Microsoft Azure Security Integration
FortiCNP provides Azure cloud integration where it integrates Azure cloud security integration data and provide critical insights for cloud security monitoring. FortiCNP will receive security findings from Azure security integration and informs users of probe findings.
The Azure security integration provides valuable data for all Vulnerabilities and part of Threats findings in Resource Risk Insights for Azure cloud resources.
Requirement
- An active Microsoft Azure AD account with security policy setup is required for Microsoft Azure to provide cloud security integration data to FortiCNP.
- Microsoft Defender for Servers Plan 2 is required to enable Azure security integration. See Enable Azure Cloud Integration
View Azure Security Integration Findings in FotiCNP
Vulnerabilities findings are accessible through INSIGHTS > Risk > Resource when clicked on an Azure cloud resource for details.
Threats findings are accessible through INSIGHTS > Risk > Resource when clicked on an Azure cloud resource for details.
Another place for Threats findings from Azure Security Integration can be found in INSIGHTS > Threat > Findings when filtered for Finding Type: Microsoft Defender for Cloud - Security Alerts.