Enabling Microsoft Defender for Cloud via Azure Policy
Azure Policy comes with a variety of built-in policy definitions, one of which is used to enable Microsoft Defender for Cloud on the scope you chose. In order to enable the service on all existing and future subscriptions, it's enough to simply assign the Enable Azure Security Center on your subscription policy to your root management group. To onboard a management group and all its subscriptions to Defender for Cloud, follow these steps: 1. Make sure to log in with an account that has Security Admin permissions, open Azure Policy, and search for the Enable Azure Security Center on your subscription policy definition. Figure 1.1 – Policy definition to enable Defender for Cloud 2. Select the definition, and then click Assign: Figure 1.2 – Assigning the policy definition 3. Select Tenant Root Group as the assignment scope. There are no other parameters you need to change. Figure 1.3 – Assigning the policy definition to your Tenant Root Group 4. Cl...