Giter VIP home page Giter VIP logo

mcw-security-baseline-on-azure's Introduction

Let us know how we’re doing!

Please take a moment to fill out the Microsoft Cloud Workshop Survey and help us improve our offerings.

Security baseline on Azure

Contoso Ltd is a multinational corporation, headquartered in the United States that provides insurance solutions worldwide. Its products include accident and health insurance, life insurance, travel, home, and auto coverage. Contoso manages data collection services by sending mobile agents directly to the insured to gather information as part of the data collection process for claims from an insured individual. These mobile agents are based all over the world and are residents of the region in which they work. Mobile agents are managed remotely through regional corporate offices.

They are exploring a lift and shift strategy to Azure, but have a large focus on Azure Security and Privacy features.

July 2020

Target audience

  • Cloud Administrators
  • Cloud Architects
  • Security Analysts
  • Security Architects

Abstracts

Workshop

In this workshop, you will learn how to design an implementation of Azure Security Center and Microsoft Compliance Manager tools to ensure a secure and privacy-focused Azure cloud-based architecture.

At the end of this workshop, you will be better able to secure your cloud-based applications and services, while ensuring privacy standards are followed and your architecture is compliant.

Whiteboard design session

In this whiteboard design session, you will work with a group to design an end-to-end solution that leverages many of Microsoft Azure’s security features.

At the end of this session, you will be better able to design and recommend solutions that help organizations properly secure their cloud-based applications while protecting their sensitive data.

Hands-on lab

In this hands-on lab, you will implement many of the Azure Security Center features to secure their cloud-based Azure infrastructure (IaaS) and applications (PaaS). Specifically, you will ensure that any internet exposed resources have been properly secured and any non-required internet access disabled. Additionally, you will implement a “jump machine” for admins with Application Security enabled to prevent admins from installing non-approved software and potentially exposing cloud resources. You will then utilize custom alerts to monitor for TCP/IP Port Scans and then fire alerts and run books based on those attacks.

At the end of this hands-on lab, you will be better able to design and build secure cloud-based architectures, and to improve the security of existing applications hosted within Azure.

Azure services and related products

  • Azure Virtual Machines and Networks with Network Security Groups
  • Virtual Private Networks (Point to Point, Site to Site)
  • Azure Web Apps
  • Azure SQL DB and corresponding security features (Threat Detection, TDE, Column Level Encryption, etc.)
  • Azure Storage Encryption
  • SQL Server Virtual Machines
  • Azure IAM
  • Azure Monitor and Log Analytics
  • Azure Sentinel
  • Azure Policy
  • Power BI
  • Azure Security Center
  • Secure Score
  • Azure Key Vault Integrations
  • Microsoft Azure Active Directory
  • Microsoft Intune
  • Conditional Access controls

Azure solutions

Security and Management

Related References

Help & Support

We welcome feedback and comments from Microsoft SMEs & learning partners who deliver MCWs.

Having trouble?

  • First, verify you have followed all written lab instructions (including the Before the Hands-on lab document).
  • Next, submit an issue with a detailed description of the problem.
  • Do not submit pull requests. Our content authors will make all changes and submit pull requests for approval.

If you are planning to present a workshop, review and test the materials early! We recommend at least two weeks prior.

Please allow 5 - 10 business days for review and resolution of issues.

mcw-security-baseline-on-azure's People

Contributors

dawnmariedesjardins avatar givenscj avatar timahenning avatar microsoftopensource avatar waltermyersiii avatar codingbandit avatar hopero929 avatar cassiejones444 avatar manuinnz avatar joelhulen avatar ldaneliukas avatar mwasham avatar msftgits avatar

Watchers

James Cloos avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.