Implement Defense in Depth on Azure
Pluralsight Hands-On Lab — Security
At a Glance
| Platform | Pluralsight |
| Category | Azure Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Windows VM via Remote Desktop |
| Completed | 2026 |
Overview
Defense in depth is a layered security strategy where multiple protection measures are applied across every tier of a workload — so that if one layer is breached, additional controls are already in place to contain the threat. In this lab, I was given a scenario as a cybersecurity engineer at a managed service provider, tasked with securing a customer-facing web application and SQL database for a fictional client. I applied security controls at each layer of the defense in depth model: perimeter, network, identity and access, compute, application, and data.
Security Layers Implemented
Perimeter
- Deployed Azure Firewall (Basic SKU, policy-based) with dedicated AzureFirewallSubnet and AzureFirewallManagementSubnet
- Created a route table (rt-01) with a default route directing all traffic through the firewall as a virtual appliance
- Configured DNAT rule collections to forward HTTP and HTTPS traffic from the firewall public IP to the web server
- Updated firewall rules to forward HTTPS (port 443) after binding a TLS certificate
Network
- Created dedicated subnets: data-subnet for Azure SQL, keyvault-subnet for Key Vault
- Deployed a Private Endpoint (pe-sql) for the Azure SQL Server and disabled its public endpoint
- Created a Private Endpoint for Key Vault and disabled public access
- Deployed Azure Bastion for secure RDP access without a public IP on the VM
- Dissociated and deleted the VM's public IP address after Bastion was in place
Identity and Access
- Enabled a system-assigned managed identity on the web server VM
- Enforced Microsoft Entra ID-only authentication on the Azure SQL Server
- Created a database-contained user for the VM's managed identity and granted db_datareader and db_datawriter roles
- Updated the web application connection string to use Entra ID passwordless authentication
Compute
- Configured Azure Update Manager with a customer-managed schedule for weekly automatic patching on the web server
- Deployed Azure Disk Encryption using a Key Vault-stored key (4096-bit RSA) for OS and data disks
Application
- Generated a self-signed TLS certificate in Key Vault and bound it to the IIS web application on port 443
- Used PowerShell and Azure VM Run Command to automate certificate binding to IIS without direct VM access
Data
- Deployed Azure Key Vault with a private endpoint for secure secret and key management
- Configured Dynamic Data Masking on the SQL database to mask the CreditCardNumber column
Security Operations
- Deployed a Log Analytics workspace (log-sentinel) and Microsoft Sentinel
- Created a Data Collection Rule to capture IIS logs from the web server
- Installed the Web Session Essentials solution from the Sentinel Content Hub
- Enabled an analytics rule to detect a single source using multiple user agents
← Back to Pluralsight Labs