Prevent hacking with our 4 tips. Read on to find out more.

Best practices to prevent hacking

November 10, 2024
No items found.
Table of contents
Who you gonna call?
Get in touch

Azure cost compass

T/m 30 september korting
op onze IT-scans

Simon Deeb, one of our cloud colleagues, attended Microsoft’s App Innovation Event at the end of November. A clear message quickly emerged: enable MFA on all accounts with Azure Subscription permissions! Why? Hackers are actively targeting poorly secured Azure subscriptions, spinning up as many virtual machines (VMs) as possible to use for crypto mining. This urgent warning was shared by Tony Krijnen, Cloud Solutions Architect for Security & Compliance. See also this post.

1. Enable MFA!  

We may sound like a broken record, but this tip is our number one priority. Simon recommends checking out our colleague Joe’s blog for more on this. The importance of MFA – why you really need to have it set up in 2022 (teamvalue.com).

2. Use PIM for roles that can create resources

By default, your user settings should hopefully be set to ‘reader/user’. Through PIM (Privileged Identity Management), you can assign various ‘contributor’ or ‘super admin’ roles via the Azure portal. Marco also referred to this in his article, highlighting how important this setting is for your secure score > Why monitoring your secure score should be part of your security management (teamvalue.com). For simple adjustments, you can create a resource yourself without needing approval. However, this changes when it comes to a production environment, where you will need an extra approval for the audit trail. PIM is a key part of security policy, the Zero Trust principle, and Just-in-Time access. Apply this tip, and your user management will no longer be a chaotic mess.  

3. Configure your Azure policies correctly and avoid creating unnecessary VMs

What do we mean by this? If your business doesn't use graphics or Machine Learning, you don't need VMs with GPUs (graphics processing units). You can easily set policies to prevent the unnecessary creation of these VMs. This means your team's permissions are configured more precisely. As an organization, you define your own allowed resource rules. For example, do you allow resources from Brazil or China? Do you only host your app services and storage accounts within Europe? We call these the ‘game rules’ for your Azure environment. What has your organization already implemented to prevent hacking? Reduce your risks!

4. Enable anomaly detection and budgeting within your Azure environment

It’s easy to set up and, according to Simon, a real lifesaver. Why? If you do get hacked, you won't lose a massive amount of money. With anomaly detection, you can set a maximum budget in Azure. Anyone who follows all the steps above, including this tip, is 99.99% safe.  

The 4 tips above are for your Azure tenant and subscriptions. In the new year, we will create an advanced version focused on enterprise-level engineering, where you can read more about Azure Blueprints, network architecture, managed devices, add extensions, and the Modern Workplace.

Scanpakket: Azure cost compass

Vol = vol
1 juli t/m 30 september
Handig informatie

Frequently asked questions (FAQ)

No items found.

Fancy a chat?

Do you have a question, or would you like to know what we can do for your organization? Feel free to get in touch with us. We’re happy to help!