Enumerating storage accounts to calculate Azure Security Center ATP for Storage Cost

This post has been republished via RSS; it originally appeared at: New blog articles in Microsoft Tech Community.

Advanced threat protection for Azure Storage provides an additional layer of security intelligence that detects unusual and potentially harmful attempts to access or exploit storage accounts. Advanced threat protection for Azure Storage ingests diagnostic logs of read, write, and delete requests to Blob storage for threat detection. You can turn on this capability in Azure Security Center for the entire subscription, which will basically enable the ATP for Azure Storage in all storage accounts that are part of the subscription.

 

One way to verify the amount of transactions/day that were analyzed, is by using the Storage account blade, under Advanced Security, as shown below:

 

SSFig2.JPG

 

While this information can help you to estimate the overall cost of this solution per storage account, for large deployments where you have multiple storage accounts, this could be hard to consolidate.

 

With the intent to facilitate this calculation, you can leverage this script (from our GitHub community / written by Microsoft) to enumerate all storage accounts and get the metrics for the last week (aggregated by day) so that you can calculate ASC Storage ATP costs. Feel free to download, and modify the script according to your needs. 

 

Leave a Reply

Your email address will not be published. Required fields are marked *

*

This site uses Akismet to reduce spam. Learn how your comment data is processed.