Video summary
Microsoft Defender for storage serves a dual purpose in securing enterprise data by addressing both pre-breach posture management and post-breach protection. On the defensive side, it ensures that storage accounts are not unnecessarily exposed to the internet or misconfigured with shared keys, while also identifying attack paths and sensitive data risks before an incident occurs. Complementing this is its advanced threat protection capability, which monitors for anomalous behaviors such as access from suspicious geographic locations or applications, unusual download patterns indicating potential data exfiltration, and other irregular activities that could signal a breach in progress.
A significant evolution highlighted in the discussion is the introduction of automated malware remediation capabilities specifically designed for Azure blobs. Previously, Defender would only alert administrators upon detecting malicious files without taking immediate action; now, when combined with soft delete features enabled on an account, the system can automatically quarantine and remove identified malware immediately after detection via upload scanning or manual on-demand scans. This proactive approach prevents further damage while maintaining data integrity through recoverable deletions, allowing security teams to analyze restored files later if necessary without losing critical evidence of the threat.
The solution offers flexible configuration options that allow organizations to tailor their security posture by enabling features at either a subscription level with specific exclusions or directly on individual storage accounts via opt-in settings for advanced capabilities like sensitive data discovery and event grid integration. While currently optimized primarily for Azure Blob Storage, including support for Data Lake Storage Gen2, the platform is expanding its reach; although full upload scanning for Azure Files shares is not yet available, it supports on-demand scans and threat detection there, with plans to introduce similar features soon alongside alternative quarantine methods that do not rely solely on soft delete profiles.
Technical limitations are clearly defined to ensure efficient operation without exhausting system resources, such as a file size cap of 50 gigabytes per scan and a depth limit for nested archives within zip files set at twenty levels to prevent memory issues. Users can further refine their security strategy by setting monthly scanning limits in terabytes, filtering out specific file types like unscannable encrypted PDFs or known safe formats such as JPEG images using prefix filters, and storing detailed results directly into index tags which incur associated costs but provide valuable metadata for automated workflows and deeper forensic analysis.
Read the full video transcript
Hello everyone and welcome to the Azure
storage talk podcast. Today we're diving
into Microsoft Defender for storage.
And specifically it's new malware
protection capabilities in Azure
storage. I'm your host Demetrius and
with me today is Eitan Bremler.
Now he's a key expert from the Microsoft
Defender for Cloud team.
And Eitan will also walk us through a
demo of these features. So sit tight and
hang around for the demo, okay?
So to set the stage for our security and
storage professional audience, let's
start with a
101 level basics.
So what is Microsoft Defender for
storage and also what types of threats
does it protect against?
So yeah, Microsoft Defender for storage
has been around for quite a few years.
If we look at Microsoft Defender for
storage today, you can look at it as
kind of
holding two legs in terms of storage
security. On the one hand, we have what
we call pre-breach or the posture
ensuring that storage is
and all the recommendations are
addressed, that storage is are not open
to the internet when you're not supposed
to, that you're not sharing keys when
you're not supposed to, rather using
entra IDs. So on the one hand, you have
all the pre-breach
recommendations and posture management.
We can show you the attack path, right?
Are there attack paths related to your
storage account?
Does it contain sensitive data which you
need to be aware of? Is it at risk? All
of that is part of our Defender for
Cloud offering.
On the other hand, we have our
post-breach protection, which is the run
part.
CWP,
protection, the cloud workload protect.
Which is divided into two capabilities.
One is our attack threat protection or
ATP, or advanced threat protection.
That's the original Defender for Storage
offering. That's how we started. The
idea behind our ATP is to detect
anomalous behavior on storage accounts.
Access from anomalous geo IPs. Access
from anomalous applications. Uh
anomalous data downloads, or what we
call data exfiltration.
And I'll touch about that in a second
when we talk about attacks.
Anomalous downloads. Like I said, so a
variety of anomalous
activity on a storage account.
The other hand, the other side, which is
what we added uh over the last couple of
years, is our malware protection.
And there we offer
uh multiple malware capabilities. It
could be malware scanning on an uploaded
file.
Or uh malware scanning on demand. If I
want to do kind of a on-demand or a
one-time scan or a
recurring scan.
Now, the reason we have our threat
protection and our malware scanning is
because the storages today are part of
different types of attacks.
A storage could be at the beginning of
an attack chain.
Or it could be at the end of an attack
chain.
I want to share with you a couple of use
cases that we see in our customers and
kind of talk about uh those attacks.
So, so until recently, Defender for
Storage was
more of a
security solution, rather than
So, we detected malware and we alerted
the battle. We did not take action.
Okay.
What recently we added, as I stated, is
our automated malware remediation
capabilities.
Which allow us, in case of blob, this is
a
blob uh feature at the moment, not for
Azure files, only for Azure blobs.
I'll explain in a second why.
What we're able to do is, once we detect
a malicious
uh malware blob
uh with malware either on upload or on
demand,
we can today automatically soft delete
it. This requires the soft delete
feature to be on within the storage
account.
And today soft delete is only allowed
for blobs. As the file doesn't allow
uh soft deleting a specific file only on
a file share. So, we're not doing that
at the moment, so it's only for blobs.
So,
uh once soft delete is enabled
or the soft delete the automatic
remediation is enabled on Defender for
Storage, we will enable soft delete
unless it's already enabled. And now
again, whenever we see a malicious blob,
we automatically delete it in storage.
It's recoverable because soft delete is
not permanent. You can recover it. And
the alert which will we send out will
not only say malicious blob found, but
also malicious blob deleted. So, the
user knows we deleted this malicious
blob. You can then go back, restore it,
analyze it, and then take further
actions.
And how does one enable this feature?
And is it on by default or something
that needs configuration?
So, Defender for Storage is on by
default, right? It's a capability
that you can either enable on your sub-
sub-
or per storage account.
So, we have the flexibility of how to
enable it. You can enable it on a
complete subscription and then exclude
specific storage account.
Um and within Defender for Storage, once
you enable it,
you have opt-in features.
For example, do I want to do on demand?
Is it opt-in? It's a manual action you
need to do.
So, um
soft delete is opt-in.
Uh you could use index tags
for example to store
uh the results of a scan that is up in.
You could use event grid
or log analytics to send out all the
alerts to the alerts table but also to
your event grid or your log bar that is
up in.
So most of the features within the
defender for storage plan that are up in
the customer chooses what they wish to
use. All right, so let's say so defender
storage it gives you both a a safety net
and also the hooks to build more
sophisticated responses if we need them.
And I I also want to touch on the the
scope of coverage.
So we know that as your storage isn't
just blobs, right? It it includes azure
files. I know you mentioned some things
that azure files does not support
for example
like a lot of enterprises use azure
azure files for file shares, but what is
the support for azure files in the
context of these malware protection
features?
Great questions. So yeah, like you said
azure storage is not only azure blobs.
It's azure blobs, it's data lakes, it's
azure files, there's tables, there's
queues.
So we support predominantly today until
now we support mainly azure blobs,
standard blobs or premium blobs and
there you have the features at on upload
now or scanning on demand now or
scanning
and
ATP the threat protection, sensitive
data discovery you can detect sensitive
blobs within storage accounts.
On the azure file side, we support the
on demand malware scanning.
We have the the threat detection and the
sensitive data discovery. What you do
not have today on azure files is on
upload malware scanning that is coming
in a road.
And the soft delete again because soft
delete is a
profile, we will have a solution
probably using quarantine capabilities
rather than soft delete. We also support
ADLS Gen2 storage account because
they're very similar to blobs. Tables,
queues are not supported. Right? So,
we're mainly looking at the the blob the
object storages.
My files. So, to summarize the 201
section, so we've learned about you
know, how to enable the features. It's
opt-in via the the portal or the API.
Also, how it works under under the
hoods, soft deletes, and also event
integration.
And maybe you could talk about some of
the key limits and and maybe some of the
best practices as well.
>> So, we have a file size limit.
Right? So, we support files up to 50 50
gigabytes. Above that, uh we don't
support. It's important to understand
that our malware scanning, we use
uh Microsoft AV.
Uh it's not our own malware scanner. We
use the standardized malware scan you
have in your different point protection
in all of the different scanners within
Microsoft security system. It's the same
engine.
Um so, we have the limitation for the
gigabytes. We also cannot scan, for
example, files encrypted with user keys
because we don't have the user keys. So,
those files will be skipped. Usually,
or you will get an error saying file's
encrypted. Uh a PDF which is which is
encrypted, if we're not we might be able
to open it or we might we might not.
Depends on the the level of encryption.
We'll We report on everything. So, you
will know when you scan whether it was
successful, skipped because we would not
scan it. Let's say it's large.
Or
uh if it will if it failed, for example,
in zip files, we have the depth limit
of about 20
sub
subfolder within a zip. The reason we
limit it is because at the end of the
day it could exhaust the memory of the
scan machine. So, we took we looked at
user behavior and user data and said,
"Okay, 20 level depth is good enough."
All the all the limitations, all the
prerequisites are all available on the
Defender for Cloud and Defender for
Storage documentation in learn.
What we have here, this is the Defender
for Cloud
blade under a storage account. So, my
storage account is called Woodrow taxes.
You can see here under I have my
containers, I have my subfolders, and
here I have my Defender for Cloud blade.
Now, in the Defender for Cloud blade,
you can see quite all of the
information. You can see that the system
the Defender for Storage plan is is on.
You can see that the the three main
subplans are on as well. Activity
monitoring, what we call the
ATP, sensitive data threat detection,
and the on-upload malware scanning,
which also includes the on-demand
malware scan.
If I click settings, you can see here
the variety of settings we have. You can
choose to opt out and turn off
the the different features. You can turn
off the type plan, you can turn off uh
the on-upload malware scanning, you can
opt uh
turn off sensitive data discovery.
You can override subscription level
capabilities and do everything on the
storage account.
You can set a limit to how much
gigabytes you want to scan per month.
This is 5,000 gigabytes. This is for the
old upload. Above that, we will stop
scanning.
You can filter out what you do not want
to scan on upload? So, different
prefixes. So, if you know you have
JPEGs, for example, that there's no
reason to scan, you could filter out.
You can choose to store
Sorry.
Uh
results within index tags or choose to
store them. Keep in mind, index tags do
incur costs.
The soft delete and the different
options of sending results, which you
can use also for further automation.
So, these are all the setting.
What we can see here is our on-demand
malware scanning uh
interface. You can see here I scanned 47
objects on my last scan, how much it
would cost me, that there were threats,
how many gigabytes.
You can see the different
recommendations that we provide you for
this storage account.
For example, use private link
or uh use keys for encryption
or restrict network access. All of these
are recommendations that our Defender
for Cloud recognized for this storage
account and display.
And you can also see the different
alerts for this storage account.
So, if I go in for the specific alerts,
you can see here we have
two alerts.
Malicious file uploaded and malicious
file uploaded and deleted. But, we
talked about the fact that you could
either choose to use soft delete or not.
So, this is when soft delete was enabled
and this is when soft delete was
disabled.
And you And so, you see the difference.
The user understands very clearly if the
file was deleted or not.
Before I go to a live showing you of how
this works, I do want to show you a few
of the alerts. So, we have the malware
alerts, like we saw here.
But, we also have our advanced
protection alerts.
For example, blob downloaded is an
advanced threat protection alert. So, if
someone downloaded a file we know has
malware, you will get an alert.
Publicly accessible storage container
has been exposed. If someone was doing a
drive-by and scanning a storage account,
we'll recognize it using our advanced
threat protection. So, you're covered
across the board, advanced protection
and malware scanning.
So, if I go back here,
what I can do here, there's a few
options we can do for malware scanning.
One is doing an on-demand malware
scanning. This now goes and scans my
entire storage account.
My blobs
my files, my containers and my files
is a burden.
You can see here, it's waiting for
completion.
You'll have the scan duration, how much
gigabytes did I scan?
Threats found. It's
Now it's complete again, scan my entire
storage account.
In addition, if I go here for a
container,
for example,
and go to my mean
container,
I can upload a file.
So, I can browse.
And I can upload here my file,
which actually contains a malware in it.
Now,
if I you can see here,
the file, if I refresh, you see the file
was deleted, because the soft delete is
on. So, if I show
my files, you can see
this has been deleted.
Right? Because it's malware.
If I go in here,
you'll see the file was deleted.
Now if I do undelete
because I want to restore it
and go and see look at it now when it's
undeleted, you can see here we have
index tags because I chose to use index
tags, you see this file is malicious.
So you have all the information here
and if I do will now go to my alerts
and refresh
I will see my new alerts here. Right?
This is from today, just now real-time
alerts. You can see that it was deleted.
So everything is managed through here.
Right?
You can see exactly uh what happened,
what we found.
This actually this file, by the way
this is a file rather than a blob. So I
was deleted.
You can also see here very nicely that
we recognize sensitive info tags.
Right? So when we scan the file
we recognize sensitive info tags. Not
only does it have any malware but it
also have sensitive info tags within the
file itself.
So you get a lot of information from the
system. There was malware, you have
sensitive info tags.
Go and look at them.
Do you need them? Are they
causing you uh over uh risk?
So that's been high level what Defender
for Storage offers.
Well, let's begin to wrap up and I I
really appreciate you sharing that. It's
been a really insightful discussion and
I myself appreciate walking through that
demo along with you. I've learned a lot
as well and so just to recap we covered
the fundamentals of Microsoft Defender
for Storage's threat protection.
The new automated remediation and when
that's with how it quarantines malware
and blobs,
and the current status of Azure files
support, and some deeper technical
considerations as well. So,
thank you so much, Itan, for sharing
your expertise here today.
And uh any any um final thing that you
would like to propose or point the
audience to just for further reading.
We're always
big more capabilities. Moving forward,
we're adding more capabilities. I'll
give you just a tip. Uh a few days
before me on this channel, uh you talked
about storage center with Fabian.
I'm actually very happy to say that in
the next few weeks, we will be visible
in storage center as well. So, going
into storage center, you will be able to
see per storage account all the cool
stuff Fabian showed you, but also do you
have Defender for storage coverage? So,
we're very happy to be integrated with
the Azure storage team, and we'll
continue to work on that integration and
release new features as we move forward.
Right, it's been truly awesome. And to
the listeners out there,
uh if you like this episode, please hit
that thumbs up button, and also be sure
to subscribe because most people just
watch and don't subscribe. So, we really
would appreciate you subscribing to the
channel as well.
And this has been another episode of
Azure Storage talk. So, Itan, thank you
so much.
Thank