You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Pulumi为Azure存储账户启用Azure Defender?

为Azure存储账户配置Azure Defender(Pulumi实现)

以下是直接可用的Pulumi配置方案,配置完成后即可自动识别存储账户的异常访问、恶意文件上传、敏感数据违规操作等安全威胁。

前置依赖

  • 使用*Azure Native v2.0+*版本的Pulumi provider,经典Azure provider不支持Defender配置接口
  • 操作账号具备Azure Security Admin 或 Owner 权限,包含Microsoft.Security/advancedThreatProtectionSettings/write操作权限

方案1:订阅级全局启用(推荐)

该方案会为订阅内所有现有和后续创建的存储账户自动开启Azure Defender,无需单独配置每个资源,代码示例(TypeScript):

import * as azure_native from "@pulumi/azure-native";

// 替换为你的Azure订阅ID
const subscriptionId = "your-azure-subscription-id";

const defenderForStorage = new azure_native.security.AdvancedThreatProtection("defender-for-storage-global", {
    resourceId: `/subscriptions/${subscriptionId}`,
    isEnabled: true,
    settingName: "current",
    // 可选:开启附加防护能力
    advancedThreatProtectionSettings: {
        // 上传时自动扫描恶意软件
        malwareScanning: {
            enabled: true,
            scanOnUpload: true,
            capGBPerMonth: 100 // 按需设置每月扫描容量上限,避免超额费用
        },
        // 开启敏感数据自动发现
        sensitiveDataDiscovery: {
            enabled: true
        }
    }
});

方案2:为指定存储账户单独启用

如果只需要给部分存储账户开启Defender,可以用单资源配置方式,代码示例(TypeScript):

import * as azure_native from "@pulumi/azure-native";

// 你的现有存储账户创建逻辑(可直接复用已有代码)
const demoStorage = new azure_native.storage.StorageAccount("demo-storage-acc", {
    resourceGroupName: "your-resource-group-name",
    accountName: "demostorageacc202406",
    sku: {
        name: azure_native.storage.SkuName.Standard_LRS
    },
    kind: azure_native.storage.Kind.StorageV2
});

// 为该存储账户单独启用Azure Defender
const storageAccDefender = new azure_native.security.AdvancedThreatProtection("demo-storage-defender", {
    resourceId: demoStorage.id,
    isEnabled: true,
    settingName: "current"
});

配置验证

执行pulumi up完成部署后,可登录Azure Portal进入对应存储账户的「Microsoft Defender for Cloud」页面,确认Defender状态为已启用,即可看到安全告警、扫描日志等输出。

常见部署问题

  • 权限报错:确认操作账号分配了Security Admin角色,不要使用仅具备存储账户编辑权限的账号配置Defender
  • 配置不生效:检查Pulumi依赖中@pulumi/azure-native的版本,低于2.0版本需要先升级provider

内容的提问来源于stack exchange,提问作者Subha_26

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.24 01:24:06