Azure Cosmos DB

Advanced Threat Protection Disabled

Risk Level: Low

Description  

This plugin ensures that the Advanced Threat Protection feature is enabled for Microsoft Azure CosmosDB accounts. Advanced Threat Protection for Azure CosmosDB provides an additional layer of security intelligence that detects unusual and potentially harmful attempts to access or exploit Azure CosmosDB accounts.

About the Service

Azure Cosmos DB: Azure Cosmos DB is a fully managed NoSQL database service for application developments. It provides a single-digit millisecond response time and ensures the full-time availability of the database.

Impact

Advanced threat protection uses threat intelligence and AI to detect suspicious activities within or outside the organisation. Disabling the option will lead to missing out on alerts regarding the activities which might have suspicious intentions.

Steps to Reproduce

  1. Login to azure portal.
  2. Click on Azure Cosmos DB under Azure services.
  3. Select an account for which error has to be detected.
  4. Click on Advanced security under the Settings section.
  5. If the Advanced Threat Protection option is set to ‘off’, go to the Steps to remediation section to remediate the problem.
  6. Repeat the process for other accounts as well.

Steps for Remediation

  1. Login to azure portal.
  2. Click on Azure Cosmos DB under Azure services.
  3. Select an account for which error has to be detected.
  4. Click on Advanced security under the Settings section.
  5. Click on the ‘On’ button at Status to set 
  6. Repeat the process for other accounts as well.

Please feel free to reach out to support@pingsafe.ai with any questions that you may have.

Thanks

PingSafe Support