Submind YouTube summaries
Thumbnail for This Microsoft Defender Feature Saves Companies Millions Annually

This Microsoft Defender Feature Saves Companies Millions Annually

Watch on YouTube

Video summary

Microsoft Defender for storage serves a dual purpose in securing enterprise data by addressing both pre-breach posture management and post-breach protection. On the defensive side, it ensures that storage accounts are not unnecessarily exposed to the internet or misconfigured with shared keys, while also identifying attack paths and sensitive data risks before an incident occurs. Complementing this is its advanced threat protection capability, which monitors for anomalous behaviors such as access from suspicious geographic locations or applications, unusual download patterns indicating potential data exfiltration, and other irregular activities that could signal a breach in progress. A significant evolution highlighted in the discussion is the introduction of automated malware remediation capabilities specifically designed for Azure blobs. Previously, Defender would only alert administrators upon detecting malicious files without taking immediate action; now, when combined with soft delete features enabled on an account, the system can automatically quarantine and remove identified malware immediately after detection via upload scanning or manual on-demand scans. This proactive approach prevents further damage while maintaining data integrity through recoverable deletions, allowing security teams to analyze restored files later if necessary without losing critical evidence of the threat. The solution offers flexible configuration options that allow organizations to tailor their security posture by enabling features at either a subscription level with specific exclusions or directly on individual storage accounts via opt-in settings for advanced capabilities like sensitive data discovery and event grid integration. While currently optimized primarily for Azure Blob Storage, including support for Data Lake Storage Gen2, the platform is expanding its reach; although full upload scanning for Azure Files shares is not yet available, it supports on-demand scans and threat detection there, with plans to introduce similar features soon alongside alternative quarantine methods that do not rely solely on soft delete profiles. Technical limitations are clearly defined to ensure efficient operation without exhausting system resources, such as a file size cap of 50 gigabytes per scan and a depth limit for nested archives within zip files set at twenty levels to prevent memory issues. Users can further refine their security strategy by setting monthly scanning limits in terabytes, filtering out specific file types like unscannable encrypted PDFs or known safe formats such as JPEG images using prefix filters, and storing detailed results directly into index tags which incur associated costs but provide valuable metadata for automated workflows and deeper forensic analysis.
Read the full video transcript
Hello everyone and welcome to the Azure storage talk podcast. Today we're diving into Microsoft Defender for storage. And specifically it's new malware protection capabilities in Azure storage. I'm your host Demetrius and with me today is Eitan Bremler. Now he's a key expert from the Microsoft Defender for Cloud team. And Eitan will also walk us through a demo of these features. So sit tight and hang around for the demo, okay? So to set the stage for our security and storage professional audience, let's start with a 101 level basics. So what is Microsoft Defender for storage and also what types of threats does it protect against? So yeah, Microsoft Defender for storage has been around for quite a few years. If we look at Microsoft Defender for storage today, you can look at it as kind of holding two legs in terms of storage security. On the one hand, we have what we call pre-breach or the posture ensuring that storage is and all the recommendations are addressed, that storage is are not open to the internet when you're not supposed to, that you're not sharing keys when you're not supposed to, rather using entra IDs. So on the one hand, you have all the pre-breach recommendations and posture management. We can show you the attack path, right? Are there attack paths related to your storage account? Does it contain sensitive data which you need to be aware of? Is it at risk? All of that is part of our Defender for Cloud offering. On the other hand, we have our post-breach protection, which is the run part. CWP, protection, the cloud workload protect. Which is divided into two capabilities. One is our attack threat protection or ATP, or advanced threat protection. That's the original Defender for Storage offering. That's how we started. The idea behind our ATP is to detect anomalous behavior on storage accounts. Access from anomalous geo IPs. Access from anomalous applications. Uh anomalous data downloads, or what we call data exfiltration. And I'll touch about that in a second when we talk about attacks. Anomalous downloads. Like I said, so a variety of anomalous activity on a storage account. The other hand, the other side, which is what we added uh over the last couple of years, is our malware protection. And there we offer uh multiple malware capabilities. It could be malware scanning on an uploaded file. Or uh malware scanning on demand. If I want to do kind of a on-demand or a one-time scan or a recurring scan. Now, the reason we have our threat protection and our malware scanning is because the storages today are part of different types of attacks. A storage could be at the beginning of an attack chain. Or it could be at the end of an attack chain. I want to share with you a couple of use cases that we see in our customers and kind of talk about uh those attacks. So, so until recently, Defender for Storage was more of a security solution, rather than So, we detected malware and we alerted the battle. We did not take action. Okay. What recently we added, as I stated, is our automated malware remediation capabilities. Which allow us, in case of blob, this is a blob uh feature at the moment, not for Azure files, only for Azure blobs. I'll explain in a second why. What we're able to do is, once we detect a malicious uh malware blob uh with malware either on upload or on demand, we can today automatically soft delete it. This requires the soft delete feature to be on within the storage account. And today soft delete is only allowed for blobs. As the file doesn't allow uh soft deleting a specific file only on a file share. So, we're not doing that at the moment, so it's only for blobs. So, uh once soft delete is enabled or the soft delete the automatic remediation is enabled on Defender for Storage, we will enable soft delete unless it's already enabled. And now again, whenever we see a malicious blob, we automatically delete it in storage. It's recoverable because soft delete is not permanent. You can recover it. And the alert which will we send out will not only say malicious blob found, but also malicious blob deleted. So, the user knows we deleted this malicious blob. You can then go back, restore it, analyze it, and then take further actions. And how does one enable this feature? And is it on by default or something that needs configuration? So, Defender for Storage is on by default, right? It's a capability that you can either enable on your sub- sub- or per storage account. So, we have the flexibility of how to enable it. You can enable it on a complete subscription and then exclude specific storage account. Um and within Defender for Storage, once you enable it, you have opt-in features. For example, do I want to do on demand? Is it opt-in? It's a manual action you need to do. So, um soft delete is opt-in. Uh you could use index tags for example to store uh the results of a scan that is up in. You could use event grid or log analytics to send out all the alerts to the alerts table but also to your event grid or your log bar that is up in. So most of the features within the defender for storage plan that are up in the customer chooses what they wish to use. All right, so let's say so defender storage it gives you both a a safety net and also the hooks to build more sophisticated responses if we need them. And I I also want to touch on the the scope of coverage. So we know that as your storage isn't just blobs, right? It it includes azure files. I know you mentioned some things that azure files does not support for example like a lot of enterprises use azure azure files for file shares, but what is the support for azure files in the context of these malware protection features? Great questions. So yeah, like you said azure storage is not only azure blobs. It's azure blobs, it's data lakes, it's azure files, there's tables, there's queues. So we support predominantly today until now we support mainly azure blobs, standard blobs or premium blobs and there you have the features at on upload now or scanning on demand now or scanning and ATP the threat protection, sensitive data discovery you can detect sensitive blobs within storage accounts. On the azure file side, we support the on demand malware scanning. We have the the threat detection and the sensitive data discovery. What you do not have today on azure files is on upload malware scanning that is coming in a road. And the soft delete again because soft delete is a profile, we will have a solution probably using quarantine capabilities rather than soft delete. We also support ADLS Gen2 storage account because they're very similar to blobs. Tables, queues are not supported. Right? So, we're mainly looking at the the blob the object storages. My files. So, to summarize the 201 section, so we've learned about you know, how to enable the features. It's opt-in via the the portal or the API. Also, how it works under under the hoods, soft deletes, and also event integration. And maybe you could talk about some of the key limits and and maybe some of the best practices as well. >> So, we have a file size limit. Right? So, we support files up to 50 50 gigabytes. Above that, uh we don't support. It's important to understand that our malware scanning, we use uh Microsoft AV. Uh it's not our own malware scanner. We use the standardized malware scan you have in your different point protection in all of the different scanners within Microsoft security system. It's the same engine. Um so, we have the limitation for the gigabytes. We also cannot scan, for example, files encrypted with user keys because we don't have the user keys. So, those files will be skipped. Usually, or you will get an error saying file's encrypted. Uh a PDF which is which is encrypted, if we're not we might be able to open it or we might we might not. Depends on the the level of encryption. We'll We report on everything. So, you will know when you scan whether it was successful, skipped because we would not scan it. Let's say it's large. Or uh if it will if it failed, for example, in zip files, we have the depth limit of about 20 sub subfolder within a zip. The reason we limit it is because at the end of the day it could exhaust the memory of the scan machine. So, we took we looked at user behavior and user data and said, "Okay, 20 level depth is good enough." All the all the limitations, all the prerequisites are all available on the Defender for Cloud and Defender for Storage documentation in learn. What we have here, this is the Defender for Cloud blade under a storage account. So, my storage account is called Woodrow taxes. You can see here under I have my containers, I have my subfolders, and here I have my Defender for Cloud blade. Now, in the Defender for Cloud blade, you can see quite all of the information. You can see that the system the Defender for Storage plan is is on. You can see that the the three main subplans are on as well. Activity monitoring, what we call the ATP, sensitive data threat detection, and the on-upload malware scanning, which also includes the on-demand malware scan. If I click settings, you can see here the variety of settings we have. You can choose to opt out and turn off the the different features. You can turn off the type plan, you can turn off uh the on-upload malware scanning, you can opt uh turn off sensitive data discovery. You can override subscription level capabilities and do everything on the storage account. You can set a limit to how much gigabytes you want to scan per month. This is 5,000 gigabytes. This is for the old upload. Above that, we will stop scanning. You can filter out what you do not want to scan on upload? So, different prefixes. So, if you know you have JPEGs, for example, that there's no reason to scan, you could filter out. You can choose to store Sorry. Uh results within index tags or choose to store them. Keep in mind, index tags do incur costs. The soft delete and the different options of sending results, which you can use also for further automation. So, these are all the setting. What we can see here is our on-demand malware scanning uh interface. You can see here I scanned 47 objects on my last scan, how much it would cost me, that there were threats, how many gigabytes. You can see the different recommendations that we provide you for this storage account. For example, use private link or uh use keys for encryption or restrict network access. All of these are recommendations that our Defender for Cloud recognized for this storage account and display. And you can also see the different alerts for this storage account. So, if I go in for the specific alerts, you can see here we have two alerts. Malicious file uploaded and malicious file uploaded and deleted. But, we talked about the fact that you could either choose to use soft delete or not. So, this is when soft delete was enabled and this is when soft delete was disabled. And you And so, you see the difference. The user understands very clearly if the file was deleted or not. Before I go to a live showing you of how this works, I do want to show you a few of the alerts. So, we have the malware alerts, like we saw here. But, we also have our advanced protection alerts. For example, blob downloaded is an advanced threat protection alert. So, if someone downloaded a file we know has malware, you will get an alert. Publicly accessible storage container has been exposed. If someone was doing a drive-by and scanning a storage account, we'll recognize it using our advanced threat protection. So, you're covered across the board, advanced protection and malware scanning. So, if I go back here, what I can do here, there's a few options we can do for malware scanning. One is doing an on-demand malware scanning. This now goes and scans my entire storage account. My blobs my files, my containers and my files is a burden. You can see here, it's waiting for completion. You'll have the scan duration, how much gigabytes did I scan? Threats found. It's Now it's complete again, scan my entire storage account. In addition, if I go here for a container, for example, and go to my mean container, I can upload a file. So, I can browse. And I can upload here my file, which actually contains a malware in it. Now, if I you can see here, the file, if I refresh, you see the file was deleted, because the soft delete is on. So, if I show my files, you can see this has been deleted. Right? Because it's malware. If I go in here, you'll see the file was deleted. Now if I do undelete because I want to restore it and go and see look at it now when it's undeleted, you can see here we have index tags because I chose to use index tags, you see this file is malicious. So you have all the information here and if I do will now go to my alerts and refresh I will see my new alerts here. Right? This is from today, just now real-time alerts. You can see that it was deleted. So everything is managed through here. Right? You can see exactly uh what happened, what we found. This actually this file, by the way this is a file rather than a blob. So I was deleted. You can also see here very nicely that we recognize sensitive info tags. Right? So when we scan the file we recognize sensitive info tags. Not only does it have any malware but it also have sensitive info tags within the file itself. So you get a lot of information from the system. There was malware, you have sensitive info tags. Go and look at them. Do you need them? Are they causing you uh over uh risk? So that's been high level what Defender for Storage offers. Well, let's begin to wrap up and I I really appreciate you sharing that. It's been a really insightful discussion and I myself appreciate walking through that demo along with you. I've learned a lot as well and so just to recap we covered the fundamentals of Microsoft Defender for Storage's threat protection. The new automated remediation and when that's with how it quarantines malware and blobs, and the current status of Azure files support, and some deeper technical considerations as well. So, thank you so much, Itan, for sharing your expertise here today. And uh any any um final thing that you would like to propose or point the audience to just for further reading. We're always big more capabilities. Moving forward, we're adding more capabilities. I'll give you just a tip. Uh a few days before me on this channel, uh you talked about storage center with Fabian. I'm actually very happy to say that in the next few weeks, we will be visible in storage center as well. So, going into storage center, you will be able to see per storage account all the cool stuff Fabian showed you, but also do you have Defender for storage coverage? So, we're very happy to be integrated with the Azure storage team, and we'll continue to work on that integration and release new features as we move forward. Right, it's been truly awesome. And to the listeners out there, uh if you like this episode, please hit that thumbs up button, and also be sure to subscribe because most people just watch and don't subscribe. So, we really would appreciate you subscribing to the channel as well. And this has been another episode of Azure Storage talk. So, Itan, thank you so much. Thank