Restrict turning Off Azure Defender

Mohammed Siyam (DevOn) 1 Reputation point
2021-08-23T10:22:54.97+00:00

Hi

I would like to know if i can add a policy or somehow block turning off Azure Defender for Storage , Key vault etc.

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,204 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. JamesTran-MSFT 36,461 Reputation points Microsoft Employee
    2021-08-23T23:22:32.82+00:00

    @Mohammed Siyam (DevOn)
    Thank you for your post!

    When it comes to Azure Security Center, it uses Azure role-based access control (Azure RBAC), which provides built-in roles that can be assigned to users, groups, and services in Azure. In order to modify Security Policies or gain access to Azure Defender, the user will need to be a Security Admin, Owner, or Contributor of that subscription.

    Since Azure Security Center is controlled via RBAC role assignments, you can block users from turning off Azure Defender by making sure they aren't assigned roles they don't need at the Subscription level.

    125794-image.png 125774-image.png
    How do permissions work in Azure Security Center?

    If you have any other questions, please let me know.
    Thank you for your time and patience throughout this issue.

    ----------

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.


  2. Mohammed Siyam (DevOn) 1 Reputation point
    2021-09-07T14:23:06.837+00:00

    Hi

    I was able to add a policy that denies disabling azure defender for storage and key vault