Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security engineer is setting up a new Azure subscription for a development team. They need to ensure that all new storage accounts created in this subscription automatically enable advanced threat protection (Microsoft Defender for Storage). How can this be achieved with the least administrative effort?

  1. AManually enable Defender for Storage on each new storage account.
  2. BCreate an Azure Policy with a 'DeployIfNotExists' effect to enable Defender for Storage on storage accounts.
  3. CConfigure a Microsoft Defender for Cloud automation to enable Defender for Storage when a new storage account is detected.
  4. DWrite an Azure Resource Manager (ARM) template to deploy storage accounts with Defender for Storage enabled.
Show answer & explanation

Correct answer: B. Create an Azure Policy with a 'DeployIfNotExists' effect to enable Defender for Storage on storage accounts.

An Azure Policy with a 'DeployIfNotExists' effect is ideal for this scenario. It automatically detects non-compliant resources (storage accounts without Defender for Storage enabled) and deploys the necessary configuration (enabling Defender for Storage) to bring them into compliance, requiring minimal ongoing administrative effort.

Why the other options are wrong

  • A. Manual configuration is not 'least administrative effort' and is prone to human error.
  • C. Microsoft Defender for Cloud automations typically trigger on alerts/recommendations, not proactively enforce configurations on resource creation like Policy.
  • D. An ARM template defines how a resource *should* be deployed, but doesn't automatically remediate existing or non-template-deployed resources.

Azure Policy 'DeployIfNotExists' Effect

An Azure Policy effect that deploys a template when a condition is met (e.g., a resource is missing a required configuration) and the resource does not exist or is not compliant.

  • Used for automatic remediation and configuration enforcement.
  • Requires a deployment template (ARM template) within the policy definition.
  • Ideal for ensuring baseline configurations like diagnostic settings or security features.

Memory trick: Policy's 'DeployIfNotExists' keeps configurations in line.

More Manage security operations questions