Protecting cloud resources.
WHAT TO CONFIGURE FIRST
Multi-factor authentication for every administrator Role assignments at the narrowest scope Network rules denying by default Management ports closed to the internet
WHAT TO USE FOR SECRETS
A key vault, with managed identities, so no credential sits in configuration.
WHAT TO ENABLE
Security posture monitoring, which reports misconfiguration against benchmarks Threat detection for key services Audit logging, retained
WHAT TO REVIEW REGULARLY
Public exposure of resources Role assignments, particularly at subscription scope Resources without network restrictions Recommendations from the posture service
WHAT THE COMMONEST EXPOSURES ARE
Storage left publicly accessible Management ports open Over-permissive role assignments Secrets in configuration or code
WHAT TO ENFORCE WITH POLICY
Required tags Permitted regions Prohibited resource types Required encryption
WHAT POLICY ENFORCEMENT PROVIDES
Prevention rather than detection.
WHAT TO PLAN
A response procedure for a compromised subscription.
WHAT TO PROTECT SPECIFICALLY
Backups, and the identities that can delete them.