檢視次數:
檢視必要的權限以部署資源,以及連接 Azure 雲端帳戶到 Trend Vision One 時授予的權限。

Azure 所需權限

功能
所需權限
說明
核心功能
  • Microsoft.ContainerService/managedClusters/listClusterUserCredential/action
  • Microsoft.ContainerService/managedClusters/read
  • Microsoft.Resources/subscriptions/resourceGroups/read
  • Microsoft.Authorization/roleAssignments/read
  • Microsoft.Authorization/roleDefinitions/read
  • */read
這些權限是將連接器部署到雲端帳戶所需的。
Server & Workload Protection
訂閱權限:
  • Microsoft.Resources/subscriptions/read
  • Microsoft.Resources/subscriptions/resourceGroups/read
  • Microsoft.Resources/providers/read
  • Microsoft.Resources/resources/read
 
虛擬機器 (VM) 權限:
  • Microsoft.Compute/virtualMachines/read
 
虛擬機器規模設定 (VMSS) 權限:
  • Microsoft.Compute/virtualMachineScaleSets/read
 
經典虛擬機 (VM) 權限:
  • Microsoft.ClassicCompute/virtualMachines/read
  • Microsoft.ClassicCompute/domainNames/read
 
網路權限:
  • Microsoft.Network/networkSecurityGroups/read
  • Microsoft.Network/networkInterfaces/read
  • Microsoft.Network/publicIPAddresses/read
  • Microsoft.Network/virtualNetworks/read
 
Azure 中繼資料 API 權限:
  • Microsoft.Resources/subscriptions/resourceGroups/read
  • Microsoft.Compute/locations/read
 
驗證和 IAM 權限:
  • Microsoft.Resources/deployments/read
  • Microsoft.Authorization/roleAssignments/read
  • Microsoft.Authorization/roleDefinitions/read
 
Cloud Security Posture
requiredResourceAccess:
  • resourceAppName: Microsoft Graph
  • 資源存取:
    • 名稱:User.Read
    • 類型: Delegated
    • 名稱:User.Read.All
    • 類型: Delegated
    • 名稱:Directory.Read.All
    • 類型: Application
    • 名稱:User.Read.All
    • 類型: Application
    • 名稱: Policy.Read.All
    • 類型: Application
 
requiredRoleAccess
  • resourceAppName: Microsoft App Configuration
    角色操作:
    • 名稱:Microsoft.AppConfiguration/configurationStores/ListKeyValue/action
  • resourceAppName: Microsoft Network
    角色操作:
    • 名稱:Microsoft.Network/networkWatchers/queryFlowLogStatus/action
  • resourceAppName: Microsoft Web
    角色操作:
    • 名稱:Microsoft.Web/sites/config/list/Action
  • resourceAppName: Microsoft Key Vault
    資料操作:
    • 名稱:Microsoft.KeyVault/vaults/keys/read
    • 名稱:Microsoft.KeyVault/vaults/secrets/readMetadata/action
requiredTenantScopeRoleAccess
  • resourceAppName: Microsoft Management
    角色操作:
    • 名稱:Microsoft.Management/managementGroups/read
無代理弱點與安全威脅偵測
訂閱權限:
  • Microsoft.ContainerRegistry/registries/generateCredentials/action
  • Microsoft.ContainerRegistry/registries/read
  • Microsoft.ContainerRegistry/registries/pull/read
  • Microsoft.ContainerRegistry/registries/tokens/write
  • Microsoft.ContainerRegistry/registries/tokens/operationStatuses/read
  • Microsoft.ContainerRegistry/registries/scopeMaps/read
  • Microsoft.ContainerRegistry/registries/tokens/read
  • Microsoft.Compute/disks/read
  • Microsoft.Compute/virtualMachines//read
  • Microsoft.HybridCompute/machines//read
  • Microsoft.Authorization/roleAssignments/write
  • Microsoft.Authorization/roleAssignments/delete
  • Microsoft.Authorization/roleAssignments/read
  • Microsoft.Compute/locations/usages/read
  • Microsoft.Quota/quotas/read
 
趨勢科技套件群組權限
Azure 內建角色:貢獻者
  • 操作:
    • Allow Actions:*
  • NotActions:
    • Microsoft.Authorization/*/Delete
    • Microsoft.Authorization/*/Write
    • Microsoft.Authorization/elevateAccess/Action
    • Microsoft.Blueprint/blueprintAssignments/write
    • Microsoft.Blueprint/blueprintAssignments/delete
    • Microsoft.Compute/galleries/share/action
    • Microsoft.Purview/consents/write
    • Microsoft.Purview/consents/delete
    • Microsoft.Resources/deploymentStacks/manageDenySetting/action
    • Microsoft.Subscription/cancel/action
    • Microsoft.Subscription/enable/action
Azure 內建角色:AcrPull
  • Microsoft.ContainerRegistry/registries/pull/read
Azure 內建角色:儲存 Blob 資料防護擁有者
  • Microsoft.Storage/storageAccounts/blobServices/containers/*
  • Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action
  • Microsoft.Storage/storageAccounts/blobServices/containers/blobs/*
趨勢科技儲存 ID 權限
Azure 內建角色:儲存 Blob 資料防護讀取者
  • Microsoft.Storage/storageAccounts/blobServices/containers/read
  • Microsoft.Storage/storageAccounts/blobServices/generateUserDelegationKey/action
  • Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read
Azure 活動記錄的雲端偵測
 
Microsoft Defender 端點日誌收集
  • Microsoft.KeyVault/vaults/secrets/read
  • Microsoft.KeyVault/vaults/secrets/write