Overview of Microsoft Defender for Resource Manager
Azure Resource Manager is the deployment and management service for Azure. It provides a management layer that enables you to create, update, and delete resources in your Azure account. You use management features, like access control, locks, and tags, to secure and organize your resources after deployment.
The cloud management layer is a crucial service connected to all your cloud resources. Because of this, it is also a potential target for attackers. Consequently, we recommend security operations teams monitor the resource management layer closely.
Microsoft Defender for Resource Manager automatically monitors the resource management operations in your organization, whether they're performed through the Azure portal, Azure REST APIs, Azure CLI, or other Azure programmatic clients. Defender for Cloud runs advanced security analytics to detect threats and alerts you about suspicious activity.
Some of these analytics are powered by Microsoft Defender for Cloud Apps (formerly known as Microsoft Cloud App Security). To benefit from these analytics, you must activate a Defender for Cloud Apps license. If you have a Defender for Cloud Apps license, then these alerts are enabled by default. To disable the alerts:
- From Defender for Cloud's menu, open Environment settings.
- Select the subscription you want to change.
- Select Integrations.
- Clear Allow Microsoft Defender for Cloud Apps to access my data, and select Save.
|Release state:||General availability (GA)|
|Pricing:||Microsoft Defender for Resource Manager is billed as shown on the pricing page|
Azure China 21Vianet
What are the benefits of Microsoft Defender for Resource Manager?
Microsoft Defender for Resource Manager protects against issues including:
- Suspicious resource management operations, such as operations from malicious IP addresses, disabling antimalware, and suspicious scripts running in VM extensions
- Use of exploitation toolkits like Microburst or PowerZure
- Lateral movement from the Azure management layer to the Azure resources data plane
A full list of the alerts provided by Microsoft Defender for Resource Manager is on the alerts reference page.
In this article, you learned about Microsoft Defender for Resource Manager.
For related material, see the following article:
- Security alerts might be generated or received by Defender for Cloud from different security products. To export all of these alerts to Microsoft Sentinel, any third-party SIEM, or any other external tool, follow the instructions in Exporting alerts to a SIEM solution.
Submit and view feedback for