Info icon
End of Life Notice: For Trend Cloud One™ - Conformity Customers, Conformity will reach its End of Sale on “July 31st, 2025” and End of Life “July 31st, 2026”. The same capabilities and much more is available in TrendAI Vision One™ Cloud Risk Management. For details, please refer to Upgrade to TrendAI Vision One™

Monitor Advanced Threat Protection Alerts for Storage Accounts

TrendAI Vision One™ provides continuous assurance that gives peace of mind for your cloud infrastructure, delivering over 1400 automated best practice checks.

Risk Level: Medium (should be achieved)

Ensure that, after enabling Microsoft Defender for Storage, an alert monitoring and response process is configured so that security alerts generated for your Azure Storage accounts are actioned in a timely manner. This is achieved by configuring continuous export within Microsoft Defender for Cloud to stream Storage-related security alerts to a Security Information and Event Management (SIEM) solution such as Microsoft Sentinel, to an Azure Event Hub, or to a Log Analytics workspace, and by integrating those alerts into your security operations workflow and incident response plan.

Security
Operational
excellence

Enabling Microsoft Defender for Storage without a monitoring process limits its value, as detected threats may go unnoticed or unaddressed. Continuous monitoring and alert triage ensure that detected threats are acted upon quickly, reducing risk exposure. By configuring continuous export of Medium and High severity Security Alerts to a SIEM solution, security teams gain a centralized, real-time view of threats targeting Azure Storage accounts, enabling faster correlation with other security signals and a more effective incident response.

Configuring continuous export requires integration effort with a SIEM or alerting tool, as well as a defined incident response process. The amount of data logged, and thus the cost incurred, can vary significantly depending on the tenant size and the volume of security alerts generated. See the following pricing information for the relevant services:


Audit

To determine if continuous export of Microsoft Defender for Storage security alerts is configured to deliver at least Medium and High severity alerts to a SIEM, perform the following operations:

Azure CLI is not available for auditing this setting. Use the Azure Portal instead.

Using Azure Console

  1. Sign in to the Microsoft Azure Portal.

  2. Navigate to Microsoft Defender for Cloud blade available at https://portal.azure.com/#view/Microsoft_Azure_Security/SecurityMenuBlade/~/0.

  3. In the left navigation panel, under Management, select Environment settings.

  4. Expand the tenant root group(s) to reveal the available subscriptions, then click on the name (link) of the Azure subscription that you want to examine.

  5. In the left navigation panel, under Settings, select Continuous export.

  6. Check whether Export enabled is set to On for either the Event Hub tab or the Log Analytics workspace tab.

  7. If Export enabled is set to On, verify that at least Security Alerts (Medium and High) is checked under Exported data types, and that the configured Export target points to an Event Hub or Log Analytics workspace connected to a SIEM solution.

  8. If Export enabled is set to Off for both tabs, or if Security Alerts (Medium and High) is not checked, continuous export of security alerts is not properly configured for the selected Azure subscription.

  9. Repeat steps no. 4 – 8 for each subscription available within your Microsoft Azure account.

Remediation / Resolution

To configure continuous export of Microsoft Defender for Storage security alerts to a SIEM solution, perform the following operations:

Azure CLI is not available for remediating this setting. Use the Azure Portal instead.

Using Azure Console

  1. Sign in to the Microsoft Azure Portal.

  2. Navigate to Microsoft Defender for Cloud blade available at https://portal.azure.com/#view/Microsoft_Azure_Security/SecurityMenuBlade/~/0.

  3. In the left navigation panel, under Management, select Environment settings.

  4. Expand the tenant root group(s) to reveal the available subscriptions, then click on the name (link) of the Azure subscription that you want to configure.

  5. In the left navigation panel, under Settings, select Continuous export.

  6. Select either the Event Hub tab, the Log Analytics workspace tab, or both, depending on your environment.

  7. Under Exported data types, select the Security Alerts checkbox and Severity (Medium and High).

  8. Under Export target, choose the Event Hub namespace/instance or the Log Analytics workspace that is tied to your SIEM solution (for example, Microsoft Sentinel).

  9. Set Export enabled to On.

  10. Choose Save to apply the configuration changes.

  11. Ensure that the exported security alerts are included in your organization's security operations workflow and incident response plan.

  12. Repeat steps no. 4 – 11 for each subscription available within your Microsoft Azure account.

References

Publication date Sep 9, 2026