Microsoft Defender for Cloud
Cloud and workloads

Determine access control requirements for multicloud security

In brief

The article now focuses on determining permissions and access controls for multicloud deployments as part of CSPM and CWPP design. It adds an overview and sections for defining objectives and assessing requirements, with updated metadata.

What Defender admins need to know

Administrators can use the clearer structure when planning multicloud access controls. No administrator action is indicated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Determine access control requirements

Overview

This article is part of a series to provide guidance as you design a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) solution across multicloud resources with Microsoft Defender for Cloud. It helps you determine the permissions and access controls required for your multicloud deployment, including identity and access management (IAM) considerations for Azure, AWS, and GCP resources.

GoalDefine access control objectives

Determine the permissions and access controls you need in your multicloud deployment.

Get startedAssess access control requirements

As part of your multicloud solution design, review access requirements for multicloud resources that users can access. As you plan, answer the following questions, take notes, and document why each answer matters.