Skip to main content
emnode
Learning path

Manage Azure posture and patching

Patching, vulnerability assessment and endpoint protection across your Azure machines.

5 lessons·~71 min total

Lessons in this path

  1. 1
    Compliance AZURE

    Ensure endpoint protection on Azure machines

    One capability across every VM and Arc-connected server: make sure each machine has a working antimalware or EDR solution installed, running, and healthy, rather than absent, switched off, or weeks behind on signatures.

    14 min
  2. 2
    Compliance AZURE

    Apply guest configuration baselines

    One capability across every Windows and Linux machine in the estate: install the machine configuration agent, assign the Azure compute security baseline, and remediate the operating-system settings that drift from it, so 'the inside of the box is configured securely' is something you can prove rather than hope.

    15 min
  3. 3
    Compliance AZURE

    Keep Azure machines patched

    One capability across every VM and Arc-enabled server: make sure each machine is reporting its update state, is actually installing the operating-system patches it is missing, and carries the agent that lets you audit what is running inside it.

    14 min
  4. 4
    Compliance AZURE

    Enable secure boot and attestation

    One capability across virtual machines, scale sets and Azure Local: give every machine a cryptographic root of trust so the platform can prove it booted the software you intended, and nothing slipped in beneath the operating system.

    14 min
  5. 5
    Compliance AZURE

    Run vulnerability assessment across Azure

    One capability across virtual machines, SQL databases and container images: make sure every resource that can run code is being scanned for known vulnerabilities, and that the findings those scans surface are actually being resolved rather than just collected.

    14 min