Microsoft Defender for Cloud
Cloud and workloads

Binary drift detection and blocking

In brief

Binary drift blocking now lists sensor version 0.10.2 or later for AKS and multicloud, and supports the multicloud ARC extension without specifying a preview release train. The documentation also warns that deleting a rule can change alerting or blocking behavior.

What Defender admins need to know

Review the updated provisioning requirements and consider the impact before deleting drift detection rules. No required administrator action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Review binary drift and blocking availability.

Prerequisites

  • Run the Defender for Container sensor.
  • Binary drift blocking (Preview) only:
    • AKS: Helm provisioning with sensor version 0.10.2.
    • Multicloud: Helm provisioning with sensor version 0.10.2 or the ARC extension using release train=preview.
  • Enable the Defender for Container sensor

    Prerequisites

    Meet the following requirements before you create or manage binary drift detection and blocking policies.

    • Run the Defender for Container sensor.
    • Binary drift blocking only:
      • AKS: Helm provisioning with sensor version 0.10.2 or above.
      • Multicloud: Helm provisioning with sensor version 0.10.2 or above, or the ARC extension.
    • Enable the Defender for Container sensor on the subscriptions and connectors.
    • The following roles and permissions:
      • To create and modify drift policies: Security Admin or higher permissions on the tenant.

    Configure drift and block policies

    Create drift and block policies to define when alerts should be generated. Each policy consists of rules that define the conditions for generating alerts. This policy-and-rule structure lets you tailor the feature to your specific needs and reduce false positives. You can create exclusions by setting higher priority rules for specific scopes or clusters, images, pods, Kubernetes labels, or namespaces.

    1. Sign in to the Azure portal.

    Binary drift policies are flexible and customizable, allowing you to manage and adjust them as needed. You can edit rules to refine their conditions or actions, duplicate rules to create similar ones with minor changes, or delete rules that are no longer necessary. Regularly reviewing and managing your rules ensures that your binary drift detection and blocking policies remain effective and aligned with your security needs.

    Edit an existing drift detection rule

    Rules can be edited to refine their conditions or actions. This flexibilityThe ability to edit rule conditions or actions allows you to adjust your policies based on the alerts you receive and your review of them, ensuring that they effectively balance security needs with operational efficiency.

    1. Sign in to the Azure portal.

    Within 30 minutes, the sensors on the protected clusters update by using the new policy.

    Duplicate an existing drift detection rule

    Rules can be duplicated to create similar ones with minor changes. This optionDuplicating a rule is useful if you want to create a new rule that is similar to an existing one, allowing you to save time and maintain consistency in your policies.

    1. Sign in to the Azure portal.

    Within 30 minutes, the sensors on the protected clusters update by using the new policy.

    Delete a drift detection rule

    Rules can be deleted when they are no longer necessary or if they generate too many false positives. Regularly reviewing and cleaning up your rules helps maintain the effectiveness of your binary drift detection and blocking policies.

    1. Sign in to the Azure portal

      1. Sign in to the Azure portal.

      2. Go to Microsoft Defender for Cloud > Environment settings.

      Defender for Cloud's alerts notify you of any binary drifts, so you can maintain the integrity of your container images. If the system detects an unauthorized external process that matches your defined policy conditions, it generates a high-severity alert for you to review. If you configure blocking rules, the system blocks the execution of those unauthorized processes.

      Based on the alerts generated and your review of them, you might need to adjust your rules in the binary drift or blocking policy. This adjustmentAdjusting the binary drift or blocking policy could involve refining conditions, adding new rules, or removing ones that generate too many false positives. The goal is to ensure that the defined binary drift and blocking policies with their rules effectively balance security needs with operational efficiency.

      The effectiveness of binary drift detection and blocking relies on your active engagement in configuring, monitoring, and adjusting policies to suit your environment's unique requirements.