如何使用Pulumi为Azure存储账户启用Azure Defender?
为Azure存储账户配置Azure Defender(Pulumi实现)
以下是直接可用的Pulumi配置方案,配置完成后即可自动识别存储账户的异常访问、恶意文件上传、敏感数据违规操作等安全威胁。
前置依赖
- 使用*Azure Native v2.0+*版本的Pulumi provider,经典Azure provider不支持Defender配置接口
- 操作账号具备Azure
Security Admin或Owner权限,包含Microsoft.Security/advancedThreatProtectionSettings/write操作权限
方案1:订阅级全局启用(推荐)
该方案会为订阅内所有现有和后续创建的存储账户自动开启Azure Defender,无需单独配置每个资源,代码示例(TypeScript):
import * as azure_native from "@pulumi/azure-native"; // 替换为你的Azure订阅ID const subscriptionId = "your-azure-subscription-id"; const defenderForStorage = new azure_native.security.AdvancedThreatProtection("defender-for-storage-global", { resourceId: `/subscriptions/${subscriptionId}`, isEnabled: true, settingName: "current", // 可选:开启附加防护能力 advancedThreatProtectionSettings: { // 上传时自动扫描恶意软件 malwareScanning: { enabled: true, scanOnUpload: true, capGBPerMonth: 100 // 按需设置每月扫描容量上限,避免超额费用 }, // 开启敏感数据自动发现 sensitiveDataDiscovery: { enabled: true } } });
方案2:为指定存储账户单独启用
如果只需要给部分存储账户开启Defender,可以用单资源配置方式,代码示例(TypeScript):
import * as azure_native from "@pulumi/azure-native"; // 你的现有存储账户创建逻辑(可直接复用已有代码) const demoStorage = new azure_native.storage.StorageAccount("demo-storage-acc", { resourceGroupName: "your-resource-group-name", accountName: "demostorageacc202406", sku: { name: azure_native.storage.SkuName.Standard_LRS }, kind: azure_native.storage.Kind.StorageV2 }); // 为该存储账户单独启用Azure Defender const storageAccDefender = new azure_native.security.AdvancedThreatProtection("demo-storage-defender", { resourceId: demoStorage.id, isEnabled: true, settingName: "current" });
配置验证
执行pulumi up完成部署后,可登录Azure Portal进入对应存储账户的「Microsoft Defender for Cloud」页面,确认Defender状态为已启用,即可看到安全告警、扫描日志等输出。
常见部署问题
- 权限报错:确认操作账号分配了
Security Admin角色,不要使用仅具备存储账户编辑权限的账号配置Defender - 配置不生效:检查Pulumi依赖中
@pulumi/azure-native的版本,低于2.0版本需要先升级provider
内容的提问来源于stack exchange,提问作者Subha_26
相关产品推荐
相关产品推荐

