Azure Security Center
Do you have an idea or suggestion based on your experience with Azure Security Center? We would love to hear it! Please take a few minutes to submit your ideas or vote up an idea submitted by another customer. All of the feedback you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Security Center. Remember that this site is only for feature suggestions and ideas!
For further reading on Azure Security Center, see our documentation. For general discussion, use our discussion forum. For technical support, take advantage of these support options.
-
Support for letting apps send custom alerts to Security Center
For example, a security issue that an application looks for and detects. Allowing the application to send a message to security center, instead of some other log/location that might get overlooked.
11 votesGreat idea. We plan to extend the integration model we have with 3rd party security solutions to any app. No ETA yet.
Daniel Alon, Group Program Manager
Azure Security Center -
Support for ATA
It would be valuable to get support for ATA for Azure Active Directory in ASC. We like the visual workflow and investigations. https://www.microsoft.com/en-us/server-cloud/products/advanced-threat-analytics/
11 votesThanks for the idea. This is something we are considering for future versions of ASC.
-
Support for all PaaS offerings
App Services, API Management, Data Lake, HDInsight, Storage Accounts, Azure Redis, Load Balancer, AAD, etc... Aggregate all logs. Make them available to 3rd party SIEM options too.
11 votesGreat idea. We have plans to implement this, but we there’s no ETA at this point.
Gilad Elyashar,
Product Manager -
Add support for Virtual Machine Scale Sets
We use VM scale sets when provisioning our environment in Azure. These scale set VMs are not supported by Azure Security Center. Please consider adding support for VM scale sets.
7 votesThanks for your feedback. We are indeed considering this for ASC. no ETA at this moment.
thanks,
Gilad Elyashar
Product Manager, Azure Security Center -
Support for Cloud Services
Today, Azure Security Center provides monitoring for Virtual Machines (including VMs that are part of Service Fabric Clusters), Virtual Networks, and Azure SQL Database. What about Cloud Services (Web and Worker roles)? Do you want to be able to manage security for Cloud Services in Security Center as well? If so, vote for this idea and share any specific requirements in the comments.
6 votesWe’ve started work on enabling security monitoring for Cloud Services. Stay tuned.
Sarah Fender, Program Manager
Azure Security Center -
Adjust baseline requirements to support IIS servers or custom environment changes.
The baseline scans are failing on IIS servers, so maybe a more generic way to adjust the baseline rules on virtual machines would be helpful.
An example of the the scenario is described here.
6 votesGreat idea. We have plans to enable more granular control on the baseline rules to support cases like this one, but we there’s no ETA at this point.
Gilad Elyashar
Product Manager -
Integration with Azure OMS
Now we have at least 2 different azure features that covering Security topic.
Security Center and Azure Operation Management Suite.Both looks not bad, but paying twice - it's not the best business approach. Also it's looks like duplication(I know the difference, but it's still very close to each other).
I think we(Microsoft) can create Solution in OMS that will consume security info from Security Center. Or Security Center could consume OMS logs.. Anyway- 2 entities, 2 times paying- it's not the best business approach.
5 votesThanks for your feedback. We are indeed planning some improvements to resolve that. No ETA that we can share at this moment.
thanks,
Gilad Elyashar
Product Manager, Azure Security Center -
ASC broken Fix please: Users who are Owner of VMs should see VMs in ASC
Azure Security Center is broken, Fix please: Users who are Owner of VMs should see VMs in Azure Security Center
Although documented here https://azure.microsoft.com/nl-nl/documentation/articles/security-center-faq/
"... this means that users will only see items related to resources where the user is assigned the role of Owner, Contributor, or Reader to the subscription or resource group that a resource belongs to."
This does not work in a full ARM RBAC Model setup.Users who are Owner of VMs, don't see VMs in Azure Security Center.
4 votesThanks.
Indeed today Azure Security Center has experiences that can’t live in a single resource hierarchy and so not applicable for users with access to a single resource (i.e. and not the the containing subscription/resource group). We will look into adding a scoped down resource level experience for such users. No ETA to provide at this point.
Thanks,
Gilad Elyashar
Product Manager -
4 votes
-
Additional Linux information on VM Security Details blade
1- Can the Linux release and Kernel version be displayed in the VM Security Details blade (or elsewhere in Security Center)?
2- Can the update count be displayed in that blade? Similar to the "x packages can be updated, y updates are security updates" message from the MOTD when logging in to Ubuntu over SSH.
4 votesThanks for the suggestion. We have plans to add this, but we there’s no ETA at this point.
Gilad Elyashar, Program Manager,
Azure Security Center team. -
Security Center
Add "Apply" option for all Security Center recommendation. Next step will be "Roll Back" option for implemented improvements.
3 votesThanks for the idea. This is something we are considering for future versions of ASC.
-
GatewaySubnet NSG recommendation
It is not allowed to attach a NSG to the GatewaySubnet in a virtual network. So it would be good if the recommendation in the Security Center of the GatewaySubnet would be not to attach a NSG.
Just mark it as green, because we cannot attach a NSG to the GatewaySubnet.
3 votesThanks for the suggestion. We do plan to to add this type of dsitinction. No ETA yet.
Gilad Elyashar, Program Manager,
Azure Security Center team. -
Export to CSV
Interested in generating reports on recommendations or security alerts in Security Center? If you could export this data to a CSV, you could create your own reports in Excel or PowerBI to share with others within in organization. Vote for this idea if you would export Security Center data to a CSV.
3 votesWe’ll watch interest. Let us know what tools you prefer to use for reporting – Excel, PowerBI, other? What reports would you be most interested in?
Sarah Fender, Program Manager
Azure Security Center -
SQL Azure Firewall Rules recommendations to report very large IP ranges
What currently is not reported is a very large range of IP addresses enabling access to SQL Azure. A rule 0.0.0.0- 255.255.255.255 will not be reported at all by Security Centre, but does pose a risk to the Database if the password and account is not strong and complex enough.
3 votesGreat idea. We have plans to implement a recommendation on that area, but we there’s no ETA at this point
-
Generate security audits fails
Azure complains about "Generate security audits":
EXPECTED VALUELocal Service, Network Service, IIS APPPOOL\DefaultAppPool
Which actually are there.. even that Azure says:
ACTUAL VALUE*S-1-5-19,*S-1-5-20,*S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415
3 votes -
Guardicore
Have you considered having Gaurdicore as a partner solution in the marketplace? I sawe their technology at Blackhat and this seems to be a gap in Azure Security Center.
2 votesYes, this is something we are considering for the future.
-
SOC
The ability create a virtual SOC, automatically selecting all appropriate apps, services. I can go in to more detail, and design ideas if anyone wants.
2 votesAzure Security Center already has some basic SOC features around monitoring and we’re certainly planing to extend those in the future. However, since SOC is a broad term it would help if you would be more specific about what exactly you had in mind and and what virtual SOC scenario you would find the most useful in Azure Security Center.
Gilad Elyashar,
Product Manager -
Create a community open source repository
It would be great to get the security community engage with Azure Security Center and allow for community contributions. I imagine that it could be something like the Azure Automation Runbook community repository, but this would be focused on integration with Azure Security Center. Azure Security Center needs to create open API for custom community developed solution like mentioned in this feedback: https://feedback.azure.com/forums/347535-azure-security-center/suggestions/12366438-support-for-letting-apps-send-custom-alerts-to-sec
1 vote -
Editing security policy, duplicate named blades
When you click on Policy within the Prevention section of ASC, a blade opens called Security policy. When you click on a subscription or Resource group to edit policy, a new blade opens also called Security policy. This creates a bit of confusion when documenting Security Center features. Perhaps the blade where you edit policy should be called, "Edit security policy"?
1 voteGreat idea. We will look into making it more understandable moving forward.
Gilad Elyashar, Program Manager,
Azure Security Center team. -
Missing Scan Data : better categorisation when VM Shutdown and Force data refresh
Within Azure Security Center / Virtual Machine Stream, we have a "Missing scan data" substream.
"Missing scan data" containing a list of VM on which :
* The VM is turn-off
* The VM is turn-on (some change was done on VM, ie. Antimalware install or not done, a Linux VM was installed, the Azure Agent is installed, but no scan happen (yet) on VM (but VM is running for 4/5 days).We believe the management could be improved :
* Some data are missing (because VM is shutdown)
* Some data could be collected, but Azure Security Center not…1 vote
- Don't see your idea?
