Skip to content

Commit cfd0c54

Browse files
authored
Merge pull request #308372 from asudbring/us503352-dns-threat-how-to
Update DNS security policy how-to for threat intelligence feed.
2 parents dee629f + b63ff73 commit cfd0c54

3 files changed

Lines changed: 15 additions & 1 deletion

File tree

articles/dns/dns-traffic-log-how-to.md

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.author: allensu
1111

1212
# Secure and view DNS traffic
1313

14-
This article shows you how to view and filter DNS traffic at the virtual network with [DNS security policy](dns-security-policy.md).
14+
This article shows you how to view and filter DNS traffic at the virtual network with [DNS security policy](dns-security-policy.md) and secure your DNS traffic with Threat intelligence feed in Azure DNS.
1515

1616
## Prerequisites
1717

@@ -132,6 +132,20 @@ To configure diagnostic settings:
132132

133133
![Screenshot of DNS traffic rules.](./media/dns-traffic-log-how-to/dns-traffic-rules.png)
134134

135+
## Secure DNS traffic with Threat intelligence feed
136+
137+
The threat intelligence feed is a fully managed domain list that’s continuously updated in the background. Within DNS Security Policy, it’s treated just like any other standard domain list — using the same configuration model for priority and for the chosen action (allow, block, or alert).
138+
139+
Select it by adding a new DNS traffic rule and configure it with the action you would like to apply and its respective priority.
140+
141+
Associate threat intelligence feed with a DNS traffic rule by selecting **Azure DNS threat intel**:
142+
143+
:::image type="content" source="./media/dns-traffic-log-how-to/enable-threat-intelligence-feed.png" alt-text="Screenshot of enablement of Threat intelligence feed." lightbox="./media/dns-traffic-log-how-to/enable-threat-intelligence-feed.png":::
144+
145+
Configure the action and priority:
146+
147+
:::image type="content" source="./media/dns-traffic-log-how-to/threat-intelligence-rule.png" alt-text="Screenshot of threat intelligence rule." lightbox="./media/dns-traffic-log-how-to/threat-intelligence-rule.png":::
148+
135149
## View and test DNS logs
136150

137151
1. Navigate to your DNS security policy and then under **Monitoring**, select **Diagnostic settings**.
45.6 KB
Loading
80.5 KB
Loading

0 commit comments

Comments
 (0)