Red Canary Managed Security Service Provider (MSSP) Access Instructions for Azure P1 will provide Red Canary organization members with direct access to your Microsoft Defender Security Center console.
These instructions are intended for customers who use Microsoft Azure P1 type licenses, which does not allow access to the Identity Governance features of Azure. If you have an E5/A5 license, see Connecting Red Canary to Microsoft Defender for Endpoint in the Red Canary Help Center.
Granting Red Canary Access consists of three steps:
- Prepare Microsoft Azure group for RBAC
- Enable Role Based Access Controls in MDE
- Add Red Canary Shared User
Before beginning the MSSP Access process for Azure P1, you will need to have access to an account with Security Administrator privileges within your Azure organization.
Prepare Microsoft Azure group for RBAC and bulk uploading Red Canary users to Azure.
- Navigate to https://portal.azure.com and log in with your Global or Security Administrator Microsoft account.
- Expand the navigation pane on the left hand side of the page and select Azure Active Directory.
- Select Groups.
- Click New Group.
- Fill in the group parameters with the following:
- Group Type: Security
- Group Name: Red Canary
- Group Description: Red Canary Access Group
- Azure AD roles can be assigned to the group: Yes
- Membership Type: Assigned
- Owners: No owners selected
- Members: No members selected
- Click Create.
Enable Role Based Access Controls in Microsoft Defender for Endpoint.
- Navigate to https://securitycenter.windows.com and log in with your Global Administrator Microsoft account.
- Click Settings | Roles | Add Item.
- Configure permissions for the new role.
- Role Name: Red Canary
- Description: Red Canary Access Role
- Select the following Permissions boxes only.
- View Data
- Security Operations
- Threat and Vulnerability Management
- Active Remediation Actions
- Security Operations
- Alerts Investigation
- Live Response Capabilities
- Basic
- View Data
- Click Assigned User Groups.
- Select the group named Red Canary.
- Click Add Selected Groups.
- Click Save.
Add the Red Canary shared user account
- Navigate to https://portal.azure.com and log in with your Global or Security Administrator Microsoft account.
- Expand the navigation pane and select Azure Active Directory.
- Select Users.
- Select New Guest User.
- Choose Create a User.
- Fill in the group parameters with the following:
- Identity
- User Name: redcanary
- Email Address: <Red Canary will provide you this email address>
- Name: Red Canary
- First Name: Leave blank
-
Last Name: Leave blank
-
Groups and Roles
-
Groups: Select the Red Canary group you just created.
-
Roles: <Don't select a role. Adding a role in this step will cause an error.>
-
-
Settings
-
Block Login: Off
-
Usage Location: United States
-
-
Leave Job Info blank.
- Identity
-
Click Create.
Add the security reader role to your Red Canary account
- Navigate to https://portal.azure.com, and then log in with your Global or Security Administrator Microsoft account.
- Expand the navigation pane, and then select Azure Active Directory.
- Select Users.
- Choose the Red Canary user that you created earlier.
- Select Assigned Roles.
- Click Add assignments.
- Select the Security Reader role.
- Click Add.
Comments
0 comments
Please sign in to leave a comment.