Search icon CANCEL
Subscription
0
Cart icon
Cart
Close icon
You have no products in your basket yet
Save more on your purchases!
Savings automatically calculated. No voucher code required
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Microsoft Defender for Cloud Cookbook

You're reading from  Microsoft Defender for Cloud Cookbook

Product type Book
Published in Jul 2022
Publisher Packt
ISBN-13 9781801076135
Pages 314 pages
Edition 1st Edition
Languages
Author (1):
Sasha Kranjac Sasha Kranjac
Profile icon Sasha Kranjac
Toc

Table of Contents (12) Chapters close

Preface 1. Chapter 1: Getting Started with Microsoft Defender for Cloud 2. Chapter 2: Multi-Cloud Connectivity 3. Chapter 3: Workflow Automation and Continuous Export 4. Chapter 4: Secure Score and Recommendations 5. Chapter 5: Security Alerts 6. Chapter 6: Regulatory Compliance and Security Policy 7. Chapter 7: Microsoft Defender for Cloud Workload Protection 8. Chapter 8: Firewall Manager 9. Chapter 9: Information Protection 10. Chapter 10: Workbooks 11. Other Books You May Enjoy

Connecting non-Azure virtual machines using Azure Arc

Before Microsoft Defender for Cloud can monitor your security posture and display security recommendations of your non-Azure computers, you must connect them to Azure. This recipe will show you how to connect a non-Azure server to Azure using Azure Arc.

Getting ready

Before you start connecting servers to Azure using Azure Arc, you must have administrative permissions on a target server to install and configure it.

Open a web browser and navigate to https://portal.azure.com.

How to do it…

To enable Microsoft Defender for Cloud Plans on multiple subscriptions at once, complete the following steps:

  1. In the Azure portal, open Azure Arc. You can open Azure Arc in multiple ways: by typing Azure Arc in the search bar, by going to All Services, or by clicking on the respective link in Favorites.
  2. On the left menu, select Servers:
Figure 2.1 – Selecting Azure Arc | Servers

Figure 2.1 – Selecting Azure Arc | Servers

  1. At the top of the Azure Arc | Servers blade, select + Add:
Figure 2.2 – Add servers with Azure Arc

Figure 2.2 – Add servers with Azure Arc

  1. In Add single server box, select Generate script.
  2. On the Prerequisites blade, read the information provided and click Next: Resource details at the bottom of the blade.
  3. On the Resource details blade, select the subscription and resource group that will contain the server you are adding and that will be managed in Azure. In addition, select the Azure region where the metadata for resources will be created, and the operating system that the server is running. If the server you are adding is unable to communicate directly to the internet and Azure data centers, specify the URL of the proxy server that the non-Azure server can use. At the bottom of the page, click Next: Tags to proceed to the next step:
Figure 2.3 – Add a server with Azure Arc – Resource details

Figure 2.3 – Add a server with Azure Arc – Resource details

  1. On the ❸ Tags blade, enter physical location tags that will identify the server you are adding, as well as any additional tags that will help you organize the resources better. At the bottom of the blade, click Next: Download and run script:
Figure 2.4 – Add a server with Azure Arc – Physical location tags

Figure 2.4 – Add a server with Azure Arc – Physical location tags

  1. In the Download and run script section, click on the Download button to download and save the OnboardingScript.ps1 script. Copy the script onto the server you are onboarding to Azure Arc. Select Close to finish and close the Add a server with Azure blade. On the top-right side of the Add servers with Azure Arc blade, click X to close the blade and return to the Azure Arc | Servers blade:
Figure 2.5 – Add a server with Arc – Download and run script

Figure 2.5 – Add a server with Arc – Download and run script

  1. On the server you are onboarding to Azure Arc, run OnboardingScript.ps1. The script will download and install Azure Connected Machine Agent, initiate authentication to Azure, create an Azure Arc-enabled server resource, and associate it with the agent:
Figure 2.6 – Executing the installation script on a target machine

Figure 2.6 – Executing the installation script on a target machine

  1. After successfully installing Azure Connected Machine Agent, authenticating, and creating an Azure Arc enabled resource in Azure, you should receive a message about having signed into the Azure Connected Machine Agent application:
Figure 2.7 – Successful Azure Connected Machine Agent sign-in message

Figure 2.7 – Successful Azure Connected Machine Agent sign-in message

  1. In the Azure portal, on the Azure Arc | Servers blade, click Refresh to display the newly onboarded server in Azure Arc:
Figure 2.8 – Newly onboarded server visible in the Azure Arc | Servers blade

Figure 2.8 – Newly onboarded server visible in the Azure Arc | Servers blade

  1. After a while, the newly added Azure Arc server will be visible in Microsoft Defender for Cloud, including its Inventory and Recommendations:
Figure 2.9 – Newly onboarded server visible in Microsoft Defender for Cloud | Inventory

Figure 2.9 – Newly onboarded server visible in Microsoft Defender for Cloud | Inventory

  1. Click on the newly added server. The Resource Health page opens.

How it works…

Azure Arc-enabled servers is a cloud service that allows you to manage servers hosted outside of Azure, such as on-premises or on other cloud providers, and it is the preferred way of adding non-Azure machines to Microsoft Defender for Cloud. Azure Arc-enabled machines support additional monitoring and configuration management tasks, such as configuration changes reporting, guest configuration policies, VM Insights, simplified deployment, update management, security monitoring, threat detection, and others. Once you connect a non-Azure machine to Azure Arc, it will be visible and protected by Microsoft Defender for Cloud.

You have been reading a chapter from
Microsoft Defender for Cloud Cookbook
Published in: Jul 2022 Publisher: Packt ISBN-13: 9781801076135
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime