Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Microsoft Defender for Azure Cosmos DB protection is available at both the subscription level and the resource level.
You can enable Microsoft Defender for Cloud on your subscription to protect all database types, including Microsoft Defender for Azure Cosmos DB. Enabling protection at the subscription level is the recommended approach.
You can also enable Microsoft Defender for Azure Cosmos DB at the resource level to protect a specific Azure Cosmos DB account.
Prerequisites
Before you begin, make sure you have the following prerequisite:
- An Azure account. If you don't already have one, create a free Azure account.
Enable database protection at the subscription level
Enable Microsoft Defender for Cloud at the subscription level to protect all database types in your subscription (recommended).
You can enable Microsoft Defender for Cloud protection on your subscription to protect database types such as Azure Cosmos DB, Azure SQL Database, Azure SQL servers on machines, and open-source relational databases.
You can also select specific resource types to protect when you configure your plan.
When you turn on enhanced security features for your subscription, Defender for Azure Cosmos DB is enabled for all your Azure Cosmos DB accounts.
To enable database protection at the subscription level:
Sign in to the Azure portal.
Navigate to Microsoft Defender for Cloud > Environment settings.
Select the relevant subscription.
Locate Databases and toggle the switch to On.
Select Save.
To select specific resource types to protect when you configure your plan:
Sign in to the Azure portal.
Navigate to Microsoft Defender for Cloud > Environment settings.
Select the relevant subscription.
Locate Databases and toggle the switch to On.
Select Select types
Toggle the desired resource type switches to On.
Select Confirm.
Enable Microsoft Defender for Azure Cosmos DB at the resource level
You can enable Defender for Azure Cosmos DB on a specific account by using the Azure portal, PowerShell, Azure CLI, an ARM template, or Azure Policy.
To enable Microsoft Defender for Cloud for a specific Azure Cosmos DB account:
Use one of the following methods: Azure portal, PowerShell, ARM template, Azure CLI, or Azure Policy.
To enable Defender for Azure Cosmos DB from the Azure portal, perform the following steps:
Sign in to the Azure portal.
Navigate to your Azure Cosmos DB account > Settings.
Select Microsoft Defender for Cloud.
Select Enable Microsoft Defender for Azure Cosmos DB.
Simulate security alerts from Microsoft Defender for Azure Cosmos DB
For a full list, see supported alerts in the Defender for Cloud alert reference.
You can use sample alerts to check alert quality and behavior.
Sample alerts also help you test alert settings, such as SIEM links, workflow automation, and email notifications.
Create sample alerts to verify that your alerting, automation, and notification pipelines work as expected.
To create sample alerts from Microsoft Defender for Azure Cosmos DB:
Sign in to the Azure portal as a Subscription Contributor user.
Navigate to the security alerts page.
Select Sample alerts.
Select the subscription.
Select the relevant Microsoft Defender for Cloud plan(s).
Select Create sample alerts.
After a few minutes, alerts appear on the security alerts page.
Alerts also appear in other configured destinations, such as connected SIEM systems and email notifications.
Next steps
You learned how to enable Defender for Azure Cosmos DB and simulate security alerts.