How to log and monitor suspicious activity on a citrix application running in azure

Mornay Richards 0 Reputation points
2023-03-23T11:22:10.1166667+00:00

How can a citrix application running in azure be monitored and logs captured on any suspicious activity that is happening on the citrix platform

I dont want to use citrix analytics for security , Can microsoft defender in the cloud be used instead.

Any other suggestions would be greatly appreciated

Not Monitored
Not Monitored
Tag not monitored by Microsoft.
36,246 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 570 Reputation points Microsoft Employee
    2024-02-13T11:08:16.6133333+00:00

    Yes, Microsoft Defender for Endpoint can be used to monitor and log suspicious activity on a Citrix application running in Azure. In addition, Azure Security Center provides continuous monitoring and alerting for suspicious activity on Azure resources, including virtual machines hosting Citrix applications.

    To enable monitoring of Citrix applications running in Azure, you can follow these steps:

    1. Deploy the Microsoft Monitoring Agent to the Citrix virtual machine. This agent is required to collect data from the virtual machine and send it to Microsoft Defender for Endpoint.
    2. Install the Microsoft Defender for Endpoint sensor on the Citrix virtual machine. This sensor collects data on processes, network connections, and other activities on the virtual machine.
    3. Configure Microsoft Defender for Endpoint to monitor the Citrix virtual machine. This involves creating a new machine group in Microsoft Defender for Endpoint and adding the Citrix virtual machine to this group.
    4. Monitor the Citrix virtual machine for suspicious activity using the Microsoft Defender for Endpoint portal. You can view alerts on suspicious activity in the portal and take action to remediate any issues.
    0 comments No comments