Identity, access and governance
- Secure Microsoft Entra ID: Privileged Identity Management, Conditional Access, MFA and passwordless sign-in
- Identities for applications, OAuth permissions and consent settings, managed identities
- Azure Key Vault: deployment, access and firewall, managing keys, secrets and certificates, Defender for Key Vault, finding exposed secrets
- Governance: Azure Policy with built-in and custom definitions, regulatory compliance in Defender for Cloud, resource locks, role management and reducing over-privileged assignments, securing Azure Backup, security requirements as infrastructure as code
Storage, databases and networking
- Secure storage accounts: firewall rules, access policies, Defender for Storage
- Databases: security configuration in Azure SQL, auditing, Defender for Databases
- Networking: network and application security groups, Azure Virtual Network Manager, security for Virtual WAN and VPN, Microsoft Entra Private Access
- Private endpoints and Private Link, Azure Firewall, checking effective security rules with Network Watcher
Secure compute and AI
- AI security: detect data over-exposure in SharePoint, assess risks around Microsoft Copilot and AI apps with Purview DSPM
- Real-time protection for Copilot Studio agents, Conditional Access for Entra Agent ID, blast-radius analysis with Defender XDR
- AI Gateway in Azure API Management, Defender for AI Service, guardrails in Foundry, the data and AI security dashboard
- Servers and virtual machines: disk encryption, Azure Bastion, just-in-time access, Azure Arc for hybrid and multicloud servers, Defender for Servers including vulnerability scanning and EDR, Secure Boot and vTPM
- Application platform: Defender for Containers, AKS, Container Registry, Container Apps, Functions, Logic Apps, App Service, Web Application Firewall, API Management
Monitor security posture
- Defender for Cloud: detect risks with Defender CSPM, assess compliance, enable workload protection plans, connect AWS and GCP, External Attack Surface Management
- Microsoft Sentinel: workspaces and roles, Content Hub, data connectors, Syslog and CEF, Windows security events, custom log tables, automation rules and playbooks, retention
- Microsoft Security Copilot: workspaces, permissions and roles, plugins and agents