|
1 |
| -Azure Arc also simplifies the process of centralizing and standardizing enterprise-wide management, monitoring, and protection of technology assets regardless of their location. In this unit, you'll learn how this principle applies to on-premises servers, including Azure Arc-enabled servers. |
| 1 | +Azure Arc helps simplify and standardize enterprise-wide management, monitoring, and protection of technology assets, regardless of their location. In this unit, you'll learn how these benefits apply to Azure Arc-enabled servers through Microsoft Defender for Cloud, Microsoft Sentinel, and Azure Monitor. |
2 | 2 |
|
3 | 3 | ## What are the security benefits of Microsoft Defender for Cloud in hybrid scenarios?
|
4 | 4 |
|
5 | 5 | To address the security challenges inherent to hybrid environments—such as high volatility and dependencies on external services—you need sophisticated tools that help assess your security posture and identify and remediate risks. Ideally, you want to deploy those tools with minimal effort. Microsoft Defender for Cloud can help you address these requirements.
|
6 | 6 |
|
7 |
| -Defender for Cloud is a cloud-based service for managing the security of your cloud and on-premises infrastructure and workloads. With Defender for Cloud capabilities, you can: |
| 7 | +Defender for Cloud helps manage the security of your cloud and on-premises infrastructure and workloads. With Defender for Cloud capabilities, you can: |
8 | 8 |
|
9 |
| -- **Improve your security stance**: Use Defender for Cloud to implement security best practices across your cloud services and on-premises servers. In addition to security best practices, you can also track compliance against regulatory standards. |
10 |
| -- **Protect your environment**: Monitor for security threats to your cloud and on-premises servers with Defender for Cloud. |
11 |
| -- **Protect your data**: Identify suspicious activity against your servers, files, and databases including potential data breaches. |
| 9 | +- **Improve your security stance**: Implement security best practices across your cloud services and on-premises servers, and track compliance against regulatory standards. |
| 10 | +- **Protect your environment**: Monitor for security threats to your servers. |
| 11 | +- **Protect your data**: Identify suspicious activity against your servers, files, and databases, including potential data breaches. |
12 | 12 |
|
13 | 13 | Defender for Cloud continuously analyzes collected data, provides you with remediation recommendations, and generates security alerts in response to attempted and actual security breaches and exploits.
|
14 | 14 |
|
15 |
| -> [!NOTE] |
16 |
| -> Azure Arc-enabled servers require Microsoft Defender for Cloud. |
17 |
| -
|
18 | 15 | ## What are the security benefits of Microsoft Sentinel in hybrid scenarios?
|
19 | 16 |
|
20 |
| -Microsoft Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution. Microsoft Sentinel delivers intelligent security analytics and threat intelligence, providing a single solution for alert detection, threat visibility, proactive hunting, and threat response. |
| 17 | +Microsoft Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution. Microsoft Sentinel delivers intelligent security analytics and threat intelligence, providing a single solution for alert detection, threat visibility, proactive hunting, and threat response. y providing a birds-eye view across the enterprise, Microsoft Sentinel helps alleviate the stress of dealing with increasingly sophisticated attacks, increasing volumes of alerts, and long resolution time frames. |
21 | 18 |
|
22 |
| -Microsoft Sentinel is your birds-eye view across your multicloud and hybrid infrastructure, alleviating the stress of increasingly sophisticated attacks, increasing volumes of alerts, and long resolution time frames. With Microsoft Sentinel, you can: |
| 19 | +With Microsoft Sentinel, you can: |
23 | 20 |
|
24 |
| -- Collect data at cloud scale across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds. |
| 21 | +- Collect data at cloud scale across all users, devices, applications, and infrastructure, including on-premises and across multiple clouds. |
25 | 22 | - Detect previously undetected threats and minimize false positives using Microsoft's analytics and unparalleled threat intelligence.
|
26 |
| -- Investigate threats with artificial intelligence and hunt for suspicious activities at scale, tapping into years of cyber security work at Microsoft. |
| 23 | +- Investigate threats with artificial intelligence and hunt for suspicious activities at scale. |
27 | 24 | - Respond to incidents rapidly with built-in orchestration and automation of common tasks.
|
28 | 25 |
|
29 | 26 | ## What are the observability benefits of Azure Monitor in hybrid scenarios?
|
30 | 27 |
|
31 |
| -With Azure Arc-enabled servers, the Azure portal can serve as a centralized dashboard for status monitoring and a launching pad for management of all your Azure Arc-enabled servers, along with all of your Azure and Azure Arc-enabled resources. The home page of the Azure Arc-enabled servers lists all of your servers, along with their resource groups, locations, and associated subscriptions. For each server, you can readily identify its name, OS version, and build. |
32 |
| - |
33 |
| -More in-depth monitoring, alerting, log collection, and log analytics are available through integration with Azure Monitor. Azure Monitor is a comprehensive solution for collecting, analyzing, and responding to telemetry from cloud and on-premises environments. Azure Monitor offers three main capabilities: |
| 28 | +The Azure portal can serve as a centralized dashboard for status monitoring and a launching pad for management of your Arc-enabled servers. You can view details for each server, including its name, OS version, location, associated subscription, and other details. |
34 | 29 |
|
35 |
| -- **Monitoring and metrics visualization**: Metrics are numerical values that represent the health status of monitored systems. |
36 |
| -- **Querying and analyzing logs**: Logs include activity, diagnostic, and telemetry. Their analysis provides deep insights into the state of monitored systems and helps facilitate troubleshooting. |
37 |
| -- **Alerting and remediation**: Alerts notify you of anomalous conditions. You can also configure them to automatically initiate a corrective action to remediate the issue that resulted in the alert. You can also configure alerts to raise an incident or create a work item through integration between Azure Monitor and your internal IT Service Management platform. |
| 30 | +More in-depth monitoring, alerting, log collection, and log analytics are available through integration with Azure Monitor. Azure Monitor is a comprehensive solution for collecting, analyzing, and responding to telemetry from cloud and on-premises environments. Azure Monitor offers three main capabilities that can be used with Azure Arc-enabled servers: |
38 | 31 |
|
39 |
| -You can store and analyze near real-time and historical data in a Log Analytics workspace. This requires installing the Log Analytics agent. For additional insight into interaction between servers and other systems in your environment, you can install the Dependency Agent. The same Log Analytics agent allows you to onboard your serves to other Azure services, such as Update Management, Change Tracking and Inventory, and Microsoft Defender for Cloud. |
| 32 | +- **Monitoring and metrics visualization**: Metrics are numerical values that represent the health status of monitored systems, presented in ways that help you understand the state of your servers. |
| 33 | +- **Querying and analyzing logs**: Logs include activity, diagnostic, and telemetry. Their analysis provides deep insights and helps facilitate troubleshooting. |
| 34 | +- **Alerting and remediation**: Alerts notify you of anomalous conditions. You can configure alerts to automatically initiate a corrective action that remediates these issues. You can also configure alerts to raise an incident or create a work item through integration between Azure Monitor and your internal IT Service Management platform. |
40 | 35 |
|
41 |
| -Once you install and configure the agent, servers will start forwarding telemetry to the Log Analytics workspace of your choice. You can subsequently display the collected data via Azure Monitor dashboards and analyze via Log Analytics queries. You can also implement metric or log-based rules that trigger alerts and autoremediation tasks. |
| 36 | +Once you install and configure Azure Monitor agent, servers will start forwarding telemetry to a Log Analytics workspace. You can subsequently display the collected data in Azure Monitor dashboards, and analyze it through Log Analytics queries. You can also implement rules that trigger alerts and autoremediation tasks. |
0 commit comments