Mitigate Threats Using Azure Defender (part 1)

 


To read part 2 please click here


Plan for Cloud Workload Protections Using Azure Defender 

Azure Defender

Azure Defender is known as the Cloud workload protection feature of the Azure Security Center and covers the two broad pillars of cloud security:
  • Cloud Security Posture Management (CSPM)- Security Center is available for free to all the Azure users which includes CSPM features such as secure score, detection of the security misconfigurations in your Azure machines, asset inventory, and more. You can also use these CSPM features to strengthen your hybrid cloud posture and track compliance with the built-in policies.
  • Cloud Workload Protection (CWP)- Security center's integrated Cloud Workload Protection Platform (CWPP), Azure Defender, brings advanced, intelligent protection to your Azure as well as hybrid resources and workloads while also enabling a wide range of extra security features. In addition to the built-in policies, if you enable any Azure Defender plan, you can also add custom policies and initiatives. 

What resource types can Azure Defender secure? 

Azure Defender provides security alerts and advanced threat protection for the virtual machines, SQL databases, containers, web applications, your network, and more.

When you enable Azure Defender from the Pricing and Settings area of the Azure Security Center, the following Defender plans are all enabled simultaneously and provides comprehensive defenses for the compute, data, as well as service layers of your environment:

  • Azure Defender for servers
  • Azure Defender for App Service
  • Azure Defender for Storage 
  • Azure Defender for SQL
  • Azure Defender for Kubernetes
  • Azure Defender for container registries
  • Azure Defender for Key Vault
  • Azure Defender for Resource Manager
  • Azure Defender for DNS

Hybrid Cloud Protection

Besides defending your Azure environment, you can also add Azure Defender capabilities to your hybrid cloud environment:
  • Protect your non-Azure servers
  • Protect your virtual machines in other clouds (such as AWS and GCP) 

You will get the customized threat intelligence and prioritized alerts according to your specific environment so that you can focus on what matters the most.

Azure Defender Security Alerts

Whenever the Azure Defender detects a threat in any area of your environment, it generates a security alert that describes the details of the affected resources, suggested remediation steps, and in some cases, an option to trigger a logic app in response.

If you want to export your alerts to Azure Sentinel, any third-party SIEM, or any other external tool, you can follow the instructions in the Stream alerts to a SIEM, SOAR, or IT Service Management Solution.

Azure Defender Advanced Protection Capabilities

Azure Defender uses an advanced analytics for tailored recommendations related to your resources which includes securing the management ports of your VMs with just-in-time access as well as adaptive application controls to create allow lists for what apps should and shouldn't run on your machines. 

Vulnerability assessment & Management

Azure Defender includes vulnerability scanning for your virtual machines and container registries at no extra cost while allowing you to easily review the findings from these vulnerability scanners and respond to them all within the Security Center which brings it closer to being the single pane of glass for all of your cloud security efforts.  


To read part 2 please click here







Comments

Popular posts from this blog

Query, Visualize, & Monitor Data in Azure Sentinel

Planning for Implementing SAP Solutions on Azure (Part 2 of 5)

Work with String Data Using KQL Statements