Microsoft Certified: Azure Security Engineer AssociateManage security operationsHard

A company is implementing Microsoft Defender for Cloud and needs to ensure that all Azure subscriptions within their tenant are continuously monitored for security posture, regulatory compliance, and threat protection, even newly created ones. They want to avoid manually onboarding each subscription. How should they configure Defender for Cloud to meet this requirement?

  1. AUse Azure Policy to enforce Defender for Cloud enablement on subscriptions.
  2. BOnboard subscriptions through the Defender for Cloud pricing and settings blade.
  3. CConnect the Azure AD tenant root management group to Defender for Cloud.
  4. DEnable Defender for Cloud for each subscription individually.
Show answer & explanation

Correct answer: C. Connect the Azure AD tenant root management group to Defender for Cloud.

Connecting the Azure AD tenant root management group to Defender for Cloud ensures that all current and future subscriptions under that tenant are automatically onboarded and monitored.

Why the other options are wrong

  • A. While Azure Policy can enforce settings, directly connecting the root management group is the primary mechanism for tenant-wide onboarding for Defender for Cloud.
  • B. This is typically done for individual subscriptions or management groups, not the entire tenant automatically for future subscriptions.
  • D. This requires manual intervention for each subscription and doesn't cover future ones automatically.

Defender for Cloud Tenant Onboarding

Onboarding the Azure AD tenant root management group to Microsoft Defender for Cloud automatically enables monitoring and protection for all current and future subscriptions within that tenant.

  • Provides tenant-wide visibility and control.
  • Simplifies onboarding for large organizations.
  • Ensures consistent security posture across all subscriptions.

Memory trick: The 'root' of your tenant secures the whole 'tree'.

More Manage security operations questions