Skip to main content
emnode
Learning path

Turn on Azure detection

Turn on Defender plans, diagnostic logging and security alerting.

5 lessons·~69 min total

Lessons in this path

  1. 1
    Compliance AZURE

    Retain Azure audit and activity logs

    One capability across your SQL estate: make sure the audit trail that records who touched a database, and what they did, is kept long enough to investigate an incident and to satisfy an auditor, rather than rolling off after a fortnight.

    14 min
  2. 2
    Compliance AZURE

    Turn on diagnostic logging for Azure resources

    One capability across the estate: make sure every resource that can be attacked is also writing the logs you would need to reconstruct what happened, so an incident leaves a trail instead of a blank.

    14 min
  3. 3
    Compliance AZURE

    Enable Microsoft Defender for Cloud plans

    One capability across Servers, Storage and Azure SQL: make sure the workloads that hold or run your data are actually being watched for threats, rather than left with the free posture tier that only scores configuration and never raises an alert.

    14 min
  4. 4
    Compliance AZURE

    Enable file integrity monitoring

    One capability for your servers: detect, and keep a tamper-evident record of, every change to the operating system files, binaries and registry keys an attacker has to touch to gain persistence, so a quiet change to a critical file stops being invisible.

    14 min
  5. 5
    Compliance AZURE

    Set a security contact and high-severity alerts

    One capability with two halves: make sure Defender for Cloud knows who to email when something goes wrong, and make sure it actually sends an email the moment a high-severity alert fires, so a real breach reaches a human instead of sitting unseen in a console.

    13 min