secure-by-design

ZeroConf Secure Infra for SMBs


Project maintained by mics-sbd Hosted on GitHub Pages — Theme by mattgraham

Next Steps

Now that you’re up and running, here are some additional things to do in order to maintain longterm security of your infrastructure. These are things we would have done for you, but Azure doesn’t quite give us a way to automate it. Check back here often!

Add Additional Owners

As good BCDR practice, you should have at least two Owner level users on your subscription.

  1. Add an additional user in AAD.
  2. Add the Owner Role to your new User

Add Additional Users to RBAC

When we provision your infrastructure, we create an RBAC group called $namePrefixadmins. These users have control over your infrastructure, including secrets. You can add more users to help manage things.

Add User to Groups

Enable MFA

Enable Multi-Factor Auth to prevent your accounts from being hijacked.

Configure Azure Sentinel

Azure Sentinel is a SIEM to help monitor your subscriptions from bad guys.

It uses existing log sources to find Indicators of Compromise and will notify you of anything nasty, or can be used to automate remediation.

Sentinel is a paid service, and you will be billed per GB of logs that it ingests. For billing, see Sentinel Pricing

  1. Create a Sentinel Workspace
  2. Connect to the workspace we provisioned
  3. Connect datasources