Microsoft Defender for Cloud
Cloud and workloads

Determine multicloud CSPM and CWPP dependencies - Microsoft Defender for Cloud

In brief

The article now more clearly describes CSPM and CWPP dependencies for AWS and GCP resources, with reorganized sections for required components and expanded dependency headings. It also clarifies Microsoft Defender for Endpoint and Azure Policy for Kubernetes descriptions.

What Defender admins need to know

Administrators can use the revised structure and explanations to identify dependencies when planning multicloud security deployments.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Determine multicloud dependencies

This article is one of a series providing guidance asdescribes the dependencies and components you design aneed to deploy cloud security posture management (CSPM) and cloud workload protection platform (CWPP) solution across multicloudAmazon Web Services (AWS) and Google Cloud Platform (GCP) resources with Microsoft Defender for Cloud. Use this guidance to identify agents, extensions, and networking requirements before you onboard multicloud connectors.

GoalMulticloud dependency planning goals

Figure outIdentify dependencies that might influence the design of your multicloud design.security solution.

Get startedIdentify required multicloud components

As you design your multicloud solution, it’s important to have a clear picture of the components needed to use all multicloud features in Defender for Cloud.

CSPM dependencies and requirements

Defender for Cloud provides cloud security posture management (CSPM) features for your Amazon Web Services (AWS) and Google Cloud Platform (GCP) workloads.

CWPP dependencies and requirements

| SQL Servers on machines | No | No | Yes | | Automatic SQL Server discovery and registration | No | No | Yes |

Defender for Servers dependencies

Enabling Defender for Servers on your AWS or GCP connector allows Defender for Cloud to provide server protection to your Google Compute Engine VMs and AWS EC2 instances.

Defender for Servers offers two different plans:

Machines must meet network requirements before onboarding the agents. Autoprovisioning is enabled by default.

Defender for Containers dependencies

Enabling Defender for Containers provides GKE and EKS clusters and underlying hosts with agentless security capabilities.

  • Azure Arc agent: Connects your GKE and EKS clusters to Azure and onboards the Defender sensor.
  • Defender sensor: Provides host-level runtime threat protection.
  • Azure Policy for Kubernetes: Extends the Gatekeeper v3v3, an admission controller that enforces policies on Kubernetes clusters, to monitor every request to the Kubernetes API server, and ensures that security best practices are being followed on clusters and workloads.
  • Kubernetes audit logs: Audit logs from the Kubernetes API server allow Defender for Containers to identify suspicious activity in your multicloud servers and provide deeper insights during alert investigation. Enable Kubernetes audit log collection at the connector level.

Check networking requirements for Defender for Containers

Make sure to check that your clusters meet network requirements so that the Defender sensor can connect with Defender for Cloud.

Defender for SQL dependencies

Defender for SQL provides threat detection for Google Compute Engine and AWS workloads. Enable the Defender for SQL Servers on Machines plan on the subscription where the connector is located.

  • Azure Monitor agent (AMA): Collects security-related configuration information and event logs from machines.
  • Automatic SQL Server discovery and registration: Supports automatic discovery and registration of SQL Servers.

Next stepsteps

[!div class="nextstepaction"] Automate connector deployment