Constraints when using Microsoft Defender for Cloud and Azure Sentinel and Azure Arc against on-premises outside of Azure

杉田 世紀 20 Reputation points
2023-03-24T02:14:14.5366667+00:00

I would like to use Microsoft Defender for Cloud and Azure Sentinel and Azure Arc to protect on-premises servers that exist outside of Azure.

Microsoft Defender for Cloud and Azure Sentinel and Azure Arc features fall into which of the following categories?

・A function that can be used for on-premises servers that exist outside of Azure

・Functions that cannot be used

・For on-premises use, VPN Gateway or Azure ExpressRoute to connect on-premises to the Azure virtual network

I have been unable to understand what features of Microsoft Defender for Cloud and Azure Sentinel and Azure Arc are available for on-premises servers that reside outside of Azure.

Can you please tell me in detail.🥺

Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
318 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,186 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
971 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andrew Blumhardt 9,491 Reputation points Microsoft Employee
    2023-03-28T06:12:36.21+00:00

    Arc and the agents (extensions) installed send data to public endpoints. The data is encrypted in transit and at rest using TLS 1.2. Special steps are required to us VPN or ExpressRoute (neither is required). TO force this communication over the VPN/ER you need AMPLS. https://learn.microsoft.com/en-us/azure/azure-monitor/logs/private-link-security

    1 person found this answer helpful.
    0 comments No comments

4 additional answers

Sort by: Most helpful
  1. Givary-MSFT 27,486 Reputation points Microsoft Employee
    2023-03-28T06:12:18.7066667+00:00

    @杉田 世紀 Thank you for reaching out to us, As I understand you would like to understand Microsoft Defender for cloud/Azure sentinel/Azure Arc for on-premise servers.

    Microsoft Defender for Cloud monitors the security posture of your Azure resources

    Microsoft Defender for Cloud allows you to protect non-Azure resources located on-premises or on other cloud providers, from virtual machines, Kubernetes services and SQL resources.

    To do so, those resources need to be connected to Azure by leveraging Azure Arc service – meaning that you can now manage and operate all your existing IT resources consistently and at-scale, wherever they reside, from Azure. You can also run Azure services anywhere, on-premises or in other public clouds, and take advantage of cloud benefits everywhere, such as scalability, fast deployment, and always up-to-date cloud innovation. 

    Microsoft Defender for Cloud overview

    • Strengthen your cloud security posture
    • Protect your multicloud and hybrid workloads by leveraging Azure ARC.

    What is Azure ARC - https://www.youtube.com/watch?v=HwmRsDRuskk

    Connect Azure Arc-enabled servers to Microsoft Sentinel - https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/manage/hybrid/server/best-practices/arc-azure-sentinel#:~:text=Connect%20Azure%20Arc%2Denabled%20servers%20to%20Microsoft%20Sentinel

    Let me know if you have any further questions, feel free to post back.

    1 person found this answer helpful.
    0 comments No comments

  2. 杉田 世紀 20 Reputation points
    2023-03-28T04:41:21.23+00:00

    thank you.

    I have read the provided documentation and have some questions.

    Condition A

    Install the Log Analytics agent on the on-premises Smith server you want to protect and register the on-premises Smith server with Azure Arc.

    Condition B

    The on-premises Smith server communicates with the Internet without going through Azure for communications other than the Log Analytics agent.

    Condition C.

    All communication performed by the on-premises Smith server is communicated with the outside via the Azure network.

    I understand that condition A must be met in order to protect on-premises Smith servers with Microsoft Defender for Cloud and Azure Sentinel.

    However, I wasn't sure if condition C must also be met or if condition B can also use Microsoft Defender for Cloud and Azure Sentinel.

    I cannot meet condition C.

    0 comments No comments

  3. 杉田 世紀 20 Reputation points
    2023-03-28T06:46:29.08+00:00

    I'm sorry, I didn't convey my intentions correctly to you because my explanation was insufficient.

    I don't want to meet condition C.

    I want to continue to use the on-premises server network without changing it.

    Can I use all features of Microsoft Defender for Cloud and Azure Sentinel even if I only meet condition A and condition B?


  4. 杉田 世紀 20 Reputation points
    2023-03-29T08:26:39.2933333+00:00

    Thank you for your detailed explanation.

    0 comments No comments