Overview and What You Will Learn
In this lab, you will enable Microsoft Defender for Cloud, review its Secure Score and recommendations, deliberately create a misconfiguration to see it get flagged, then fix it and watch the score respond - connecting an abstract number to concrete, actionable fixes.
Why This Matters in Production
A team assumes their Azure environment is reasonably secure because nothing has gone wrong yet, without ever checking whether basic protections like disk encryption or public access restrictions are actually enabled across their resources. Secure Score turns that vague assumption into a specific, prioritized list of exactly what to fix, ranked by how much each fix actually improves the environment's real security posture.
Core Principles
Defender for Cloud continuously scans your actual deployed resources and compares their configuration against a set of security best practices, producing both a single overall score and a specific list of recommendations behind that score.
+------------------------------------------+| Defender for Cloud scans deployed resources|+------------------------------------------+ | v+------------------------------------------+| Compares against security best practices || (encryption, network exposure, patching, || identity hygiene, and more) |+------------------------------------------+ | v+------------------------------------------+| Secure Score: a single number reflecting || how many recommended controls are actually || implemented, out of the total that apply |+------------------------------------------+ | v+------------------------------------------+| Specific, actionable recommendations || (e.g. "enable disk encryption on this VM") |+------------------------------------------+The score itself is less important than the specific recommendations behind it - a low score with three critical, easy fixes is a better position to be in than a slightly higher score hiding one deeply entrenched, hard-to-fix issue.
Detailed Step-by-Step Practical Lab
- Create a Resource Group and a storage account with an intentionally weak configuration to observe being flagged:
az group create --name rg-defender-lab-mumbai --location centralindia az storage account create \ --name stdefenderlabrahul \ --resource-group rg-defender-lab-mumbai \ --location centralindia \ --sku Standard_LRS \ --allow-blob-public-access trueNote
--allow-blob-public-access truedeliberately creates a misconfiguration for this lab - allowing public access to blobs is a common real-world finding Defender for Cloud specifically checks for and flags.
- Check your current Secure Score for the subscription:
az security secure-scores list --output table- List current recommendations, which should include a flag for the storage account's public access setting created in step 1:
az security tasks list --output table- Review the specific recommendation details for the public blob access finding, then fix it by disabling public access:
az storage account update \ --name stdefenderlabrahul \ --resource-group rg-defender-lab-mumbai \ --allow-blob-public-access false- Recommendations and score updates are not instantaneous - Defender for Cloud re-evaluates on its own schedule, so re-check after some time has passed:
az security secure-scores list --output table- Review recommendations by severity to understand prioritization - high-severity findings should generally be addressed before lower-severity ones, even if a lower-severity fix would be quicker to implement:
az security tasks list \ --query "[?properties.severity=='High']" --output table- Clean up:
az group delete --name rg-defender-lab-mumbai --yes --no-waitProduction Best Practices & Common Pitfalls
Common MistakeChasing Secure Score as a number to maximize, rather than actually reading and prioritizing the specific recommendations behind it. A slightly lower score with all critical, high-severity issues resolved is a stronger security position than a higher score that still has one serious unresolved finding sitting among many minor ones.
TipReview Secure Score recommendations regularly, not just once during initial setup. New resources get created, configurations drift over time, and a recommendation that didn't apply last month may apply today simply because something new was deployed.
- Not every recommendation applies equally to every environment. A recommendation about a service you don't actually use can often be safely dismissed rather than chased purely to raise the score - use judgment about which recommendations genuinely matter for your specific workloads.
- Free-tier Defender for Cloud gives you Secure Score and basic recommendations; paid tiers add active threat protection. Understand which tier you're on so you know whether you're getting recommendations only, or genuine real-time threat detection as well.
Quick Reference & Troubleshooting Commands
| Command | Description |
|---|---|
az security secure-scores list |
Check the current Secure Score |
az security tasks list |
List current security recommendations |
az security tasks list --query "[?properties.severity=='High']" |
Filter recommendations by severity |
az storage account update --allow-blob-public-access false |
Fix a common public-access misconfiguration |