Skip to main content
Version: Next

Phase 04: Security & Governance

Runbook Azure

DOCUMENT CATEGORY: Runbook SCOPE: Security and governance configuration PURPOSE: Apply security controls, policies, and compliance baselines

Status: Active


Overview

This stage configures security controls, compliance policies, and governance for the Azure Local environment. These configurations ensure the cluster meets security requirements and organizational compliance standards.

Prerequisites

  • Azure Local cluster deployed and Arc-enabled
  • Monitoring configured (Stage 18)
  • Log Analytics workspace available

Steps

StepTitleDescription
1Enable Defender for CloudEnable Microsoft Defender for Cloud protection
2Apply Azure Policy InitiativesApply governance policies and initiatives
3Configure Security BaselinesConfigure security baseline settings
4Enable Security LoggingConfigure security event logging
5Configure Azure Update ManagerConfigure patch management and update orchestration

Stage Completion Criteria

  • Defender for Cloud enabled for cluster resources
  • Azure Policy initiatives assigned
  • Security baselines configured
  • Security logging enabled and forwarding to Log Analytics
  • Azure Update Manager configured with maintenance schedules

PreviousUpNext
Phase 19: Backup & DROperational FoundationsPhase 21: Licensing & Telemetry