Practical Security Monitoring and Response in Microsoft Azure

Practical Security Monitoring and Response in Microsoft Azure

Source: YouTube · SANS Cloud Security · published Nov 28, 2023 · 33:42

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Darren Leong presents a practical approach to Azure security monitoring and incident response, emphasizing zero trust, identity-centric security, and proactive defense. 01:30

Key Takeaways:
• Zero Trust centers on verifying explicitly, enforcing least privilege access, and assuming breach by ingesting logs and documenting response plans 01:30
• Secure identity with MFA everywhere, document exceptions, track privileged identities, and leverage Conditional Access as if-then rules 04:00
• Microsoft Entra provides risky sign-in detection, unfamiliar location baselining, and smart lockout (event 50053) blocking password spray attacks 10:30
• Key detection opportunities include Graph API audit logs (public preview), CLI tool access, and PIM role abuse outside business hours 15:00
• Incident response preparation—ingesting logs into SIEM via Graph Security API and defining use cases and runbooks—is the most critical step 25:30
• Proactive defense includes running AzureHound, leveraging Microsoft on-demand assessments, and applying threat intelligence for new cloud TTPs 28:00

Effective Azure security requires shifting from perimeter-based thinking to identity-centric monitoring, combining strong preventive controls with detection and proactive threat hunting.

Sources:

  • 01:30 Zero trust principles
  • 04:00 Identity security and Conditional Access
  • 10:30 Entra risk-based analytics
  • 15:00 Detection opportunities
  • 25:30 Incident response preparation
  • 28:00 Proactive defense

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

um okay so my name is Darren Leong um I'm here today to talk about uh practical security monitoring um and instant response uh in Microsoft aor um so just a little bit about myself um so been in information cyber security um for a little while now um I'm currently in Dubai um so it's around 10:30 here at night um um so I've been in Dubai for the last three years um you know we have some pretty hot summers here in Dubai um for three to four months a year um you know a lot of the time is spent indoors and uh I thought I'd just illustrate that fact with a picture that I took from the car um during the summer this year so got up to about 50 degrees here um so I have a mate over here who said that his record for kind of highest temperature was you know close to 60° so um yeah it it does get pre…