Centralized policy management with Azure Security Center

Sharing is caring!

&NewLine;<p>Azure Security Center is one of the primary tools in Azure used to detect threats&period; Security Center allows organizations to control and monitor the security of all of their running resources using intelligent threat detection to protect them from cyberattacks&period; As part of that threat detection&comma; Security Center provides recommendations to close potential security holes and ensure compliance with your corporate policy and security guidelines&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Security Center provides an easy-to-read dashboard which shows compliance&comma; security health&comma; and security alerts&period; This is available right off the main Azure portal dashboard&comma; or through the search window&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<div class&equals;"wp-block-image"><figure class&equals;"aligncenter"><img src&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;learn&sol;modules&sol;identify-threats-with-azure-security-center&sol;media&sol;1-security-center&period;png" alt&equals;"Screenshot showing the Azure Security Center view in the Azure portal"&sol;><&sol;figure><&sol;div>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Azure Security Center is fully integrated with Azure Policy&period; <&sol;strong>Security Center can monitor policy compliance across all of your subscriptions using a default set of <em>security policies<&sol;em>&period; A security policy defines the set of controls that are recommended for resources within the specified subscription or resource group&period; These security policies define the <em>desired<&sol;em> configuration of your workloads and help to ensure compliance with company or regulatory security requirements&period; These defaults can be customized and defined to match your specific organizational needs&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Azure management groups<&sol;strong> provide the ability to efficiently manage access&comma; policies&comma; and reporting on groups of subscriptions&comma; as well as effectively manage the entire Azure estate by performing actions on the root management group&period; Each Azure AD tenant is given a single top-level management group called the root management group&period; This root management group is built into the hierarchy to have all management groups and subscriptions fold up to it&period; This group allows global policies and Azure role assignments to be applied at the directory level&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>The root management group is created automatically when you do any of the following actions&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ol class&equals;"wp-block-list"><li>Opt in to use Azure management groups by navigating to&nbsp&semi;<strong>Management Groups<&sol;strong>&nbsp&semi;in the&nbsp&semi;<a href&equals;"https&colon;&sol;&sol;portal&period;azure&period;com&sol;">Azure portal<&sol;a>&period;<&sol;li><li>Create a management group via an API call&period;<&sol;li><li>Create a management group with PowerShell&period;<&sol;li><&sol;ol>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>You can use Azure Policy to enable Azure Security Center on all the Azure subscriptions within the same management group &lpar;MG&rpar;&period; This is more convenient than accessing them individually from the portal and works even if the subscriptions belong to different owners&period;<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Here are a few of the built-in security policies that Security Center monitors&colon;<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Secure transfer to storage accounts should be enabled<&sol;li><li>Azure AD administrator for SQL server should be provisioned<&sol;li><li>Client authentication should use Azure Active Directory<&sol;li><li>Diagnostics logs in Key Vault should be enabled<&sol;li><li>System updates should be installed on your machines<&sol;li><li>Audit missing blob encryption for storage accounts<&sol;li><li>Just-In-Time network access control should be applied on virtual machines<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>It&&num;8217&semi;s recommended to leave all the security policies enabled&comma; however&comma; sometimes a recommendation will be generated that isn&&num;8217&semi;t relevant to your environment&period; You can turn it off by <strong>disabling the security policy<&sol;strong> that is sending the recommendation&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>In the <strong>Policy &amp&semi; Compliance<&sol;strong> section&comma; select <strong>Security policy<&sol;strong>&period;<&sol;li><li>Select the subscription or management group that shouldn&&num;8217&semi;t show the recommendation&period;<&sol;li><li>Select the assigned policy&colon;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image"><img src&equals;"https&colon;&sol;&sol;docs&period;microsoft&period;com&sol;en-us&sol;learn&sol;modules&sol;identify-threats-with-azure-security-center&sol;media&sol;3-disable-policy&period;png" alt&equals;"Screenshot of the screen to disable the recommendation"&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list" id&equals;"block-cb525e28-600a-49bd-809f-5bc7cc4b5af1"><li>In the <strong>PARAMETERS<&sol;strong> section&comma; locate the policy that sends the recommendation you want to disable&comma; and from the dropdown list&comma; select <strong>Disabled<&sol;strong>&period;<&sol;li><li>Select <strong>Save<&sol;strong> to persist your changes&period; The change can take up to 12 hours to replicate through the Azure infrastructure&period;<&sol;li><&sol;ul>&NewLine;