For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-lqv.md. A documentation index is available at /llms.txt.

Microsoft Defender for Resource Manager should be enabled

Description

Microsoft Defender for Resource Manager monitors control-plane operations performed through Azure Resource Manager and detects suspicious activity such as the use of risky toolkits, abuse of service principals, and lateral movement attempts. Enabling this plan at the Standard tier covers every subscription that issues ARM operations.

Remediation

See Protect your resources with the Resource Manager plan for step-by-step instructions on enabling the plan.