SlideShare a Scribd company logo
Securing Azure Cosmos DB using Microsoft
Defender
Ankit Rao
๏ถ Senior Software Engineer at Zscaler
๏ถ Cloud and Cloud Security Enthusiast
๏ถ AWS Community Builder
๏ถ Pune (MH), India
: @_AnkitRao
: @ankit-rao
Motivation
Source: https://marketwatch.com
๏ถ The Global Cloud Security Market is
expected to grow from USD 5 Billion in
2016 to USD ~13 billion by 2022, at an
estimated CAGR of 17%.
๏ถ The lack of awareness about cloud
security among organizations and the
fear of losing their data confidentiality
are among some factors restraining
market growth.
๏ถ Further, the biggest identified cloud
threats occur mostly due to the
misconfiguration of cloud platforms.
๏ถAzure Cosmos DB โ€“ An overview
๏ถCloud Security โ€“ A shared responsibility model
๏ถMicrosoft Defender for Cosmos DB
๏ถAzure Cosmos DB โ€“ Security best practices
๏ถDemo
๏ถReferences
Agenda
Securing Azure CosmosDb using Microsoft Defender
Cloud Security โ€“ A shared responsibility model
๏ถ Cloud security refers to the
technologies, policies, controls, and
services that protect cloud data,
applications, and infrastructure from
threats.
๏ถ Cloud Security is a shared
responsibility model. The diagram
besides, shows how your
responsibility decreases with a PaaS
provider like Azure Cosmos DB.
Microsoft Defender for Cosmos DB
๏ถ Microsoft Defender for Cosmos DB provides an extra layer of security
intelligence that detects unusual and potentially harmful attempts to
access or exploit Azure Cosmos DB accounts.
๏ถ This layer of protection allows you to address threats, even without
being a security expert, and integrate them with central security
monitoring systems.
๏ถ Security alerts are triggered when anomalies in activity occur.
๏ถ Access from unusual locations
๏ถ Unusual data extraction
๏ถ Further, Defender will provide a centralized view with respect to the
security posture of the Cosmos DB, which helps users implement
security best practices.
Azure Cosmos DB โ€“ Security best practices
Network security and
firewall settings
๏ถUsing an IP firewall is the
first layer of protection to
secure your database.
๏ถAzure Cosmos DB
supports policy driven IP-
based access controls for
inbound firewall support.
๏ถEnsure that Cosmos DB is
accessible over selected
networks only.
Azure Cosmos DB โ€“ Security best practices
Replicate data globally
๏ถ Global replication lets you scale globally, provide low-latency access to your data around the
world.
๏ถ In the context of security, global replication ensures data protection against regional failures.
Azure Cosmos DB โ€“ Security best practices
Backup and Restore
๏ถAzure Cosmos databases are backed up
regularly and stored in a geo redundant
store.
๏ถAzure Cosmos DB's point-in-time restore
feature helps in multiple scenarios such
as the following:
๏ถ To recover from an accidental write or delete
operation within a container.
๏ถ To restore a deleted account, database, or a
container.
๏ถ To restore into any region (where backups
existed) at the restore point in time.
Azure Cosmos DB โ€“ Security best practices
Key rotation
๏ถ Rotating keys periodically significantly reduces the chances that a compromised set of access
keys can be used without your knowledge to access the database.
Azure Cosmos DB โ€“ Security best practices
Resource lock
๏ถResource lock prevents users in your
organization from accidentally deleting or
modifying critical resources.
๏ถThe lock overrides any permissions the user
might have.
Microsoft Defender for Cosmos DB - Demo
๏ถSecurity in Azure Cosmos DB
๏ถMicrosoft Defender for Cosmos DB (Preview)
References
Questions ??
: @_AnkitRao
: @ankit-rao
Thank you!
Enjoy the upcoming sessions!

More Related Content

PDF
Longji Vwamhi | Infrastructure With Microsoft Defender
PDF
Two Level Auditing Architecture to Maintain Consistent In Cloud
ย 
PPTX
cosmodb ppt project.pptxakfjhaasjfsdajjkfasd
PDF
Interview Questions for Azure Security.pdf
PPTX
cosmodb ppt personal.pptxgskjhkjsfgkhkjgskhk
PDF
Cloud Computing Interview Questions PDF By ScholarHat
PDF
DEVELOPING APPLICATION FOR CLOUD โ€“ A PROGRAMMERโ€™S PERSPECTIVE
PPTX
Cloud Camp: Infrastructure as a service advance workloads
Longji Vwamhi | Infrastructure With Microsoft Defender
Two Level Auditing Architecture to Maintain Consistent In Cloud
ย 
cosmodb ppt project.pptxakfjhaasjfsdajjkfasd
Interview Questions for Azure Security.pdf
cosmodb ppt personal.pptxgskjhkjsfgkhkjgskhk
Cloud Computing Interview Questions PDF By ScholarHat
DEVELOPING APPLICATION FOR CLOUD โ€“ A PROGRAMMERโ€™S PERSPECTIVE
Cloud Camp: Infrastructure as a service advance workloads

Similar to Securing Azure CosmosDb using Microsoft Defender (20)

DOC
Security Issues in Cloud Computing by rahul abhishek
PDF
Security Issues in Cloud Computing by rahul abhishek
PDF
Security Threat Solution over Single Cloud To Multi-Cloud Using DepSky Model
PDF
Improve cyber resiliency and protect data from cyber ransomware threats by us...
PDF
A PRACTICAL CLIENT APPLICATION BASED ON ATTRIBUTE-BASED ACCESS CONTROL FOR UN...
PDF
BackupRestoreInfographic.pdf
PDF
Developing a real time application on the cloud using node js , socket.io and...
PDF
AZ-900 Microsoft Azure Fundamentals Summary.pdf
PDF
Bloombase StoreSafe Intelligent Storage Firewall secures sensitive informatio...
PPTX
Azure Storage
PDF
Securing Red Hat workloads on Azure - Summary Presentation
PDF
IaaS Cloud Providers: A comparative analysis
PPTX
Azure Cloud Services
PPTX
Level 200 - Intro to Azure Storage1.pptx
PDF
7 Advantages of Migrating to Microsoft Azure
PDF
Top 20 Cloud Security Professional Interview Q&A.pdf
PDF
Top 20 Cloud Security Professional Interview Questions and Answers
PDF
Ready to Ace Your Cloud Security Interview.
PDF
A Detailed Analysis of the Issues and Solutions for Securing Data in Cloud
PDF
Database security technique with database cache
ย 
Security Issues in Cloud Computing by rahul abhishek
Security Issues in Cloud Computing by rahul abhishek
Security Threat Solution over Single Cloud To Multi-Cloud Using DepSky Model
Improve cyber resiliency and protect data from cyber ransomware threats by us...
A PRACTICAL CLIENT APPLICATION BASED ON ATTRIBUTE-BASED ACCESS CONTROL FOR UN...
BackupRestoreInfographic.pdf
Developing a real time application on the cloud using node js , socket.io and...
AZ-900 Microsoft Azure Fundamentals Summary.pdf
Bloombase StoreSafe Intelligent Storage Firewall secures sensitive informatio...
Azure Storage
Securing Red Hat workloads on Azure - Summary Presentation
IaaS Cloud Providers: A comparative analysis
Azure Cloud Services
Level 200 - Intro to Azure Storage1.pptx
7 Advantages of Migrating to Microsoft Azure
Top 20 Cloud Security Professional Interview Q&A.pdf
Top 20 Cloud Security Professional Interview Questions and Answers
Ready to Ace Your Cloud Security Interview.
A Detailed Analysis of the Issues and Solutions for Securing Data in Cloud
Database security technique with database cache
ย 
Ad

Recently uploaded (20)

PDF
Soil Improvement Techniques Note - Rabbi
PPTX
6ME3A-Unit-II-Sensors and Actuators_Handouts.pptx
PPT
A5_DistSysCh1.ppt_INTRODUCTION TO DISTRIBUTED SYSTEMS
PDF
keyrequirementskkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
PDF
Categorization of Factors Affecting Classification Algorithms Selection
ย 
PDF
Analyzing Impact of Pakistan Economic Corridor on Import and Export in Pakist...
PPT
Introduction, IoT Design Methodology, Case Study on IoT System for Weather Mo...
PPT
Total quality management ppt for engineering students
PDF
III.4.1.2_The_Space_Environment.p pdffdf
PDF
Exploratory_Data_Analysis_Fundamentals.pdf
PDF
Artificial Superintelligence (ASI) Alliance Vision Paper.pdf
PDF
COURSE DESCRIPTOR OF SURVEYING R24 SYLLABUS
PPTX
Artificial Intelligence
PDF
BIO-INSPIRED HORMONAL MODULATION AND ADAPTIVE ORCHESTRATION IN S-AI-GPT
ย 
PDF
Enhancing Cyber Defense Against Zero-Day Attacks using Ensemble Neural Networks
PPT
Occupational Health and Safety Management System
PDF
PPT on Performance Review to get promotions
PPTX
UNIT 4 Total Quality Management .pptx
PDF
Unit I ESSENTIAL OF DIGITAL MARKETING.pdf
PPTX
Fundamentals of Mechanical Engineering.pptx
Soil Improvement Techniques Note - Rabbi
6ME3A-Unit-II-Sensors and Actuators_Handouts.pptx
A5_DistSysCh1.ppt_INTRODUCTION TO DISTRIBUTED SYSTEMS
keyrequirementskkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkkk
Categorization of Factors Affecting Classification Algorithms Selection
ย 
Analyzing Impact of Pakistan Economic Corridor on Import and Export in Pakist...
Introduction, IoT Design Methodology, Case Study on IoT System for Weather Mo...
Total quality management ppt for engineering students
III.4.1.2_The_Space_Environment.p pdffdf
Exploratory_Data_Analysis_Fundamentals.pdf
Artificial Superintelligence (ASI) Alliance Vision Paper.pdf
COURSE DESCRIPTOR OF SURVEYING R24 SYLLABUS
Artificial Intelligence
BIO-INSPIRED HORMONAL MODULATION AND ADAPTIVE ORCHESTRATION IN S-AI-GPT
ย 
Enhancing Cyber Defense Against Zero-Day Attacks using Ensemble Neural Networks
Occupational Health and Safety Management System
PPT on Performance Review to get promotions
UNIT 4 Total Quality Management .pptx
Unit I ESSENTIAL OF DIGITAL MARKETING.pdf
Fundamentals of Mechanical Engineering.pptx
Ad

Securing Azure CosmosDb using Microsoft Defender

  • 1. Securing Azure Cosmos DB using Microsoft Defender Ankit Rao ๏ถ Senior Software Engineer at Zscaler ๏ถ Cloud and Cloud Security Enthusiast ๏ถ AWS Community Builder ๏ถ Pune (MH), India : @_AnkitRao : @ankit-rao
  • 2. Motivation Source: https://marketwatch.com ๏ถ The Global Cloud Security Market is expected to grow from USD 5 Billion in 2016 to USD ~13 billion by 2022, at an estimated CAGR of 17%. ๏ถ The lack of awareness about cloud security among organizations and the fear of losing their data confidentiality are among some factors restraining market growth. ๏ถ Further, the biggest identified cloud threats occur mostly due to the misconfiguration of cloud platforms.
  • 3. ๏ถAzure Cosmos DB โ€“ An overview ๏ถCloud Security โ€“ A shared responsibility model ๏ถMicrosoft Defender for Cosmos DB ๏ถAzure Cosmos DB โ€“ Security best practices ๏ถDemo ๏ถReferences Agenda
  • 5. Cloud Security โ€“ A shared responsibility model ๏ถ Cloud security refers to the technologies, policies, controls, and services that protect cloud data, applications, and infrastructure from threats. ๏ถ Cloud Security is a shared responsibility model. The diagram besides, shows how your responsibility decreases with a PaaS provider like Azure Cosmos DB.
  • 6. Microsoft Defender for Cosmos DB ๏ถ Microsoft Defender for Cosmos DB provides an extra layer of security intelligence that detects unusual and potentially harmful attempts to access or exploit Azure Cosmos DB accounts. ๏ถ This layer of protection allows you to address threats, even without being a security expert, and integrate them with central security monitoring systems. ๏ถ Security alerts are triggered when anomalies in activity occur. ๏ถ Access from unusual locations ๏ถ Unusual data extraction ๏ถ Further, Defender will provide a centralized view with respect to the security posture of the Cosmos DB, which helps users implement security best practices.
  • 7. Azure Cosmos DB โ€“ Security best practices Network security and firewall settings ๏ถUsing an IP firewall is the first layer of protection to secure your database. ๏ถAzure Cosmos DB supports policy driven IP- based access controls for inbound firewall support. ๏ถEnsure that Cosmos DB is accessible over selected networks only.
  • 8. Azure Cosmos DB โ€“ Security best practices Replicate data globally ๏ถ Global replication lets you scale globally, provide low-latency access to your data around the world. ๏ถ In the context of security, global replication ensures data protection against regional failures.
  • 9. Azure Cosmos DB โ€“ Security best practices Backup and Restore ๏ถAzure Cosmos databases are backed up regularly and stored in a geo redundant store. ๏ถAzure Cosmos DB's point-in-time restore feature helps in multiple scenarios such as the following: ๏ถ To recover from an accidental write or delete operation within a container. ๏ถ To restore a deleted account, database, or a container. ๏ถ To restore into any region (where backups existed) at the restore point in time.
  • 10. Azure Cosmos DB โ€“ Security best practices Key rotation ๏ถ Rotating keys periodically significantly reduces the chances that a compromised set of access keys can be used without your knowledge to access the database.
  • 11. Azure Cosmos DB โ€“ Security best practices Resource lock ๏ถResource lock prevents users in your organization from accidentally deleting or modifying critical resources. ๏ถThe lock overrides any permissions the user might have.
  • 12. Microsoft Defender for Cosmos DB - Demo
  • 13. ๏ถSecurity in Azure Cosmos DB ๏ถMicrosoft Defender for Cosmos DB (Preview) References
  • 15. Thank you! Enjoy the upcoming sessions!