Enable Microsoft Defender for Azure Cosmos DB
Microsoft Defender for Azure Cosmos DB protection is available at both the Subscription level, and resource level. You can enable Microsoft Defender for Cloud on your subscription to protect all database types on your subscription including Microsoft Defender for Azure Cosmos DB (recommended). You can also choose to enable Microsoft Defender for Azure Cosmos DB at the Resource level to protect a specific Azure Cosmos DB account.
Prerequisites
- An Azure account. If you don't already have an Azure account, you can create your Azure free account today.
Enable database protection at the subscription level
The subscription level enablement enables Microsoft Defender for Cloud protection for all database types in your subscription (recommended).
You can enable Microsoft Defender for Cloud protection on your subscription in order to protect all database types, for example, Azure Cosmos DB, Azure SQL Database, Azure SQL servers on machines, and OSS RDBs. You can also select specific resource types to protect when you configure your plan.
When you enable Microsoft Defender for Cloud's enhanced security features on your subscription, Microsoft Defender for Azure Cosmos DB is automatically enabled for all of your Azure Cosmos DB accounts.
To enable database protection at the subscription level:
Sign in to the Azure portal.
Navigate to Microsoft Defender for Cloud > Environment settings.
Select the relevant subscription.
Locate Databases and toggle the switch to On.
Select Save.
To select specific resource types to protect when you configure your plan:
Follow steps 1 - 4 above.
Select Select types
Toggle the desired resource type switches to On.
Select Confirm.
Enable Microsoft Defender for Azure Cosmos DB at the resource level
You can enable Microsoft Defender for Cloud on a specific Azure Cosmos DB account through the Azure portal, PowerShell, Azure CLI, ARM template, or Azure Policy.
To enable Microsoft Defender for Cloud for a specific Azure Cosmos DB account:
Sign in to the Azure portal.
Navigate to your Azure Cosmos DB account > Settings.
Select Microsoft Defender for Cloud.
Select Enable Microsoft Defender for Azure Cosmos DB.
Simulate security alerts from Microsoft Defender for Azure Cosmos DB
A full list of supported alerts is available in the reference table of all Defender for Cloud security alerts.
You can use sample Microsoft Defender for Azure Cosmos DB alerts to evaluate their value, and capabilities. Sample alerts will also validate any configurations you've made for your security alerts (such as SIEM integrations, workflow automation, and email notifications).
To create sample alerts from Microsoft Defender for Azure Cosmos DB:
Sign in to the Azure portal as a Subscription Contributor user.
Navigate to the security alerts page.
Select Sample alerts.
Select the subscription.
Select the relevant Microsoft Defender plan(s).
Select Create sample alerts.
After a few minutes, the alerts will appear in the security alerts page. Alerts will also appear anywhere that you've configured to receive your Microsoft Defender for Cloud security alerts. For example, connected SIEMs, and email notifications.
Next steps
In this article, you learned how to enable Microsoft Defender for Azure Cosmos DB, and how to simulate security alerts.