Reader small image

You're reading from  Azure Security Cookbook

Product typeBook
Published inMar 2023
Reading LevelBeginner
PublisherPackt
ISBN-139781804617960
Edition1st Edition
Languages
Tools
Right arrow
Author (1)
Steve Miles
Steve Miles
author image
Steve Miles

Steve Miles is a Microsoft security and Azure/hybrid MVP and MCT with over 20 years of experience in security, networking, storage, end user computing, and cloud solutions. His current focus is on securing, protecting, and managing identities, Windows clients, and Windows server workloads in hybrid and multi-cloud platform environments. His first Microsoft certification was on Windows NT and he is an MCP, MCITP, MCSA, and MCSE for Windows and many other Microsoft products. He also holds multiple Microsoft Fundamentals, Associate, Expert, and Specialty certifications in Azure security, identity, network, M365, and D365. He also holds multiple security, networking vendor, and other public cloud provider certifications.
Read more about Steve Miles

Right arrow

Using Microsoft Defender for Cloud

In the previous chapter, we covered recipes for using Azure Advisor to review security recommendations for your environments and provide alerts and remediation.

This chapter will teach you how to implement security posture management and workload protection using Microsoft Defender for Cloud.

By the end of this chapter, you will have gone through the following recipes to make the most effective use of Microsoft Defender for Cloud:

  • Reviewing the components and capabilities of Defender for Cloud
  • Enabling enhanced security features of Defender for Cloud
  • Adding a Regulatory Standard to the Regulatory compliance dashboard
  • Assessing your regulatory compliance

Technical requirements

This chapter assumes that you have an Azure AD tenancy and an Azure subscription from completing the recipes in previous chapters of this cookbook. If you skipped straight to this section, the information needed to create a new Azure AD tenancy and an Azure subscription for these recipes is included in the following list of requirements.

For this chapter, the following is required:

Review Defender for Cloud components

This recipe will provide you with a high-level overview of the capabilities of Microsoft Defender for Cloud.

Getting ready

This recipe requires the following:

  • A device with a browser, such as Edge or Chrome, to access the Azure portal: https://portal.azure.com
  • Access to an Azure subscription, where you have access to the Owner role for the Azure subscription

How to do it…

This task consists of only one step - reviewing the components of Defender for Cloud.Task – review the components of Defender for Cloud

Perform the following steps:

  1. Sign in to the Azure portal: https://portal.azure.com.
  2. In the search bar, type defender for cloud; click Microsoft Defender for Cloud from the list of services shown.
Figure 8.1 – Search for the Defender for Cloud resource

Figure 8.1 – Search for the Defender for Cloud resource

  1. When Microsoft Defender for Cloud opens, it will load the Overview page.
  2. From the top of...

Enable enhanced security features of Defender for Cloud

This recipe will teach you how to take full advantage of the CWP capabilities provided by enabling the enhanced features of Microsoft Defender for Cloud.

The extended Security Posture and Detection and Response features are available to improve your security posture and workload protection. They can be enabled for subscriptions via the paid-for Defender plans.

Getting ready

This recipe requires the following to be in place:

  • A device with a browser, such as Edge or Chrome, to access the Azure portal: https://portal.azure.com.
  • Access to an Azure subscription, where you have access to the Owner role for the Azure subscription.
  • In addition, you should have the Security Administrator role assigned.
  • The subscription should not have the enhanced security features of Microsoft Defender for Cloud already enabled. More info can be found at the following URL: https://learn.microsoft.com/en-us/azure/defender-for...

Add a standard to the Regulatory compliance dashboard

This recipe will teach you how to enable enhanced features of Microsoft Defender for Cloud to improve your security posture and workload protection.

Getting ready

This recipe requires the following to be in place:

  • A device with a browser, such as Edge or Chrome, to access the Azure portal: https://portal.azure.com.
  • Access to an Azure subscription, where you have access to the Owner role for the Azure subscription.
  • To access the compliance dashboard and managing standards, you must have Resource Policy Contributor and Security Admin as minimum roles.
  • You must have at least Reader (or Global Reader) access to view the compliance data; Security Reader access will not suffice.
  • The subscription should have the enhanced security features of Microsoft Defender for Cloud already enabled.

How to do it…

This task consists of the following step:

  • Adding a regulatory compliance standard
  • ...

Assess your regulatory compliance

This recipe will teach you how to assess your regulatory compliance against a standard we added to the previous recipe. Regulatory compliance standards are an enhanced feature of Microsoft Defender for Cloud to improve your security posture and workload protection.

Getting ready

This recipe requires the following to be in place:

  • A device with a browser, such as Edge or Chrome, to access the Azure portal: https://portal.azure.com
  • Access to an Azure subscription, where you have access to the Owner role
  • In addition, you should have the Security Administrator role assigned
  • The subscription should have the enhanced security features of Microsoft Defender for Cloud already enabled. More info can be found at the following URL: https://learn.microsoft.com/en-us/azure/defender-for-cloud/enhanced-security-features-overview
  • The preceding recipe should have been completed, to add a regulatory compliance standard, so your environment...
lock icon
The rest of the chapter is locked
You have been reading a chapter from
Azure Security Cookbook
Published in: Mar 2023Publisher: PacktISBN-13: 9781804617960
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime

Author (1)

author image
Steve Miles

Steve Miles is a Microsoft security and Azure/hybrid MVP and MCT with over 20 years of experience in security, networking, storage, end user computing, and cloud solutions. His current focus is on securing, protecting, and managing identities, Windows clients, and Windows server workloads in hybrid and multi-cloud platform environments. His first Microsoft certification was on Windows NT and he is an MCP, MCITP, MCSA, and MCSE for Windows and many other Microsoft products. He also holds multiple Microsoft Fundamentals, Associate, Expert, and Specialty certifications in Azure security, identity, network, M365, and D365. He also holds multiple security, networking vendor, and other public cloud provider certifications.
Read more about Steve Miles