
Explore Azure security center to identify vulnerabilities and threat assessment across virtual machines, storage, web apps, and networks, and learn encryption for data at rest and in transit.
Identify assets, assess threats and vulnerabilities, and implement controls with Azure Security Center to safeguard the confidentiality, integrity, and availability of data in the cloud and on premises.
Explore the CIA triangle—confidentiality, integrity, and availability—through data at rest and in transit, encryption with keys, access controls, integrity checks, backups, and disaster recovery.
Protect data encrypted at rest in storage accounts, databases, and virtual disks, and data in transit across networks; rely on security groups and Azure Security Center for scans and remediation.
Gain a unified view of security across your hybrid infrastructure and hybrid workloads, automating resource discovery, policy provisioning, and adaptive threat protections powered by machine learning and threat intelligence.
Discover how azure security center provides unified security management for hybrid and cloud workloads, with centralized policies, continuous assessment, and built-in dashboards prioritizing alerts and remediation suggestions.
Distinguish assets, threats, vulnerabilities, and risks, and learn how vulnerability management reduces risk by explaining how threats exploit weaknesses in your infrastructure.
Configure Azure Security Center with a free trial, install or skip agents, define security policies, and enable data collection with the Microsoft monitoring agent while creating workspace to store logs.
Configure threat detection and data sharing with cloud applications in Azure Security Center, set email alerts, pricing tiers, and customize OS hardening rules with a downloadable JSON baseline for VMs.
Discover how Azure Security Center recommendations improve resource security hygiene and compliance by prioritizing high-impact items like MFA, antivirus, and vulnerability assessments across VMs, storage, and web apps.
Explore Azure's network map and topology to identify exposed resources, like web servers with public IPs, and implement remediation using security groups and a next generation firewall.
Explore Azure security center insights by identifying vulnerabilities in SQL, storage, and identity, enabling auditing, encryption, and MFA to improve secure score and prevent account breaches.
Add non-Azure machines to the workspace by downloading and installing the appropriate agent for servers or Linux machines, using the workspace ID and primary key to connect to the workspace.
Explore log analytics in azure security center by viewing workspaces for non-Azure machines, configuring data sources, and deploying the agent to collect logs from virtual machines.
Install the OMS agent on a non-Azure / AWS server, connect to Log Analytics with the workspace ID and key, and verify event forwarding.
Configure log analytics by selecting data sources such as Windows event logs, application logs, security and system logs, and performance counters, while monitoring machine heartbeat.
Run and refine log analytics queries to collect events from Azure machines and other hosts, visualize results, save favorite queries, export to Power BI, and set alerts for centralized troubleshooting.
Install endpoint protection on virtual machines from Azure Security Center. Choose Microsoft anti-malware or another vendor, configure scanning exclusions, enable realtime protection, and verify installation.
Enable just in time access to lock down inbound management ports, reducing brute-force exposure while providing controlled VM access; monitor ports under standard-tier security center configurations.
Master security solutions by integrating Azure Security Center with third-party monitoring tools, on-premises infrastructure, and Active Directory, enabling centralized event aggregation, log analytics, and alert-driven vulnerability remediation.
Learn to encrypt Azure virtual machine disks with a PowerShell script, store keys in a vault, and authenticate to Azure before running the extension and verifying encryption.
Verify disk encryption on Windows VM by checking BitLocker status and drive locks in Azure console; encryption can take 12–15 minutes and may require switching VMs when binaries conflict.
Enable auditing on your SQL database, configure a separate storage account for audit logs, set a retention policy, and optionally link to Log Analytics or Event Hub.
Enable auditing on SQL Server by configuring auditing, selecting a storage target such as log analytics or event hub, and saving to capture create, read, update, and delete operations.
Explore how Azure Security Center helps you add multiple owners to your subscription and deploy next-generation firewalls. Identify vulnerabilities with Qualys and Nessus to support intrusion detection and prevention systems.
Identify and monitor file and registry changes with file integrity monitoring in Azure Security Center, comparing current and prior scans across Windows and Linux to detect attacks.
Enable file integrity monitoring in Azure Security Center by selecting the workspace with the most virtual machines, and monitor Windows files and registry changes.
Configure file integrity monitoring (FIM) in Azure Security Center by enabling FIM, selecting Windows and Linux files and registry entries to monitor, linking storage accounts, and scheduling content uploads.
Explore Azure Security Center for a holistic view of your infrastructure, with encryption at rest and in transit, layered defenses, auditing, threat detection, and shared responsibility across IaaS, PaaS, SaaS.
In this course, students will get an understanding of various features available in Azure Security Center. There are theory sessions followed by practical ones. There will be live demonstrations as we progress through the class. There are numerous new features that Azure Security has as on today. You will learn various aspects like vulnerability assesment , risks , database Security, Azure storage account security , log analytics , Integration with OMS and log analytics .
You will see more content in near future . This will include Governance, Risk and compliance in the world of Azure Security.
As cloud is a moving target , I am sure there will be new features offered by Microsoft . I will keep this course updated to ensure that you get the latest and greatest stuff in this course at all times.
Happy Learning