last sync: 2023-Sep-29 17:58:48 UTC

Azure Policy definition

Configure Microsoft Defender for Azure Cosmos DB to be enabled

Source Azure Portal
Display name Configure Microsoft Defender for Azure Cosmos DB to be enabled
Id 82bf5b87-728b-4a74-ba4d-6123845cf542
Version 1.0.0
details on versioning
Category Security Center
Microsoft docs
Description Microsoft Defender for Azure Cosmos DB is an Azure-native layer of security that detects attempts to exploit databases in your Azure Cosmos DB accounts. Defender for Azure Cosmos DB detects potential SQL injections, known bad actors based on Microsoft Threat Intelligence, suspicious access patterns, and potential exploitations of your database through compromised identities or malicious insiders.
Mode All
Type BuiltIn
Preview False
Deprecated False
Effect Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
RBAC role(s)
Role Name Role Id
Security Admin fb1c8493-542b-48eb-b624-b4c8fea62acd
Rule aliases THEN-ExistenceCondition (1)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Security/pricings/pricingTier Microsoft.Security pricings properties.pricingTier false
Rule resource types IF (1)
Microsoft.Resources/subscriptions
THEN-Deployment (1)
Microsoft.Security/pricings
Compliance Not a Compliance control
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
Configure Microsoft Defender for Databases to be enabled 9d46421d-1a48-4636-8d1a-5525ed29172d Security Center GA BuiltIn
Deploy Microsoft Defender for Cloud configuration Deploy-MDFC-Config Security Center GA ALZ
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-03-11 18:16:48 add 82bf5b87-728b-4a74-ba4d-6123845cf542
JSON compare n/a
JSON
api-version=2021-06-01