Mitigate Threats Using Azure Defender (part 1)
To read part 2 please click here
Plan for Cloud Workload Protections Using Azure Defender
Azure Defender
- Cloud Security Posture Management (CSPM)- Security Center is available for free to all the Azure users which includes CSPM features such as secure score, detection of the security misconfigurations in your Azure machines, asset inventory, and more. You can also use these CSPM features to strengthen your hybrid cloud posture and track compliance with the built-in policies.
- Cloud Workload Protection (CWP)- Security center's integrated Cloud Workload Protection Platform (CWPP), Azure Defender, brings advanced, intelligent protection to your Azure as well as hybrid resources and workloads while also enabling a wide range of extra security features. In addition to the built-in policies, if you enable any Azure Defender plan, you can also add custom policies and initiatives.
What resource types can Azure Defender secure?
When you enable Azure Defender from the Pricing and Settings area of the Azure Security Center, the following Defender plans are all enabled simultaneously and provides comprehensive defenses for the compute, data, as well as service layers of your environment:
- Azure Defender for servers
- Azure Defender for App Service
- Azure Defender for Storage
- Azure Defender for SQL
- Azure Defender for Kubernetes
- Azure Defender for container registries
- Azure Defender for Key Vault
- Azure Defender for Resource Manager
- Azure Defender for DNS
Hybrid Cloud Protection
- Protect your non-Azure servers
- Protect your virtual machines in other clouds (such as AWS and GCP)
You will get the customized threat intelligence and prioritized alerts according to your specific environment so that you can focus on what matters the most.
Azure Defender Security Alerts
Whenever the Azure Defender detects a threat in any area of your environment, it generates a security alert that describes the details of the affected resources, suggested remediation steps, and in some cases, an option to trigger a logic app in response.
If you want to export your alerts to Azure Sentinel, any third-party SIEM, or any other external tool, you can follow the instructions in the Stream alerts to a SIEM, SOAR, or IT Service Management Solution.
Azure Defender Advanced Protection Capabilities
Vulnerability assessment & Management
To read part 2 please click here
Comments
Post a Comment