Best practice rules for Defender
- Apply Latest OS Patches
Ensure that the latest OS patches available for Microsoft Azure virtual machines (VMs) are applied.
- Configure Additional Email Addresses for Azure Security Center Notifications
Ensure that additional email addresses are provided to receive security notifications.
- Detect Create, Update or Delete Security Solution Events
Security solution changes have been detected within your Microsoft Azure cloud account.
- Detect Update Security Policy Event
Azure security policy changes have been detected within your Microsoft Azure cloud account.
- Email Notification for Alerts
Ensure that Email Notification for Alerts is set to On.
- Email To Subscription Owners
Ensure that Send email also to subscription owners is set to On.
- Enable Agentless Container Vulnerability Assessment
Enable agentless vulnerability assessment for container images.
- Enable Agentless Discovery for Kubernetes
Enable agentless API-based discovery of Kubernetes resources.
- Enable Agentless Scanning for Machines in Microsoft Defender for Cloud
Ensure that "Agentless scanning for machines" is enabled in Microsoft Defender for Cloud for your Azure subscriptions.
- Enable All Parameters for Microsoft Defender for Cloud Default Policy
Ensure that all the parameters supported by Microsoft Defender for Cloud default policy are enabled.
- Enable Attack Path Email Notifications
Ensure that email notifications for attack paths with an appropriate risk level are enabled in Microsoft Defender for Cloud.
- Enable Automatic Provisioning of Microsoft Defender for Containers Components
Ensure that automatic provisioning of security components is enabled for Azure containers.
- Enable Automatic Provisioning of Vulnerability Assessment for Virtual Machines
Ensure that automatic provisioning of vulnerability assessment solutions is enabled for virtual machines.
- Enable Automatic Provisioning of the Monitoring Agent
Ensure that "Automatic provisioning of monitoring agent" feature is enabled to enhance security at the virtual machine (VM) level.
- Enable DDoS Protection Standard Monitoring for Public Virtual Networks
Ensure that monitoring of DDoS protection at the Azure virtual network level is enabled.
- Enable Defender Auto Provisioning Extensions
Enable auto-provisioning extensions for Microsoft Defender for Cloud in your Azure subscriptions.
- Enable Defender for APIs
Ensure that Defender for APIs is enabled for Azure API Management services.
- Enable Defender for Endpoint Integration with Microsoft Defender for Cloud
Ensure that Defender for Endpoint – Defender for Cloud integration is enabled.
- Enable File Integrity Monitoring in Microsoft Defender for Cloud
Ensure that the File Integrity Monitoring (FIM) component is enabled in Microsoft Defender for Cloud to monitor critical system files for signs of attack or compromise.
- Enable High Severity Email Notifications
Ensure that Email Notification for Alerts is set to On.
- Enable Microsoft Defender Standard Pricing Tier
Ensure that Microsoft Defender for Cloud standard pricing tier is enabled in your Azure account.
- Enable Microsoft Defender for Cloud Apps Integration
Ensure that Microsoft Defender for Cloud Apps integration is enabled.
- Enable Microsoft Defender for Cloud for App Service Instances
Ensure that Microsoft Defender for Cloud is enabled for Azure App Service instances.
- Enable Microsoft Defender for Cloud for Azure Containers
Ensure that Microsoft Defender for Cloud is enabled for Azure containers.
- Enable Microsoft Defender for Cloud for Azure DNS (Legacy)
Ensure that Microsoft Defender for Cloud is enabled for resources that use Azure DNS.
- Enable Microsoft Defender for Cloud for Azure Resource Manager
Ensure that Microsoft Defender for Cloud is enabled for Azure Resource Manager.
- Enable Microsoft Defender for Cloud for Azure SQL Database Servers
Ensure that Microsoft Defender for Cloud is enabled for SQL database servers.
- Enable Microsoft Defender for Cloud for Key Vaults
Ensure that Microsoft Defender for Cloud is enabled for Azure key vault resources.
- Enable Microsoft Defender for Cloud for Open-Source Relational Databases
Ensure that Microsoft Defender for Cloud is enabled for open-source relational databases.
- Enable Microsoft Defender for Cloud for SQL Server Virtual Machines
Ensure that Microsoft Defender for Cloud is enabled for SQL Server virtual machines.
- Enable Microsoft Defender for Cloud for Storage Accounts
Ensure that Microsoft Defender for Cloud is enabled for Azure storage accounts.
- Enable Microsoft Defender for Cloud for Virtual Machines
Ensure that Microsoft Defender for Cloud is enabled for virtual machine (VM) servers.
- Enable Microsoft Defender for IoT Hub
Ensure that Microsoft Defender for IoT is set to 'On' for your Azure IoT Hub resources.
- Enable Monitoring of Deprecated Accounts
Ensure that the monitoring of deprecated accounts is enabled.
- Enable Virtual Machine IP Forwarding Monitoring
Ensure that IP forwarding enabled on your Azure virtual machines (VMs) is being monitored.
- Enable Vulnerability Assessment Periodic Recurring Scans
Ensure that Vulnerability Assessment Periodic Recurring Scans are enabled for SQL database servers.
- Enable Vulnerability Assessment for Microsoft SQL Servers
Ensure that Vulnerability Assessment is enabled for Microsoft SQL database servers.
- Ensure Microsoft Defender CSPM is Enabled
Ensure that Microsoft Defender CSPM is set to 'On' to continuously assess cloud resources for security misconfigurations, compliance risks, and exposure to threats.
- Ensure Microsoft Defender EASM is Enabled
Ensure that Microsoft Defender External Attack Surface Management (EASM) is deployed to continuously discover, inventory, and monitor your organization's externally exposed digital assets.
- Ensure Non-Deprecated Microsoft Cloud Security Benchmark Policies Are Not Disabled
Ensure that non-deprecated Microsoft Cloud Security Benchmark (MCSB) policies are not set to a Disabled effect to maintain visibility into your security recommendations.
- Microsoft Defender for Cloud Recommendations
Ensure that Microsoft Defender for Cloud recommendations are examined and resolved.
- Microsoft Defender for Cloud Security Alerts
Ensure that Microsoft Defender for Cloud security alerts are examined and resolved.
- Monitor Adaptive Application Safelisting
Ensure that Adaptive Application controls isn't set to Disabled.
- Monitor Advanced Threat Protection Alerts for Storage Accounts
Ensure that a monitoring and response process is configured to action Microsoft Defender for Storage security alerts in a timely manner.
- Monitor Disk Encryption
Ensure that Disk Encryption isn't set to Disabled.
- Monitor Endpoint Protection
Ensure that Endpoint protection isn't set to Disabled.
- Monitor External Accounts with Write Permissions
Ensure that the external accounts with write permissions are monitored using Azure Security Center.
- Monitor JIT Network Access
Ensure that JIT Network Access isn't set to Disabled.
- Monitor Network Security Groups
Ensure that Network Security Groups isn't set to Disabled.
- Monitor OS Vulnerabilities
Ensure that Security Configurations isn't set to Disabled
- Monitor SQL Auditing
Ensure that SQL Auditing isn't set to Disabled
- Monitor SQL Encryption
Ensure that SQL Encryption isn't set to Disabled.
- Monitor Storage Blob Encryption
Ensure that Storage Encryption isn't set to Disabled.
- Monitor System Updates
Ensure that System updates isn't set to Disabled.
- Monitor Vulnerability Assessment
Ensure that Vulnerability Assessment isn't set to Disabled.
- Monitor Web Application Firewall
Ensure that Web Application Firewall isn't set to Disabled.
- Monitor the Total Number of Subscription Owners
Ensure that the total number of subscription owners within your Azure account is monitored.
- Next Generation Firewall(NGFW) Monitoring
Ensure that Next generation firewall isn't set to Disabled.
- Security Contact Emails
Ensure that a valid security contact email address is set.
- Security Contact Phone Number
Ensure that a valid security contact phone number is set.