
Best practices to prevent hacking
Azure cost compass
op onze IT-scans
Simon Deeb, one of our cloud colleagues, attended Microsoft’s App Innovation Event at the end of November. A clear message quickly emerged: enable MFA on all accounts with Azure Subscription permissions! Why? Hackers are actively targeting poorly secured Azure subscriptions, spinning up as many virtual machines (VMs) as possible to use for crypto mining. This urgent warning was shared by Tony Krijnen, Cloud Solutions Architect for Security & Compliance. See also this post.
1. Enable MFA!
We may sound like a broken record, but this tip is our number one priority. Simon recommends checking out our colleague Joe’s blog for more on this. The importance of MFA – why you really need to have it set up in 2022 (teamvalue.com).
2. Use PIM for roles that can create resources
By default, your user settings should hopefully be set to ‘reader/user’. Through PIM (Privileged Identity Management), you can assign various ‘contributor’ or ‘super admin’ roles via the Azure portal. Marco also referred to this in his article, highlighting how important this setting is for your secure score > Why monitoring your secure score should be part of your security management (teamvalue.com). For simple adjustments, you can create a resource yourself without needing approval. However, this changes when it comes to a production environment, where you will need an extra approval for the audit trail. PIM is a key part of security policy, the Zero Trust principle, and Just-in-Time access. Apply this tip, and your user management will no longer be a chaotic mess.
3. Configure your Azure policies correctly and avoid creating unnecessary VMs
What do we mean by this? If your business doesn't use graphics or Machine Learning, you don't need VMs with GPUs (graphics processing units). You can easily set policies to prevent the unnecessary creation of these VMs. This means your team's permissions are configured more precisely. As an organization, you define your own allowed resource rules. For example, do you allow resources from Brazil or China? Do you only host your app services and storage accounts within Europe? We call these the ‘game rules’ for your Azure environment. What has your organization already implemented to prevent hacking? Reduce your risks!
4. Enable anomaly detection and budgeting within your Azure environment
It’s easy to set up and, according to Simon, a real lifesaver. Why? If you do get hacked, you won't lose a massive amount of money. With anomaly detection, you can set a maximum budget in Azure. Anyone who follows all the steps above, including this tip, is 99.99% safe.
The 4 tips above are for your Azure tenant and subscriptions. In the new year, we will create an advanced version focused on enterprise-level engineering, where you can read more about Azure Blueprints, network architecture, managed devices, add extensions, and the Modern Workplace.
Scanpakket: Azure cost compass
1 juli t/m 30 september
Frequently asked questions (FAQ)
Fancy a chat?
Do you have a question, or would you like to know what we can do for your organization? Feel free to get in touch with us. We’re happy to help!

