-
Notifications
You must be signed in to change notification settings - Fork 981
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update Microsoft Defender for Cloud plan for Containers #876
Conversation
@faister Could you perform the testing here for China (Mooncake)? I have updated the guidance and all the code so should just need deploying and testing 👍 Can all be found in my fork/branch here: https://github.com/jtracey93/Enterprise-Scale/tree/fix-874-mdfc-containers Let me know 👍 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
@jtracey93 Sounds good, will try to get some testing done before we speak mid-week. Trying to finish off the other task I told you about. |
Thanks @faister, this should also fit into that other piece of work nicely 👍 If you can test before mid-week (just need the definitions and assignments tested really, confirming the new built-in definition |
@jtracey93 All good! The new built-in definition |
@Azure/enterprisescale-vteam @Azure/customer-architecture-team - This is now ready for review/approval as testing in all 3 clouds has been completed and attached as evidence above 👍👍 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM - good work @jtracey93
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Overview/Summary
As described in issue #874, Microsoft Defender for Cloud has released a new plan to all clouds (Public, Gov, China) for Containers that replaces the plans for Kubernetes & Container Registries.
This has now gone GA as per the announcement here: https://docs.microsoft.com/azure/defender-for-cloud/release-notes#microsoft-defender-for-containers-plan-released-for-general-availability-ga.
This PR fixes/adds/changes/removes
Deploy-ASCDF-Config
initiative to use the new plan and policy and removed the Kubernetes & Container Registry plan/policies from the initiative, as shown in the below table:Breaking Changes
None. However, customers should review the guidance here around the plan changes and what it means for existing subscriptions and new subscriptions: https://docs.microsoft.com/azure/defender-for-cloud/release-notes#microsoft-defender-for-containers-plan-released-for-general-availability-ga
Testing Evidence
Public (Commercial)
URL to test yourself: https://portal.azure.com/#blade/Microsoft_Azure_CreateUIDef/CustomDeploymentBlade/uri/https%3A%2F%2Fraw.neting.cc%2Fjtracey93%2FEnterprise-Scale%2Ffix-874-mdfc-containers%2FeslzArm%2FeslzArm.json/uiFormDefinitionUri/https%3A%2F%2Fraw.neting.cc%2Fjtracey93%2FEnterprise-Scale%2Ffix-874-mdfc-containers%2FeslzArm%2Feslz-portal.json
China (Mooncake)
Tested here by @faister #876 (comment)
Gov (Fairfax)
Tested by @rspott (thanks 👍)
As part of this Pull Request I have
main
branch/docs/wiki/whats-new.md
)