Microsoft cloud security benchmark: Azure compute benchmark

Microsoft cloud security benchmark: Azure compute benchmark

This article is contributed. See the original author and article here.

Azure compute benchmark is now aligned with CIS


 


Security benchmarks help organizations strengthen their security posture and meet various cloud security compliance requirements. The Microsoft cloud security benchmark announced at Ignite 2022 provides clear and concrete guidance to securely configure cloud resources.


 


Today, we are excited to announce a new Azure compute benchmark for Azure virtual machines. This newly released benchmark has the CIS recommended security configurations aligned with the Azure environment. this new benchmark takes into consideration the cloud-specific security controls and removes non-applicable controls that have no significant risk impact in cloud environment.


 


CIS Azure Compute Microsoft Windows Server 2019 Benchmark v1.0.0’ can be downloaded from CIS benchmark for Cloud computeYou will be able to seamlessly monitor the secure configuration settings of the new CIS benchmark in Microsoft Defender for Cloud as well as via the built-In Windows baseline Azure policy in the Azure policy Portal.


 


gugovind_0-1668813756632.png


  Figure 1: Azure Security and CIS benchmark team collaboration


 


Benchmark usage scenarios


Using Microsoft Defender for Cloud:


You will be able to monitor the security baseline settings for Windows Server in the Microsoft Defender for Cloud portal by going to the ‘Remediate Security Configurations’ in ‘Recommendations’ section and selecting ‘Vulnerabilities in security configuration on your Windows machines should be remediated (powered by Guest Configuration)’


 


gugovind_0-1668817670486.png


Figure 2: Microsoft Defender for Cloud Portal


 


You will be able see the status of each baseline rule, view baseline failures through ‘Expected’ and ‘Actual’ values, understand the risk and impact of each misconfiguration, and view additional steps to remediate them.


 


gugovind_1-1668817772214.png


Figure 3: Windows Baseline Recommendation


 


Using as a ‘BuiltIn’ Policy in Azure Policy Portal:


Alternatively, you can also leverage the Windows Baseline available as a built-in policy to monitor the security configurations setting of your Windows servers. You can assign the “Windows machines should meet requirements of the Azure compute security baseline” and monitor the compliance results in the Azure Policy portal.


 


gugovind_3-1668817974975.png


Figure 4: Azure Policy Portal


 


What Next?



  • Achieving CIS benchmark certification for the Azure compute baseline: We will be working with the CIS benchmark team to certify the benchmark monitoring implementation to ensure it meets the CIS requirements.

  • Publishing a Linux baseline for Ubuntu distributions that is specific to Azure compute: Similar to Windows Server Benchmark, we will be working with CIS benchmark team to develop the Linux baseline for Ubuntu distributions specific to Azure.


We want to thank the CIS benchmark team, contributors from the CIS community and multiple teams within Microsoft for their help with publishing the benchmark!


 


If you would like to participate in improving the benchmark or provide feedback, please send us an email. We would love to hear your success stories and feedback on how to make it better!


 


Additional References:





 

Learning Op: Migrate Away From ADFS to Azure AD

Learning Op: Migrate Away From ADFS to Azure AD

This article is contributed. See the original author and article here.

 


Hello to our illustrious and awesome readers!


 


Brandon Wilson here today with a short post just to give our readers a heads up on an excellent learning opportunity that we thought it might be helpful for many of you.


 


Since there is already content out there, I won’t be going into depth on this, other than to say it will cost you a couple of hours, for a couple of days, and we anticipate the time will be well spent! Go forth and learn (and then pass the knowledge around)! The below content summary will take you to the page to see upcoming workshop dates/times, as well as provide you with the registration link.


 


So, without further ado, let’s introduce this CTO! style:


 


BrandonWilson_0-1668808352630.jpeg


 


Title: Upcoming Microsoft Workshops: How to successfully migrate away from AD FS to Azure AD


Source: Community Events List


Author: Melissa Cox


Publication Date: November 2, 2022


Content excerpt:


Join us to learn how to successfully migrate from AD FS to Azure AD to benefit from improved security and better user experience for your organization. During this in-depth workshop, we want to share why other customers have moved to Azure AD, and what to keep in mind to successfully migrate from AD FS.


 


BrandonWilson_1-1668808352633.jpeg


 


Thanks for reading, and I hope this helps you out…we’ll see you on Azure (AD)!