安全中心建议-CLI-是否要关闭? [英] Security Centre recommendations - CLI - Turning off?
问题描述
嗨
我有一个安全策略,其中我的所有组件都符合标准(100%符合标准).我的Azure Advisor中也没有任何建议.但是,我还有一个 不会消失的资源安全卫生" 建议.因此,我有许多问题无法在您的文档中找到答案
I have a security policy where all my components are compliant (100% compliance). I have no recommendations in my Azure Advisor either. However, I still have one "Resource Security Hygiene" recommendation that would just not go away. So I have a number of questions that i can't find answers for in your documentations
(1)这些建议在哪里确定?这些建议与我的政策之间的对应关系在哪里?
(1) Where are these recommendations determined? Where is the mapping between these recommendations and my policy?
(2)我需要能够关闭其中一些建议,因为我的客户已经在Azure之外实现了MFA,并且不希望添加更多.我该怎么办?
(2) I need to be able to turn off some of these recommendations because my client already has MFA implemented outside of Azure, and don't wish to add more. How do i do that please?
(3)我需要通过PowerShell访问这些建议.是否有模块或其他工具可以轻松关闭这些建议?我知道Azure Advisor具有,但这不是我想要的,我想要安全中心中的安全卫生 建议.
(3) I need to access these recommendations via PowerShell. Is there a module or anything that provides an easy access to turn off these recommendations? I know that Azure Advisor has, but that's not what I want, I want Security Hygiene in the security centre recommendations.
感谢您的帮助吗?
推荐答案
您好 HannaH021 ,
我们了解您对Azure安全中心门户中的建议存在疑问.请根据要求找到答案.
1.建议的确定不仅取决于您的安全策略以及后端的许多其他因素.该建议到底是什么?它显示了哪些缓解措施?
2.尽管已经启用了MFA,但此建议是否仍与MFA违规有关??如果您可以共享屏幕截图和更多详细信息,将很有帮助.或者,您可以按照以下步骤取消建议
We understand you have questions on a suggested recommendation in your Azure Security Center portal. Please find the answers as requested.
1. The recommendations are determined not just on the basis of your security policy and many other factors in the back-end . What exactly is the recommendation about and what mitigation steps does it show ?
2. Is this recommendations somehow related to MFA non-compliance despite MFA being already enabled ?? If you could share screenshots and some more details it will be helpful. Alternatively you could follow the following steps to dismiss the recommendations
individually .
- 转到资源安全卫生"中的安全评分"图块.框架.它应该列出类似"7份积极建议"之类的内容.如下图所示.
- 单击活动推荐"的链接后,它将带您进入下图所示的下一个刀片.
-
但是,我不认为可以通过powershell批量完成此操作.即使单个项目将被撤消,安全评分仍将继续显示建议.
However , I do not think that this can be done in bulk through powershell. And the Secure Score will still continue to display recommendations even though the individual items would have been dismissed.
3.请使用以下ASC Powershell模块.提供了来自github的示例链接.但是,似乎并不能使用Powershell来访问建议.
ASC Powershell模块:- https://www. powershellgallery.com/packages/AzureRM.Security/0.2.0-preview
ASC Powershell参考:- https://github.com/Azure/azure-powershell/blob/preview/src/ResourceManager/Security/Commands.Security/help/AzureRM.Security.md
ASC示例:- https://github.com/Microsoft/Azure-Security-Center/blob/master/quickstarts/ASC-Samples.ps13. Please use the following ASC powershell modules. A link for sample from github is provided. However It dos not seem that you would be able to access the recommendations using powershell.
ASC Powershell Module :- https://www.powershellgallery.com/packages/AzureRM.Security/0.2.0-preview
ASC Powershell Reference :- https://github.com/Azure/azure-powershell/blob/preview/src/ResourceManager/Security/Commands.Security/help/AzureRM.Security.md
ASC sample :- https://github.com/Microsoft/Azure-Security-Center/blob/master/quickstarts/ASC-Samples.ps1请查看有关如何安装模块的博客. https://blogs.technet.microsoft.com/germanageability/2018/09/04/installing-and-testing-the-new-azure-security-center-preview-cmdlets/
Get-AzureRmSecurityTask 将为您提供针对应用该策略的每种资源所建议的建议类型的详细信息.
我们期待在同一方面为您提供更多帮助.如果以上信息对您有帮助,请标记为答案,以使社区受益.
谢谢.Please check the blog on how to install the module. https://blogs.technet.microsoft.com/germanageability/2018/09/04/installing-and-testing-the-new-azure-security-center-preview-cmdlets/
Get-AzureRmSecurityTask will give you details of the types of recommendation suggested for each resource where the policy is applied.
We look forward to helping you more on the same. In case the above information helped you , please mark it as answer so that it can benefit the community .
Thank you.
这篇关于安全中心建议-CLI-是否要关闭?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!