Investigating threats with Defender for Cloud
In Chapter 13, Security Monitoring and Reporting, we enabled and configured the enhanced security features of Defender for Cloud to gain the benefits of all available advanced features. This included just-in-time VM access, regulatory compliance dashboard and reports, adaptive application controls, EDR for servers, and threat protection for PaaS services. With the enhanced security features enabled, you can investigate threats in Defender for Cloud by following these steps:
- Sign into the Azure portal at https://portal.azure.com.
- Search for
Microsoft Defender for Cloud
and open it. - Click on Security Alerts within the General section.
- Here, you can view active alerts and the associated affected resources. Select one of the alerts to review additional information in the window that appears on the right, as shown in the following screenshot.