Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Defender for Cloud’s Active User feature helps security administrators identify the most active users responsible for remediation recommendations. Security administrators must monitor and address potential threats such as attack paths and their associated recommendations to secure cloud resources.
The Active User feature suggests up to three potential active users. The suggestion is based on the users control plane activities on the specific resource, its related resource group, or the associated subscription. This feature improves the speed and efficiency of the remediation process and strengthens overall security posture.
Security administrators can assign and the recommendation directly to the most appropriate user from the suggested active user list. The assigned user receives a notification and a due date for remediation, which eliminates the need for manual investigation to determine responsibility. This approach streamlines the workflow and saves time for security teams.
Prerequisites
Enable the Defender for Cloud Security Posture Management (CSPM) plan.
You have one of the following roles and permissions:
- Security Administrator
- Owner
- Contributor
Assign a recommendation to an active user
Defender for Cloud's Active User feature suggests up to three potential Active Users. It bases its suggestions on their control plane activities on the specific resource, its related resource group, or the associated subscription per recommendation.
Sign in to the Azure portal.
Navigate to Defender for Cloud > Recommendations.
Review the Recommendation owner column.
Select a recommendation with a suggested owner.
The Recommendation owner and set due date section suggests the top Active User on the affected resource.
Select Assign owner & set due date.
Review the activity and confidence assigned to the top three suggested users.
Select More info to view more information about the user, including, name, email address, the user's manager, department, role, and last activities.
(Recommended) Select an owner from the list of suggested users.
(Optional) Select add a user manually if you don't want to assign any of the suggested users.
(Optional) Select a remediation timeframe.
(Optional) Toggle Apply grace period.
(Optional) Set email notifications.
Select Create.
If you selected to set an email notification, the Active User receives an email with the recommendation details and a link to the recommendation in Defender for Cloud.