Microsoft Defender for Cloud
Cloud and workloads

Assign access to workload owners

In brief

The article now describes how AWS and GCP onboarding creates security connectors and an IAM role, and clarifies assigning RBAC permissions to account or project connectors at subscription, resource group, or resource scope.

What Defender admins need to know

Administrators get clearer instructions for identifying connectors, assigning access, and selecting the security connector resource type.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Assign access to workload owners

When you onboard your Amazon Web Service (AWS) or Google Cloud Platform (GCP) environments, Defender for Cloud automatically creates a security connector as an Azure resource in the connected subscription and resource group. Defender for Cloudresource. It also creates the identity provider assets up an Identity and Access Management (IAM) role required during onboarding.as the identity provider.

To assign permissions on a specific connector under the parentaccount or project connector, first decide which AWS accounts or GCP projects your users need to access.need. Then identifyfind the security connectors that map tomatch those accounts or projects.

Prerequisites

Configure permissions on the security connector

PermissionsYou manage permissions for security connectors are managed through Azure role-based access control (RBAC).

You can assign roles to users, groups, and applications at theany level: subscription, resource group, or resource level.resource.

To configure connector permissions:

1. Select the **Types equals all** filter.

1. Enter `securityconnector` in the value field and add a check to theselect `microsoft.security/securityconnectors`.

    :::image type="content" source="media/assign-access-to-workload/security-connector.png" alt-text="Screenshot that shows where the field is located and where to enter the value on the screen." lightbox="media/assign-access-to-workload/security-connector.png":::