Ensure that, after enabling Microsoft Defender for Storage, an alert monitoring and response process is configured so that security alerts generated for your Azure Storage accounts are actioned in a timely manner. This is achieved by configuring continuous export within Microsoft Defender for Cloud to stream Storage-related security alerts to a Security Information and Event Management (SIEM) solution such as Microsoft Sentinel, to an Azure Event Hub, or to a Log Analytics workspace, and by integrating those alerts into your security operations workflow and incident response plan.
excellence
Enabling Microsoft Defender for Storage without a monitoring process limits its value, as detected threats may go unnoticed or unaddressed. Continuous monitoring and alert triage ensure that detected threats are acted upon quickly, reducing risk exposure. By configuring continuous export of Medium and High severity Security Alerts to a SIEM solution, security teams gain a centralized, real-time view of threats targeting Azure Storage accounts, enabling faster correlation with other security signals and a more effective incident response.
Configuring continuous export requires integration effort with a SIEM or alerting tool, as well as a defined incident response process. The amount of data logged, and thus the cost incurred, can vary significantly depending on the tenant size and the volume of security alerts generated. See the following pricing information for the relevant services:
Audit
To determine if continuous export of Microsoft Defender for Storage security alerts is configured to deliver at least Medium and High severity alerts to a SIEM, perform the following operations:
Azure CLI is not available for auditing this setting. Use the Azure Portal instead.Remediation / Resolution
To configure continuous export of Microsoft Defender for Storage security alerts to a SIEM solution, perform the following operations:
Azure CLI is not available for remediating this setting. Use the Azure Portal instead.References
- Azure Official Documentation
- Security alerts and incidents
- Set up continuous export in the Azure portal
- Ingest Microsoft Defender for Cloud alerts into Microsoft Sentinel
- What is Microsoft Defender for Storage
- CIS Security Documentation
- CIS Microsoft Azure Foundations Benchmark