Events
May 19, 6 PM - May 23, 12 AM
Calling all developers, creators, and AI innovators to join us in Seattle @Microsoft Build May 19-22.
Register todayThis browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
In Microsoft Defender for Cloud, the Defender for Azure Cosmos DB plan within Defender for Databases detects potential SQL injections, known bad actors, and suspicious access patterns based on Microsoft Threat Intelligence. It also identifies potential exploitation of your database through compromised identities or malicious insiders.
Defender for Azure Cosmos DB continually analyzes the personal data stream from the Azure Cosmos DB service. When it detects potentially malicious activities, it generates security alerts in Defender for Cloud. These alerts provide details of the suspicious activity, along with relevant investigation steps, remediation actions, and security recommendations to prevent future attacks.
You can enable Microsoft Defender for Azure Cosmos DB for all your databases (recommended), or you can enable it at either the subscription level or the resource level. Importantly, Defender for Azure Cosmos DB doesn't access the Azure Cosmos DB account data and doesn't affect the service's performance.
For billing information about Defender for Azure Cosmos DB, see the Defender for Cloud pricing page.
The following table lists supported and unsupported Azure Cosmos DB APIs in Defender for Azure Cosmos DB:
Supported | Not supported |
---|---|
Azure Cosmos DB for NoSQL | Azure Cosmos DB for Apache Cassandra Azure Cosmos DB for MongoDB Azure Cosmos DB for Table Azure Cosmos DB for Apache Gremlin |
For cloud availability, see Defender for Cloud support matrices for Azure commercial/other clouds.
Defender for Azure Cosmos DB uses advanced threat detection capabilities and Microsoft Threat Intelligence data. It continuously monitors your Azure Cosmos DB accounts for threats like SQL injection, compromised identities, and data exfiltration.
Defender for Cloud provides action-oriented security alerts with details of the suspicious activity and guidance on how to mitigate threats. Use this information to quickly remediate security issues and improve the security of your Azure Cosmos DB accounts.
You can export alerts to Microsoft Sentinel, to any partner security information and event management (SIEM) solution, or to any external tool. To learn how to stream alerts, see Stream alerts to monitoring solutions.
Activities that trigger security alerts enriched with threat intelligence include:
Tip
For a comprehensive list of all Defender for Azure Cosmos DB alerts, see Alerts for Azure Cosmos DB. This information is useful for workload owners who want to know what threats can be detected. It can also help security operations center (SOC) teams gain familiarity with detections before investigating them. Learn more about how to manage and respond to security alerts in Microsoft Defender for Cloud.
Events
May 19, 6 PM - May 23, 12 AM
Calling all developers, creators, and AI innovators to join us in Seattle @Microsoft Build May 19-22.
Register todayTraining
Module
Set up Microsoft Defender for Cloud - Training
Discover how to leverage Microsoft Defender for Cloud through the Azure portal to ensure the security of your Azure services and workloads, offering continuous threat detection and prevention.
Certification
Microsoft Certified: Azure Cosmos DB Developer Specialty - Certifications
Write efficient queries, create indexing policies, manage, and provision resources in the SQL API and SDK with Microsoft Azure Cosmos DB.