Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.
4.5. Reflection Checkpoint
Key Takeaways
- Azure's core infrastructure services each protect a different layer: DDoS Protection (volumetric floods), Azure Firewall (centralized L3-L7), WAF (application-layer/OWASP), NSGs (lightweight per-subnet L3/4), Bastion (secure VM access without public IPs), and Key Vault (secrets/keys/certificates).
- CSPM (Defender for Cloud) finds misconfigurations before an attack; cloud workload protection defends running resources during an active threat — they answer different questions.
- Microsoft Sentinel combines SIEM (collect/correlate/detect) and SOAR (automate response via playbooks) in one cloud-native platform, correlating raw signals into investigable incidents.
- Microsoft Defender XDR is a correlation layer unifying Defender for Endpoint, Office 365, Identity, and Cloud Apps into single incidents — not a standalone product.
- Each specialized Defender product protects a distinct surface: Office 365 (email), Endpoint (devices/EDR), Cloud Apps (SaaS/CASB), Identity (on-prem AD), plus Vulnerability Management (exposure) and Threat Intelligence (external context).
- The Microsoft Defender portal is the unified interface where all of the above actually get investigated and acted on.
Connecting Forward
Phase 5 shifts from "protecting the infrastructure and detecting threats" to "protecting and governing the data itself" — Microsoft Purview's compliance, information protection, and investigation capabilities. Notice the same continuous-verification theme from GRC (Phase 2.1.5) reappears here as Compliance Manager and compliance score.
Self-Check Questions
- A company needs to filter traffic based on the destination domain name (FQDN) across many virtual networks centrally. Which service fits, and why wouldn't an NSG alone be sufficient?
- Why does Sentinel's value come specifically from combining SIEM and SOAR, rather than either capability alone?
- An attack touches email, an endpoint, and on-premises AD. Which single layer unifies detection across all three, and what does it actually do with the individual products' signals?
Written byAlvin Varughese
Founder•18 professional certifications