Secure compute
Server and Virtual Machine Security
CoreProtect virtual machines and servers with encryption, controlled administration, time-bound exposure, hybrid management, Defender coverage, agentless discovery, trusted launch, and configuration enforcement.
Aligned to the live SC-500 guide, which publishes no skills-measured date; guide and product behavior verified September 23, 2026.
Why this matters
Server protection spans boot integrity, disks, network administration, operating-system configuration, endpoint telemetry, vulnerability assessment, and multicloud inventory. Each control observes or enforces a different layer.
Must Know
- Azure Disk Storage server-side encryption protects managed disks by default; disk encryption sets and customer-managed keys add key-control requirements, while guest-level options address different needs.
- Azure Bastion provides browser or native-client RDP and SSH connectivity through a managed service so VMs do not require public IP addresses for administration.
- JIT VM access keeps selected management ports closed and creates a time-limited inbound rule only after an authorized request.
- Azure Arc projects supported non-Azure servers into Azure management. Defender for Servers adds workload protection and can cover Azure, Arc-enabled, AWS, and GCP machines according to plan and onboarding.
- Defender for Servers plan settings determine components such as endpoint detection and response and vulnerability assessment; coverage must be verified at the correct subscription or connector.
- Agentless scanning examines supported VM disks and configuration without deploying an in-guest agent; it complements rather than replaces EDR telemetry and response.
- Trusted launch combines secure boot and vTPM for supported generation 2 VMs; integrity monitoring supplies evidence about boot trust.
- Azure Machine Configuration audits or enforces guest settings through policy assignments and machine configuration packages.
Compare and Distinguish
- Bastion supplies an administrative connection path; JIT controls when selected inbound management ports may open.
- Agentless scanning discovers vulnerabilities or secrets from snapshots; EDR observes and responds to runtime endpoint behavior.
- Secure boot and vTPM protect boot trust; disk encryption protects stored disk data; Machine Configuration governs guest state.
Scenario examples
- Scenario: Administrators need RDP without public VM addresses. Think: deploy Bastion with the required subnet and permissions.
- Scenario: Security needs vulnerability inventory without installing another agent. Think: enable agentless scanning but retain EDR for runtime detection.
- Scenario: A policy requires trusted boot plus encrypted disks. Think: configure supported trusted-launch features and the appropriate disk encryption control.
Exam traps
- Bastion does not grant operating-system credentials or Azure VM login roles.
- JIT is not a persistent allow rule and does not replace patching or strong authentication.
- Arc onboarding alone does not enable every Defender for Servers component.
- Agentless scanning cannot perform live endpoint containment.
Key takeaways
- Minimize direct management exposure and use time-bound access.
- Verify Defender component coverage rather than assuming onboarding implies protection.
- Combine boot trust, encryption, runtime telemetry, vulnerability discovery, and guest configuration.
How it works
- Azure platform controls protect VM disks and boot while network services constrain administration paths.
- Arc and Defender connect server inventory, posture, vulnerability, EDR, and agentless evidence into cloud security operations.
Objects and administrative surfaces
- VM disk encryption, disk encryption sets, Key Vault permissions, security type, secure boot, vTPM, and integrity monitoring.
- Azure Bastion host, virtual network and subnet, JIT policies, NSG rules, and request history.
- Azure Arc machine inventory, Defender for Servers plan components, vulnerability findings, EDR onboarding, agentless scanning, and Machine Configuration assignments.
When to use it
- Use Bastion for private administrative access and JIT where time-bound port opening remains necessary.
- Use Machine Configuration when policy must inspect or enforce operating-system settings across Azure-managed servers.
Security and governance implications
- Protect disk keys, Bastion access, JIT approval, Arc onboarding credentials, Defender plan changes, and policy exemptions.
- Track machines without EDR, vulnerability assessment, agentless coverage, trusted launch, or compliant guest configuration.
Troubleshooting signals
- For Bastion failure, check subnet, routing, NSG, target VM state, credentials, and user authorization.
- For missing Defender results, check plan scope, connector or Arc state, component provisioning, platform support, and scan recency.
More detail
- Choose and configure disk encryption and key ownership.
- Deploy Bastion and JIT according to the administration path.
- Onboard Arc and Defender for Servers across cloud boundaries and verify EDR, vulnerability, and agentless components.
- Configure trusted launch and Machine Configuration for platform and guest security.
Ready for the quiz?
- When do Bastion and JIT solve different requirements?
- Why does agentless scanning not replace EDR?
- Which features establish trusted launch for a supported VM?
Related objectives
- D3.2.S1 — Implement and configure disk encryption
- D3.2.S2 — Plan and implement Azure Bastion
- D3.2.S3 — Enable and enforce use of just-in-time (JIT) VM access
- D3.2.S4 — Extend security controls to hybrid and multicloud servers by using Azure Arc
- D3.2.S5 — Onboard servers to Defender for Servers in Defender for Cloud, including hybrid and multicloud scenarios
- D3.2.S6 — Configure Defender for Servers settings, including vulnerability scanning, and endpoint detection and response (EDR)
- D3.2.S7 — Implement and manage agentless scanning for VMs in Defender for Servers
- D3.2.S8 — Configure security features on a VM, including secure boot, virtual Trusted Platform Module (vTPM), integrity monitoring, and security type
- D3.2.S9 — Enforce security configuration of Azure-managed servers by using Azure Machine Configuration