Implement security for servers and virtual machines - Part 3
Details
In Part 3 of our Servers and Virtual Machines security series, we will focus on two important challenges every Cloud Security Engineer must address:
How do you securely provide administrative access to virtual machines without leaving management ports permanently exposed?
And:
How do you ensure that operating system security configurations remain compliant across hundreds or thousands of servers?
This session will explore how Microsoft Defender for Cloud Just-in-Time VM Access, Azure Policy, and Azure Machine Configuration can help organizations reduce their attack surface and continuously enforce secure server configurations.
About the Session
Virtual machines remain a critical part of enterprise cloud infrastructure, but they also present significant security risks when administrative services are exposed or operating system configurations drift away from organizational standards.
Leaving management ports such as RDP and SSH permanently accessible increases the potential attack surface, while inconsistent server configurations can introduce vulnerabilities, compliance gaps, and operational risk.
During this session, participants will learn how Microsoft Azure helps organizations address these challenges through:
- Just-in-Time access to virtual machines
- Time-bound administrative connectivity
- Centralized access policies
- Access auditing
- Azure Policy enforcement
- Operating system security baselines
- Azure Machine Configuration
- Continuous auditing and remediation
The objective is to move from manually securing individual servers toward a policy-driven, scalable, and continuously enforced server security model.
What You Will Learn
By the end of the session, participants should understand how to:
- Explain the security risks associated with permanently exposed RDP and SSH ports
- Understand how JIT VM access reduces the attack surface
- Enable Just-in-Time access for Azure virtual machines
- Configure per-port access policies
- Request temporary administrative access
- Audit JIT access activities
- Enforce JIT requirements using Azure Policy
- Understand how Azure Machine Configuration works
- Deploy and configure Machine Configuration prerequisites
- Audit Windows and Linux operating system configurations
- Apply Microsoft-provided security baseline policies
- Understand audit versus enforcement modes
- Enforce server configuration requirements using Azure Policy
- Create custom Machine Configurations for organization-specific requirements
- Apply configuration controls to Azure and Azure Arc-enabled servers
- Build a policy-driven server security architecture
Who Should Attend?
This session is ideal for:
- Participants in the Cloud and AI Security Bootcamp
- Cloud Security Engineers
- Azure Security Engineers
- System Administrators
- Windows and Linux Administrators
- Azure Administrators
- Infrastructure Engineers
- Cloud Architects
- Security Architects
- Azure Arc administrators
- SOC and Security Operations professionals
- DevSecOps Engineers
- Governance and Compliance professionals
- Professionals preparing for the SC-500 certification
- Anyone responsible for securing Azure servers and virtual machines
Why You Should Attend
Server security is not simply about deploying antivirus software or configuring firewall rules.
A modern server security strategy must answer critical questions:
- Are RDP and SSH ports permanently exposed?
- Who can request administrative access?
- How long should that access remain available?
- Can access activities be audited?
- Are operating system security baselines consistently applied?
- Can configuration drift be detected and remediated?
- Can the same governance model extend to hybrid servers?
This session will help participants understand how Microsoft Defender for Cloud, Just-in-Time VM Access, Azure Policy, Azure Machine Configuration, and Azure Arc can work together to address these challenges.
Whether you are administering infrastructure, designing cloud security architectures, working in security operations, or preparing for the SC-500 Cloud and AI Security Engineer certification, this session will provide practical knowledge you can apply to real-world environments.
Come ready to learn, ask questions, and strengthen your understanding of secure server administration and configuration governance.
Learn. Connect. Govern. Secure the Cloud.
