Search icon CANCEL
Subscription
0
Cart icon
Cart
Close icon
You have no products in your basket yet
Save more on your purchases!
Savings automatically calculated. No voucher code required
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Microsoft Defender for Cloud Cookbook

You're reading from  Microsoft Defender for Cloud Cookbook

Product type Book
Published in Jul 2022
Publisher Packt
ISBN-13 9781801076135
Pages 314 pages
Edition 1st Edition
Languages
Author (1):
Sasha Kranjac Sasha Kranjac
Profile icon Sasha Kranjac
Toc

Table of Contents (12) Chapters close

Preface 1. Chapter 1: Getting Started with Microsoft Defender for Cloud 2. Chapter 2: Multi-Cloud Connectivity 3. Chapter 3: Workflow Automation and Continuous Export 4. Chapter 4: Secure Score and Recommendations 5. Chapter 5: Security Alerts 6. Chapter 6: Regulatory Compliance and Security Policy 7. Chapter 7: Microsoft Defender for Cloud Workload Protection 8. Chapter 8: Firewall Manager 9. Chapter 9: Information Protection 10. Chapter 10: Workbooks 11. Other Books You May Enjoy

Configuring GCP Security Command Center and enabling GCP Security Command Center API

For any environment that spans multiple cloud providers, cloud security services must span multiple cloud platforms as well.

Connecting a Google Cloud Platform (GCP) environment to Microsoft Defender for Cloud involves several steps. We will break this process into separate recipes so that this will be easier to understand and implement.

To onboard a Google Cloud Platform account into Microsoft Defender for Cloud, you need to configure GCP Security Center and enable Security Health Analytics first.

Getting ready

Before configuring GCP Security Center, you should have GCP Organization and a Google Cloud Identity account set up.

Open a web browser and navigate to https://console.cloud.google.com.

How to do it…

To onboard a GCP account into Microsoft Defender for Cloud, complete the following steps:

  1. In GCP Console, in the top-right corner select, an account. The selected account should belong to a GCP organization that contains or will contain a project you will connect to Security Command Center. If you already have a project, skip to Step 4.
  2. If the dashboard area is empty and you do not have a project, click Create project.
  3. On the New Project page, enter a value for Project name. Choose the project's Organization and Location and click Create.
  4. On the left-hand side menu, under Security, click Security Command Center. If you get a message stating Page not viewable for projects. This page is only viewable in the project/folder scope for Premium Tier organizations. Upgrade your organization to Premium, then from the drop-down menu on the right, select an Organization and click Select.
  5. If you get an error message stating You do not have sufficient permissions to view this page, from the top-left corner, click Google Cloud Platform. Then, under IAM & Admin menu, select IAM:
Figure 2.28 – Editing the service account role permissions

Figure 2.28 – Editing the service account role permissions

  1. Identify the account with an Organization Administrator role or the account that you are currently logged into and using to set up Security Command Center. To edit the account, click the pencil icon next to it.
  2. Click + ADD ANOTHER ROLE to add a role. Add the Security Center Admin, Security Admin, and Create Service Account roles and click SAVE:
Figure 2.29 – Adding roles to a service account

Figure 2.29 – Adding roles to a service account

  1. If you receive a message stating that Security Command Center has not been onboarded or activated yet, refresh the browser tab. Make sure you selected the right organization. After few moments, the Settings – Get started page should open, and Security Command Center, Standard tier should be selected. Click NEXT:
Figure 2.30 – Security Command Center – Choosing a tier

Figure 2.30 – Security Command Center – Choosing a tier

  1. On the Choose Services page, check whether Security Health Analytics is Enabled by default, and review the rest of the information. Click NEXT.
  2. On the Grant Permissions page, review the Required Roles and Service Account Created information. Click GRANT ROLES. The messages should indicate if the process of granting roles and the test have been completed. Click NEXT:
Figure 2.31 – Granting permissions to a service account

Figure 2.31 – Granting permissions to a service account

  1. On the Confirm page, Ready to complete setup will inform you that you are ready to finish setting up Security Command Center. Click FINISH to complete the Security Command Center setup process.
  2. Click the Vulnerabilities tab to display Security Health Analytics findings for the organization. To display Security Health Analytics for a project, under Projects Filter, click the plus (+) sign to Add a project to the Projects Filter.
  3. In GCP Console, under APIs & Services, click Dashboard. Click on Library or + ENABLE APIS AND SERVICES.
  4. On the Welcome to the API Library page, in the Search for APIs & Services search bar, type security.
  5. Click on an entry representing Security Command Center API:
Figure 2.32 – Choosing a Security Command Center API

Figure 2.32 – Choosing a Security Command Center API

  1. On the Security Command Center API page, click ENABLE.

How it works…

The first part of connecting a GCP account to Microsoft Defender for Cloud is to set up Security Command Center for your organization. First, you must grant appropriate permissions to an administrative account. This way, Security Command Center will display security-related information about services. Once you've completed the necessary setup, it may take some time for security information to be displayed in Security Command Center. To enable Security Command Center's functionality, you must provide access to cloud assets and findings within an organization via the Security Command Center API.

You have been reading a chapter from
Microsoft Defender for Cloud Cookbook
Published in: Jul 2022 Publisher: Packt ISBN-13: 9781801076135
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime