Manage Azure posture and patching
Patching, vulnerability assessment and endpoint protection across your Azure machines.
Lessons in this path
- 1 Compliance AZURE
Ensure endpoint protection on Azure machines
One capability across every VM and Arc-connected server: make sure each machine has a working antimalware or EDR solution installed, running, and healthy, rather than absent, switched off, or weeks behind on signatures.
14 min - 2 Compliance AZURE
Apply guest configuration baselines
One capability across every Windows and Linux machine in the estate: install the machine configuration agent, assign the Azure compute security baseline, and remediate the operating-system settings that drift from it, so 'the inside of the box is configured securely' is something you can prove rather than hope.
15 min - 3 Compliance AZURE
Keep Azure machines patched
One capability across every VM and Arc-enabled server: make sure each machine is reporting its update state, is actually installing the operating-system patches it is missing, and carries the agent that lets you audit what is running inside it.
14 min - 4 Compliance AZURE
Enable secure boot and attestation
One capability across virtual machines, scale sets and Azure Local: give every machine a cryptographic root of trust so the platform can prove it booted the software you intended, and nothing slipped in beneath the operating system.
14 min - 5 Compliance AZURE
Run vulnerability assessment across Azure
One capability across virtual machines, SQL databases and container images: make sure every resource that can run code is being scanned for known vulnerabilities, and that the findings those scans surface are actually being resolved rather than just collected.
14 min