWS account, all the logs, alerts, sec scores etc, are also forwarded to the custom LAW. I assume this is based on the fact that DfC AWS connector is located in my subscription and AWS config will follow residing subscription setup.

My question is, can i somehow change this behaviour and set indyvidual LAW only for AWS DfC logs? If lets say i need to take consideration for data residency or data segregation, how would i do that in DfC? so far i can't find the option to do it...

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,315 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,406 questions
{count} votes

Accepted answer
  1. Ryan Hill 28,631 Reputation points Microsoft Employee
    2024-08-12T14:48:19.03+00:00

    Hi @Paweł Haubus,

    I've reached out to the product team for additional insights. Accordingly, there are several solutions which are dictated by the boundaries of your workstream.

    1. If you just removing sensitive data, you can create an ingestion transformation rule that remove the fields/values.
    2. If you want to allow access to some users and not others, you can split the incoming data into two workspaces. Similar to what you've done thus far but you don't need to create two separate subscriptions to achieve this. You would essentially filter the data on one and leave as-is on the other.
    3. If the non-sensitive data consumers are looking for less granular data, you can use a summary rule to create clean and aggregated summaries of the original data assign different RBAC roles to uses for the results.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.