Implement Windows Server IaaS VM network security

Solution Architect
Technology Manager
Azure Cloud Shell
Azure Portal
Azure Virtual Machines

In this module, you will focus on how to improve the network security for Windows Server infrastructure as a service (IaaS) virtual machines (VMs) and how to diagnose network security issues with those VMs.

Learning objectives

After completing this module, you will be able to:

  • Implement Network Security Groups (NSGs) with Windows Server IaaS VMs.
  • Implement adaptive network hardening.
  • Implement Azure Firewall.
  • Implement Windows Defender Firewall in Windows Server IaaS VMs.
  • Choose an appropriate filtering solution.
  • Capture network traffic with Network Watcher.


To get the best learning experience from this module, it's important that you have knowledge and experience in the following areas:

  • Managing Windows Server operating systems (OSs) and Windows Server workloads in on-premises scenarios, including AD DS, Domain Name System (DNS), the Distributed File System (DFS), Microsoft Hyper-V, and file and storage services
  • Common Windows Server management tools
  • Core Microsoft compute, storage, networking, and virtualization technologies
  • On-premises resiliency Windows Server–based compute and storage technologies
  • Implementing and managing IaaS services in Azure
  • Microsoft Entra ID
  • Security-related technologies (firewalls, encryption, multi-factor authentication)
  • Windows PowerShell scripting
  • Automation and monitoring