May 27, 2025May 25, 2025 Defender for Cloud – Part 11: Data and AI Security Table of Contents Note before the start. This is the final part of this DefenderForCloud series. It had originally almost double amount of parts but time and real-life struggles have decreased these and also my posts are usually very long so it takes a lot of time to write these. And I want to write also other topics than DefenderForCloud. But I have touched the different topics in these posts so I think there are no or just a few topics which are not yet mentioned. Time of this series is coming to the end because summer is coming (and I need a break) and there are significant changes coming to DefenderForCloud. And it’s no use to continue this forever. What means Data and AI security in Defender for Cloud In short it means Data Security Posture Management (DSPM) and AI workload security. Microsoft says “ Data security posture management in Microsoft Defender for Cloud helps you reduce data risk and respond to data breaches. With data security posture management, you can: Automatically discover sensitive data resources across multiple clouds. Evaluate data sensitivity, data exposure, and how data flows across the organization. Proactively and continuously uncover risks that might lead to data breaches. Detect suspicious activities that might indicate ongoing threats to sensitive data resources.” And for AI Security “ Defender for Cloud discovers AI workloads and identifies details of your organization’s AI BOM. This visibility allows you to identify and address vulnerabilities and protect generative AI applications from potential threats. Defender for Cloud automatically and continuously discovers deployed AI workloads across the following services: Azure OpenAI Service Azure AI foundry Azure Machine Learning Amazon Bedrock Google Vertex AI “ These two functions are compiled together for one dashboard. In short what you will see in the dashboard are the data and AI related resources in Azure or linked resources to Azure via data connectors. Overview The Data and AI security dashboard allows you to: A unified view of all organizational data and AI resources in a single interface. Gain insights into data storage locations and the types of resources that hold it. Assess the protection coverage of data and AI resources. View attack paths, recommendations, and data threat analysis in one location. Mitigate critical threats and improve security posture in data and AI environments. Discover useful data and AI insights by highlighting queries in the security explorer. Identify and summarize sensitive data resources within your cloud data resource and AI assets Data and AI Security Dashboard in two images (dashboard didn't fit to one image). Click to enlarge. Pre-requisitesTo use the dashboard fully you need to enable these per subscription:Defender CSPM planDefender for storages planDefender for databases planAI workloads planand in DCSPM plan settings:Sensitive data discoveryAlso some subscription level resource providers are needed to use the Security Explorer:Microsoft.Security/assessments/readMicrosoft.Security/assessments/subassessments/readMicrosoft.Security/alerts/readNOTE: The comprehensive list of supported environments, platformes and resources for sensitive data discovery.Data SecurityDefender for Cloud provides visibility and contextual insights into your organizational security posture. With DCSPM you can proactively identify and prioritize critical data risks, distinguishing them from less risky issues.Data Security features for example sensitivity settings need these roles:Compliance data administratorCompliance administratorso common roles like Security Administrator, Security Operator, Security Reader are not enough. Top section of the data and AI dashboard. Click to enlarge. In the top section you will see:Scope shows the amouint of subscriptions which are included in the Dashboard (Azure, AWS, GCP).All data shows the storages, databases and other sources for the Dashboard.Coverage status shows the plans status; are they full or partially enabled.Attention shows the amount of resources which has critical or high severities, alerts or recommendations. The middle section of the data and AI dashboard. Click to enlarge. In the middle section you see data related insightsThe amount of high severity alerts and the MITRE ATT&CK tactics for themThe amount of critical and high severity recommendations and risk factors for themThe amount of Critical and high severitys attack paths and risk factors for themThe amount of sensitive data discovery info types and sensitivy labels if there are any.The data threat protection alerts on managed databases and storages by severityThe data queries seen by Cloud Security ExplorerThe amount of Internet-faced data sources also seen by Cloud Security Explorer AI SecurityDefender for Cloud provides insights from your organization’s AI security posture. You can reduce risks within your AI workloads using security recommendations and attack path analysis. But of course you need Defender CSPM plan to get those. The bottom section of the data and AI dashboard. Click to enlarge. In the bottom section you seeThe total amount of AI related resources and if possible divided to pre-recognized servicesAI threat detection divided to scanned prompts and detected alerts also by severityAI queries and Interned-faced resources seen by Cloud Security Explorer The MDC Series (so far) ends here. Maybe sequel in the future. Thanks for reading. The parts of the MDC blog series Part 0: Microsoft Defender for Cloud – The EPIC blog series – introductionPart 1: Getting started aka Setup Part 2: The Asset Inventory Part 3: Security posturePart 4: Security recommendationsPart 5: Security alertsPart 6: Attack path analysisPart 7: Cloud security explorerPart 8: WorkbooksPart 9: Regulatory compliancePart 10: Workload protectionspart 10.5: Advanced Workload protectionPart 11: Data and AI security – The end of the series Jussi Metso Author is a a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future. Share on Social Mediaxfacebooklinkedinwhatsapp Discover more from Jussi Metso Subscribe to get the latest posts sent to your email. Type your email… Subscribe DEFENDER FOR CLOUD #cloudsecurity#mdcseries
DEFENDER FOR CLOUD Defender for Cloud – Part 9: Regulatory compliance March 13, 2025May 25, 2025 Microsoft Defender for Cloud provides Regulatory Compliance capabilities to help organizations assess and maintain compliance with industry standards, frameworks, and regulatory requirements. It continuously monitors cloud resources and provides insights into security posture, ensuring alignment with compliance benchmarks. Read More
DEFENDER FOR CLOUD Defender for Cloud – Part 5: Security Alerts August 31, 2024May 25, 2025 Defender for Cloud helps you to detect and prevent threats to your hybrid cloud environment. When a threat is detected, Defender for Cloud raises security alerts. On this security alerts page, you can triage your alerts, investigate the findings, and quickly respond manually or with predefined automated workflows. Read More
DEFENDER FOR CLOUD Defender for Cloud – Part 6: Attack Path Analysis February 12, 2025May 25, 2025 Defender for Cloud Attack path analysis addresses security issues that pose immediate threats and have the greatest potential for exploitation in your environment. Defender for Cloud analyzes which security issues are part of potential attack paths that attackers could use to breach your environment. Read More