Microsoft Defender for Cloud PoC Series – Microsoft Defender for Key Vault

Published Aug 12 2021 07:50 AM 4,437 Views
Microsoft

 

Introduction

This Microsoft Defender for Cloud PoC Series provides guidelines on how to perform a proof of concept for a specific Microsoft Defender plan. For a more holistic approach where you need to validate Microsoft Defender for Cloud, please read How to Effectively Perform a Microsoft Defender for Cloud PoC article.

Azure Key Vault is used to store and access secrets, such as API keys, passwords, certificates, or cryptographic keys. Having critical data makes it a priority to maximize the threat protection of the vaults that can be provided with the security intelligence of Microsoft Defender for Key Vault.

 

Planning

As part of your Microsoft Defender for Key Vault PoC you need to identify the use case scenarios that you want to validate. Some common scenarios include access from an IP that was identified by Microsoft Threat Intelligence as suspicious, a user/service principal performing anomalous changes in policies or a high volume of operations – tailored to each tenant – within the Key Vault. You can use the Alerts identified by Microsoft Defender for Key Vault as your starting point to plan which actions you want to execute.

Enabling this bundle at the subscription level will not affect the performance of your Azure Key Vaults since there are no agents and it is performed in Azure’s backend.

 

Preparation

You need at least Security Admin role to enable Microsoft Defender for Key Vault. For more information about roles and privileges, visit this article.

From the readiness perspective, make sure to review the following resources to better understand Azure Defender for Key Vault:

 

Implementation and validation

You can use the sample alert feature to validate Microsoft Defender for Key Vault alerts, or you can simulate Microsoft Defender for Key Vault alerts by following the instructions in Validating Azure Key Vault threat detection in Microsoft Defender for Cloud.

Understanding the alerts for Key Vault can help you identify suspicious activities and eliminate noise if necessary. Read this article for more information on how to respond to Key Vault alerts.

 

Conclusion

By the end of this PoC you should be able to determine the value of this solution and the importance to have this level of threat detection to your workloads.

 

P.S. Subscribe to our Microsoft Defender for Cloud Newsletter to stay up to date on helpful tips and new releases and join our Tech Community where you can be one of the first to hear the latest Microsoft Defender for Cloud news, announcements and get your questions answered by experts.

 

Reviewers

Walner Dort - Program Manager, Azure Security Machine Learning

@Yuri Diogenes  - Principal PM Manager, Microsoft Defender for Cloud CxE

%3CLINGO-SUB%20id%3D%22lingo-sub-2641138%22%20slang%3D%22en-US%22%3EMicrosoft%20Defender%20for%20Cloud%20PoC%20Series%20%E2%80%93%20Microsoft%20Defender%20for%20Key%20Vault%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2641138%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EIntroduction%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EThis%20Microsoft%20Defender%20for%20Cloud%20PoC%20Series%20provides%20guidelines%20on%20how%20to%20perform%20a%20proof%20of%20concept%20for%20a%20specific%20Microsoft%20Defender%20plan.%20For%20a%20more%20holistic%20approach%20where%20you%20need%20to%20validate%20Microsoft%20Defender%20for%20Cloud%2C%20please%20read%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-security-center%2Fhow-to-effectively-perform-an-azure-security-center-poc%2Fba-p%2F516874%22%20target%3D%22_blank%22%3EHow%20to%20Effectively%20Perform%20a%20Microsoft%20Defender%20for%20Cloud%20PoC%3C%2FA%3E%20article.%3C%2FP%3E%0A%3CP%3EAzure%20Key%20Vault%20is%20used%20to%20store%20and%20access%20secrets%2C%20such%20as%20API%20keys%2C%20passwords%2C%20certificates%2C%20or%20cryptographic%20keys.%20Having%20critical%20data%20makes%20it%20a%20priority%20to%20maximize%20the%20threat%20protection%20of%20the%20vaults%20that%20can%20be%20provided%20with%20the%20security%20intelligence%20of%20Microsoft%20Defender%20for%20Key%20Vault.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EPlanning%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EAs%20part%20of%20your%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-key-vault-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Defender%20for%20%3C%2FA%3E%3CSPAN%3EKey%20Vault%3C%2FSPAN%3E%20PoC%20you%20need%20to%20identify%20the%20use%20case%20scenarios%20that%20you%20want%20to%20validate.%20Some%20common%20scenarios%20include%20%3CA%20href%3D%22https%3A%2F%2Fattack.mitre.org%2Ftactics%2FTA0001%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Eaccess%3C%2FA%3E%20from%20an%20IP%20that%20was%20identified%20by%20Microsoft%20Threat%20Intelligence%20as%20suspicious%2C%20a%20user%2Fservice%20principal%20performing%20anomalous%20changes%20in%20policies%20or%20a%20high%20volume%20of%20operations%20%E2%80%93%20tailored%20to%20each%20tenant%20%E2%80%93%20within%20the%20Key%20Vault.%20You%20can%20use%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Falerts-reference%23alerts-azurekv%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EAlerts%3C%2FA%3E%20identified%20by%20Microsoft%20Defender%20for%20Key%20Vault%20as%20your%20starting%20point%20to%20plan%20which%20actions%20you%20want%20to%20execute.%3C%2FP%3E%0A%3CP%3EEnabling%20this%20bundle%20at%20the%20subscription%20level%20will%20not%20affect%20the%20performance%20of%20your%20Azure%20Key%20Vaults%20since%20there%20are%20no%20agents%20and%20it%20is%20performed%20in%20Azure%E2%80%99s%20backend.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EPreparation%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EYou%20need%20at%20least%20%3CSTRONG%3ESecurity%20Admin%20role%3C%2FSTRONG%3E%20to%20enable%20Microsoft%20Defender%20for%20Key%20Vault.%20For%20more%20information%20about%20roles%20and%20privileges%2C%20visit%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-permissions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20article%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3EFrom%20the%20readiness%20perspective%2C%20make%20sure%20to%20review%20the%20following%20resources%20to%20better%20understand%20Azure%20Defender%20for%20Key%20Vault%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DD2gPijzZoAY%26amp%3Bt%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMicrosoft%20Defender%20for%20Key%20Vault%20%7C%20Azure%20Security%20Center%20in%20the%20Field%20%2313%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-key-vault-introduction%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EMicrosoft%20Defender%20for%20Key%20Vault%20Documentation%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EImplementation%20and%20validation%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EYou%20can%20use%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-alert-validation%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Esample%20alert%3C%2FA%3E%20feature%20to%20validate%20Microsoft%20Defender%20for%20Key%20Vault%20alerts%2C%20or%20you%20can%20simulate%20Microsoft%20Defender%20for%20Key%20Vault%20alerts%20by%20following%20the%20instructions%20in%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-security-center%2Fvalidating-azure-key-vault-threat-detection-in-azure-security%2Fba-p%2F1220336%22%20target%3D%22_blank%22%3EValidating%20Azure%20Key%20Vault%20threat%20detection%20in%20Microsoft%20Defender%20for%20Cloud%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3EUnderstanding%20the%20alerts%20for%20Key%20Vault%20can%20help%20you%20identify%20suspicious%20activities%20and%20eliminate%20noise%20if%20necessary.%20Read%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fdefender-for-key-vault-usage%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20article%3C%2FA%3E%20for%20more%20information%20on%20how%20to%20respond%20to%20Key%20Vault%20alerts.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EConclusion%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EBy%20the%20end%20of%20this%20PoC%20you%20should%20be%20able%20to%20determine%20the%20value%20of%20this%20solution%20and%20the%20importance%20to%20have%20this%20level%20of%20threat%20detection%20to%20your%20workloads.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EP.S.%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FASCNewsSubscribe%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3ESubscribe%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Eto%20our%20Microsoft%20Defender%20for%20Cloud%20Newsletter%20to%20stay%20up%20to%20date%20on%20helpful%20tips%20and%20new%20releases%20and%3C%2FSPAN%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FASCTechCommunity%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ejoin%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSPAN%3Eour%26nbsp%3BTech%20Community%26nbsp%3Bwhere%20you%20can%20be%20one%20of%20the%20first%20to%20hear%20the%20latest%20Microsoft%20Defender%20for%20Cloud%20news%2C%20announcements%20and%20get%20your%20questions%20answered%20by%20experts.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EReviewers%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EWalner%20Dort%20-%20Program%20Manager%2C%26nbsp%3B%3CSPAN%3EAzure%20Security%20Machine%20Learning%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F124214%22%20target%3D%22_blank%22%3E%40Yuri%20Diogenes%3C%2FA%3E%26nbsp%3B%26nbsp%3B-%20Principal%20PM%20Manager%2C%20Microsoft%20Defender%20for%20Cloud%20CxE%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2641138%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22new_teaser.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F320532iE006FA1FE35D28AF%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22new_teaser.png%22%20alt%3D%22new_teaser.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E
Co-Authors
Version history
Last update:
‎Oct 27 2021 12:28 PM
Updated by:
We support Ukraine and condemn war. Push Russian government to act against war. Be brave, vocal and show your support to Ukraine. Follow the latest news HERE