Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard

A global enterprise has implemented Microsoft Defender for Cloud across all its Azure subscriptions, which are organized into several management groups. The security team needs to ensure that a specific set of security recommendations, defined by a custom Azure Policy, is applied consistently to all new and existing Linux virtual machines across all subscriptions within a particular management group. How should the security team achieve this with minimal administrative overhead?

  1. AAssign the custom Azure Policy at the subscription level for each subscription containing Linux VMs.
  2. BAssign the custom Azure Policy at the target management group level, with a 'DeployIfNotExists' effect, and ensure auto-provisioning for the Log Analytics agent is enabled.
  3. CManually assign the custom Azure Policy to each Linux VM as it is provisioned.
  4. DCreate a separate Azure Automation runbook to periodically check and remediate non-compliant Linux VMs.
Show answer & explanation

Correct answer: B. Assign the custom Azure Policy at the target management group level, with a 'DeployIfNotExists' effect, and ensure auto-provisioning for the Log Analytics agent is enabled.

Assigning the Azure Policy at the management group level ensures it applies to all current and future subscriptions and resources within that group. Using a 'DeployIfNotExists' effect automatically remediates non-compliant resources. Enabling auto-provisioning for the Log Analytics agent ensures the necessary agent is present for Defender for Cloud to collect data and for the policy to be effective on Linux VMs.

Why the other options are wrong

  • A. Assigning at the subscription level requires repeated assignments for multiple subscriptions and doesn't cover new subscriptions in the management group automatically.
  • C. Manual assignment is not scalable and increases overhead, contradicting 'minimal administrative overhead'.
  • D. An Azure Automation runbook is a reactive and more complex approach compared to the proactive and integrated 'DeployIfNotExists' policy effect.

Management Group Policy with DeployIfNotExists

Assigning an Azure Policy with the 'DeployIfNotExists' effect at the management group level ensures automatic and consistent application of security configurations and remediation across all current and future subscriptions and resources within that management group.

  • Scalable for large organizations.
  • Ensures continuous compliance.
  • Requires appropriate permissions at the management group scope.
  • Often used with auto-provisioning of agents for Defender for Cloud.

Memory trick: Management Group Policy: One rule for the whole enterprise floor.

More Mitigate threats using Microsoft Defender for Cloud questions