Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
When you onboard your Amazon Web Service (AWS) or Google Cloud Platform (GCP) environments, Defender for Cloud automatically creates a security connector as an Azure resource in the connected subscription and resource group. Defender for Cloud also creates the identity provider as an Identity and Access Management (IAM) role required during onboarding.
To assign permissions on a specific connector under the parent connector, first decide which AWS accounts or GCP projects users need to access. Then identify the security connectors that map to those accounts or projects.
Prerequisites
An Azure account. If you don't already have an Azure account, you can create your Azure free account today.
At least one security connector for Connect Azure subscriptions, Onboard AWS accounts, or Onboard GCP projects.
Configure permissions on the security connector
Permissions for security connectors are managed through Azure role-based access control (RBAC).
You can assign roles to users, groups, and applications at the subscription, resource group, or resource level.
To configure connector permissions:
Sign in to the Azure portal.
Navigate to Microsoft Defender for Cloud > Environment settings.
Locate the relevant AWS or GCP connector.
Assign permissions to workload owners by using All resources or Azure Resource Graph in the Azure portal.
Select Access control (IAM).
Select +Add > Add role assignment.
Select the desired role.
Select Next.
Select + Select members.
Search for and select the relevant user or group.
Select the Select button.
Select Next.
Select Review + assign.
Review the information.
Select Review + assign.
After you set permissions on the security connector, workload owners can view Defender for Cloud recommendations for associated AWS and GCP resources.