How can we take care of vulnerabilities in the Azure portal? please provide me steps best steps.

A ngel 20 Reputation points
2023-08-28T06:30:08.16+00:00

How can we take care of vulnerabilities in the Azure portal? please provide me steps best steps.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2023-08-29T21:54:03.1+00:00

    Hi @A ngel ,

    I understand that you are trying to address security vulnerabilities in the Azure portal.

    If you are referring specifically to the vulnerability assessments from Microsoft Defender for Cloud, you can go to view and remediate these findings by following these steps:

    1. From Defender for Cloud's menu, open the Recommendations page.
    2. Select the recommendation Machines should have vulnerability findings resolved.

    Defender for Cloud shows you all the findings for all VMs in the currently selected subscriptions. The findings are ordered by severity.

    [The findings from your vulnerability assessment solutions for all selected subscriptions.

    ](https://learn.microsoft.com/en-us/azure/defender-for-cloud/media/remediate-vulnerability-findings-vm/vulnerabilities-should-be-remediated.png#lightbox)

    1. To filter the findings by a specific VM, open the "Affected resources" section and click the VM that interests you. Or you can select a VM from the resource health view, and view all relevant recommendations for that resource.

    Defender for Cloud shows the findings for that VM, ordered by severity.

    1. To learn more about a specific vulnerability, select it.

    [Details pane for a specific vulnerability.

    ](https://learn.microsoft.com/en-us/azure/defender-for-cloud/media/remediate-vulnerability-findings-vm/vulnerability-details.png#lightbox)

    The details pane that appears contains extensive information about the vulnerability, including:

    • Links to all relevant CVEs (where available)
      • Remediation steps
        • Any additional reference pages
    1. To remediate a finding, follow the remediation steps from this details pane.

    If your goal is to address vulnerabilities more generally and maintain security best practices, you can monitor and respond to threat activity using the Microsoft Defender for Cloud and Microsoft Defender for Endpoint's recommendations, as well as the other security portals listed here.

    I recommend reviewing the security best practices and patterns guide here, as well as the Azure Operational Security best practices guide here.

    In addition, as general guidance for avoiding vulnerabilities, I would recommend the following best practices:

    1. Use Identity and Access Management and Role-Based Access Control to ensure that only authorized users have access to resources, and assign access using the principal of least privilege.
    2. Use Conditional Access to enforce security policies for accessing your resources.
    3. Use Azure Monitor to monitor your resources and detect security threats.
    4. Keep your resources updated with the latest security patches.

    Let me know if this addresses your question and if you have further concerns. I'm not sure if your question was more specifically focused on the logistics of addressing Microsoft Defender for Cloud vulnerabilities, or about security best practices to avoid vulnerabilities in general. I tried to address both questions.

    If the information helped you, please Accept the answer. This will help us and improve discoverability for others in the community who may be researching similar questions. Otherwise let us know if you have further concerns.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.