Turn on Azure detection
Turn on Defender plans, diagnostic logging and security alerting.
Lessons in this path
- 1 Compliance AZURE
Retain Azure audit and activity logs
One capability across your SQL estate: make sure the audit trail that records who touched a database, and what they did, is kept long enough to investigate an incident and to satisfy an auditor, rather than rolling off after a fortnight.
14 min - 2 Compliance AZURE
Turn on diagnostic logging for Azure resources
One capability across the estate: make sure every resource that can be attacked is also writing the logs you would need to reconstruct what happened, so an incident leaves a trail instead of a blank.
14 min - 3 Compliance AZURE
Enable Microsoft Defender for Cloud plans
One capability across Servers, Storage and Azure SQL: make sure the workloads that hold or run your data are actually being watched for threats, rather than left with the free posture tier that only scores configuration and never raises an alert.
14 min - 4 Compliance AZURE
Enable file integrity monitoring
One capability for your servers: detect, and keep a tamper-evident record of, every change to the operating system files, binaries and registry keys an attacker has to touch to gain persistence, so a quiet change to a critical file stops being invisible.
14 min - 5 Compliance AZURE
Set a security contact and high-severity alerts
One capability with two halves: make sure Defender for Cloud knows who to email when something goes wrong, and make sure it actually sends an email the moment a high-severity alert fires, so a real breach reaches a human instead of sitting unseen in a console.
13 min