Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Mastering Azure Security Center
Rating: 3.6 out of 5(59 ratings)
849 students

Mastering Azure Security Center

Learn about the world of security in Azure
Last updated 9/2018
English
English [Auto],

What you'll learn

  • Students will have proficiency in features / Services offered by Microsoft Azure Security Center
  • Undertand the concepts of encryption in Azure.
  • Get a deeper insight of threat intelligence, identifying vulnerabilites , Log analytics etc
  • Monitor non-Azure VM's with Log analytics and integrate with OMS.
  • Install end point protection on VM's from security center
  • Deep dive into Azure security center

Course content

1 section29 lectures1h 57m total length
  • Introduction2:35

    Explore Azure security center to identify vulnerabilities and threat assessment across virtual machines, storage, web apps, and networks, and learn encryption for data at rest and in transit.

  • Overview of Information Security4:55

    Identify assets, assess threats and vulnerabilities, and implement controls with Azure Security Center to safeguard the confidentiality, integrity, and availability of data in the cloud and on premises.

  • Understanding CIA Triad7:29

    Explore the CIA triangle—confidentiality, integrity, and availability—through data at rest and in transit, encryption with keys, access controls, integrity checks, backups, and disaster recovery.

  • General Data Security Principles3:00

    Protect data encrypted at rest in storage accounts, databases, and virtual disks, and data in transit across networks; rely on security groups and Azure Security Center for scans and remediation.

  • Azure Security Center Capabilities2:00

    Gain a unified view of security across your hybrid infrastructure and hybrid workloads, automating resource discovery, policy provisioning, and adaptive threat protections powered by machine learning and threat intelligence.

  • Why Azure Security Center2:28

    Discover how azure security center provides unified security management for hybrid and cloud workloads, with centralized policies, continuous assessment, and built-in dashboards prioritizing alerts and remediation suggestions.

  • Information Security Terminlogies Warm up2:57

    Distinguish assets, threats, vulnerabilities, and risks, and learn how vulnerability management reduces risk by explaining how threats exploit weaknesses in your infrastructure.

  • Configuring Security Center - I5:07

    Configure Azure Security Center with a free trial, install or skip agents, define security policies, and enable data collection with the Microsoft monitoring agent while creating workspace to store logs.

  • Configuring Security Center - II3:34

    Configure threat detection and data sharing with cloud applications in Azure Security Center, set email alerts, pricing tiers, and customize OS hardening rules with a downloadable JSON baseline for VMs.

  • Resource Security Hygine - Recommendation6:39

    Discover how Azure Security Center recommendations improve resource security hygiene and compliance by prioritizing high-impact items like MFA, antivirus, and vulnerability assessments across VMs, storage, and web apps.

  • Resource Security Hygine - Network Map6:27

    Explore Azure's network map and topology to identify exposed resources, like web servers with public IPs, and implement remediation using security groups and a next generation firewall.

  • Resource Security Hygine - SQL, Storage and Identity3:16

    Explore Azure security center insights by identifying vulnerabilities in SQL, storage, and identity, enabling auditing, encryption, and MFA to improve secure score and prevent account breaches.

  • Adding Non-Azure Machines to workspace0:49

    Add non-Azure machines to the workspace by downloading and installing the appropriate agent for servers or Linux machines, using the workspace ID and primary key to connect to the workspace.

  • Log Analytics4:42

    Explore log analytics in azure security center by viewing workspaces for non-Azure machines, configuring data sources, and deploying the agent to collect logs from virtual machines.

  • Installing OMS Agent - NON Azure / AWS Server3:12

    Install the OMS agent on a non-Azure / AWS server, connect to Log Analytics with the workspace ID and key, and verify event forwarding.

  • Configuring Log Analytics5:43

    Configure log analytics by selecting data sources such as Windows event logs, application logs, security and system logs, and performance counters, while monitoring machine heartbeat.

  • Running Sample queries - Log Analytics5:35

    Run and refine log analytics queries to collect events from Azure machines and other hosts, visualize results, save favorite queries, export to Power BI, and set alerts for centralized troubleshooting.

  • Enabling End Point Protection1:39

    Install endpoint protection on virtual machines from Azure Security Center. Choose Microsoft anti-malware or another vendor, configure scanning exclusions, enable realtime protection, and verify installation.

  • Understanding Just In TIme ( JIT )2:13

    Enable just in time access to lock down inbound management ports, reducing brute-force exposure while providing controlled VM access; monitor ports under standard-tier security center configurations.

  • Security Solutions4:28

    Master security solutions by integrating Azure Security Center with third-party monitoring tools, on-premises infrastructure, and Active Directory, enabling centralized event aggregation, log analytics, and alert-driven vulnerability remediation.

  • Enabling Disk Encryption with Powershell10:33

    Learn to encrypt Azure virtual machine disks with a PowerShell script, store keys in a vault, and authenticate to Azure before running the extension and verifying encryption.

  • Verify Disk Encryption3:59

    Verify disk encryption on Windows VM by checking BitLocker status and drive locks in Azure console; encryption can take 12–15 minutes and may require switching VMs when binaries conflict.

  • Enabling Auditing on SQL Database4:40

    Enable auditing on your SQL database, configure a separate storage account for audit logs, set a retention policy, and optionally link to Log Analytics or Event Hub.

  • Enabling Auditing on SQL Server1:37

    Enable auditing on SQL Server by configuring auditing, selecting a storage target such as log analytics or event hub, and saving to capture create, read, update, and delete operations.

  • Inspecting Other Vulnerabilities3:48

    Explore how Azure Security Center helps you add multiple owners to your subscription and deploy next-generation firewalls. Identify vulnerabilities with Qualys and Nessus to support intrusion detection and prevention systems.

  • What is File Intergrity Monitoring ( FIM ) ?4:08

    Identify and monitor file and registry changes with file integrity monitoring in Azure Security Center, comparing current and prior scans across Windows and Linux to detect attacks.

  • Enabling FIM1:31

    Enable file integrity monitoring in Azure Security Center by selecting the workspace with the most virtual machines, and monitor Windows files and registry changes.

  • Configuring FIM3:43

    Configure file integrity monitoring (FIM) in Azure Security Center by enabling FIM, selecting Windows and Linux files and registry entries to monitor, linking storage accounts, and scheduling content uploads.

  • Conclusion4:53

    Explore Azure Security Center for a holistic view of your infrastructure, with encryption at rest and in transit, layered defenses, auditing, threat detection, and shared responsibility across IaaS, PaaS, SaaS.

Requirements

  • Understanding of Azure Services
  • Passionate to learn cutting edge technologies
  • Zest to do the labs and research as we progress through the course.
  • Microsoft Azure account to do the labs
  • Minimal Understanding of Information Security

Description

In this course, students will get an understanding of various features available in Azure Security Center. There are theory sessions followed by practical ones. There will be live demonstrations as we progress through the class. There are numerous new features that Azure Security has as on today. You will learn various aspects like vulnerability assesment , risks , database Security, Azure storage account security , log analytics , Integration with OMS and log analytics .

You will see more content in near future . This will include Governance, Risk and compliance in the world of Azure Security.

As cloud is a moving target , I am sure there will be new features offered by Microsoft . I will keep this course updated to ensure that you get the latest and greatest stuff in this course at all times.

Happy Learning

Who this course is for:

  • Anyone willing to build career in cloud platforms specifically Cloud Security / Azure Security