
Explore how cloud shared responsibility shifts security tasks to you, and how Azure Security Center provides tools and insights to harden networks and defend cyberspace.
Microsoft renamed security center to Defender for Cloud, with workload protections replacing Azure Defender and environment settings renamed, while all other options stay the same.
Enable Azure Defender to activate Defender plan in Azure Security Center, compare free plan and Defender modes, and enable plan per subscription or resource type with pricing and trial options.
Learn how cloud connectors extend Azure Security Center to VMs in other clouds, enabling multi-cloud security with unified monitoring by connecting enterprise accounts, selecting subscriptions, and providing credentials.
Enable the Defender plan on the Log Analytics workspace to avoid misconfiguration and reduced functionality, ensuring full protection and visibility of all features in Security Center and pricing settings.
Learn to create rules to suppress alerts for a period or permanently, set expiration dates, and simulate dismissal to reduce non-genuine alerts in Defender for Cloud.
Explore how Azure Security Center uses secure score to quantify your security posture across resources and subscriptions. Track progress over time on the overview page to communicate readiness to stakeholders.
Explore how the Azure Security Center groups recommendations into controls, each a logical set of related actions, with MFA themes and secure management ports, and learn how scores are calculated.
Begin with a top-down approach; each control has a maximum score by importance, and points come from fully remediating all items across affected resources, with points divided per resource.
Discover autofix in Azure Security Center (Defender for Cloud) that automatically deploys fixes on affected resources, earns compliance points, and delivers full compliance within 24 hours after deployment.
Calculate the secure score for each subscription using a weighted function based on deployed resources. Track the overall score over time to demonstrate security posture and readiness to stakeholders.
Enforce deny mode in security center policies prevents creation of non-compliant resources, keeping your secure score high while ensuring correct configuration and remediation.
Enable continuous export of the secure score to a Log Analytics workspace to view its changes over time in the prebuilt workbook chart.
Explore how Security Center recommendations enable automated fixes, such as provisioning data collection agents on eligible machines and disabling blob public access across storage accounts, to quickly resolve issues.
Explore how deny and enforce options in Azure Security Center prevent creation of unhealthy resources, ensuring resources added after policy takes effect comply with security settings.
Explore the inventory dashboard in Azure Security Center to view resources and subscriptions with their security state and recommendations, using filters by source types, environment, and vulnerabilities.
Explore how Azure Security Center uses built-in initiatives to validate regulatory compliance against PCI and ISO standards and automatically assign the Microsoft security benchmark to the subscription.
Create exemptions for Azure Security Center controls at security, management group, subscription, and resource levels, with optional expiration and categorization, and observe impact on compliance scores.
Manage compliance policies by adding, disabling, or deleting security standards at the subscription level, create custom initiatives, and track compliance in the regulatory compliance dashboard.
Track compliance over time using the regulatory compliance dashboard and the compliance over time workbook; export data to a log analytics workspace to view streaming updates and snapshots.
Network Map
Show how inventory data is collected at specific frequencies—Windows registry every 15 minutes and files every 30 minutes—plus a per-machine limit of 500 files and daily snapshots.
Track file integrity monitoring changes in Azure Security Center by analyzing registry and file changes, using the log analytics workspace default query to verify configuration changes.
Learn to filter and query Windows service changes in Defender for Cloud to identify who changed a service and when, using change type filters, distinct services, and cake rule queries.
Lecture explains why a Feigenbaum change wasn't detected due to using the report name instead of the actual file name and demonstrates recursion in the directory with 30 minute wait.
Retake demonstrates detecting file content changes using blob links and two snapshots to compare pre and post states in the portal.
Discover how application control in Defender for Cloud reduces workload by building a baseline of running apps and creating allow lists to alert on unauthorized software, using app locker capabilities.
Create custom groups in Defender for Cloud, assign and move VMs between groups, and configure adaptive application control rules, including publisher and hash-based rules with auditing and allow lists.
Welcome to the Azure Security Center (Microsoft Defender for Cloud) Course.
Cloud has made life easier for us, no doubt. With a few clicks, we can provision new VMs and resources. The Security of the provisioned resources in the Cloud remains a shared responsibility.
Your share of responsibility increases as we go from SaaS to PaaS to IaaS.
Why can this be overwhelming?
· The sheer number of workloads itself can be overwhelming.
· Azure has 100+ services and more supporting services under the hood. – A small team may not have the skills to operate all of them.
· Mere inexperience with Cloud operations can be a factor as well.
· The team can be pre-occupied with cloud migration itself with no time to focus on governance
· The self-service model of cloud services and easy exposure of resources to the internet make the task harder.
· The malicious attack campaigns are getting more sophisticated especially with the involvement of state actors.
In face of such challenges, Azure security center is the first and the best line of defense.
Azure Security Center helps you secure your environment by providing you with the tools, information, and insights needed to harden your network and secure services.
In this course, we will explore the many features of Azure Security Center in detail and understand how it can help you in defending your cyberspace.
What will you learn
Learn the main features of Defender for Cloud a.k.a Security Center
Detailed demo of Security Center features
Walkthrough of installing agents
Real-life use cases and guidance