How to add defender malware scanner for azure storage account

Dileepa Mabulage 5 Reputation points
2023-11-06T09:43:30.9433333+00:00

User's image

Im trying to enable malware scanner for my azure storage account but its throwing me this error.

Plan enablement partially succeeded. Could not enable on-upload malware scanning: Exception of type 'Microsoft.Rest.Azure.CloudException' was thrown.. Could not enable sensitive data discovery: Exception of type 'Microsoft.Rest.Azure.CloudException' was thrown.

I encountered this error enabling the defernder via atorage account

storage_account => Microsoft Defender for Cloud

User's image

for this configuration It wont work
User's image

Azure Storage Accounts
Azure Storage Accounts
Globally unique resources that provide access to data management services and serve as the parent namespace for the services.
3,384 questions
Azure Blob Storage
Azure Blob Storage
An Azure service that stores unstructured data in the cloud as blobs.
3,094 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,499 questions
{count} vote

1 answer

Sort by: Most helpful
  1. Anand Prakash Yadav 7,830 Reputation points Microsoft Vendor
    2023-11-09T08:46:12.9533333+00:00

    Hi Dileepa Mabulage,

    Thank you for posting your query here!

    As the on-upload malware scanning and sensitive data discovery features could not be enabled for your Azure storage account, please note that for Malware Scanning and sensitive data threat detection at subscription and storage account levels, you need Owner roles (subscription owner/storage account owner) or specific roles with corresponding data actions.

    The following table summarizes the permissions you need for each scenario. The permissions are either built-in Azure roles or action sets that you can assign to custom roles.

    User's image

    User's image

    Details on unsupported features and services in Malware Scanning: https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-malware-scan#limitations

    Please let us know if you have any further queries. I’m happy to assist you further.


    Please do not forget to "Accept the answer” and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.