Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

4.5. Reflection Checkpoint

Key Takeaways

  • Azure's core infrastructure services each protect a different layer: DDoS Protection (volumetric floods), Azure Firewall (centralized L3-L7), WAF (application-layer/OWASP), NSGs (lightweight per-subnet L3/4), Bastion (secure VM access without public IPs), and Key Vault (secrets/keys/certificates).
  • CSPM (Defender for Cloud) finds misconfigurations before an attack; cloud workload protection defends running resources during an active threat — they answer different questions.
  • Microsoft Sentinel combines SIEM (collect/correlate/detect) and SOAR (automate response via playbooks) in one cloud-native platform, correlating raw signals into investigable incidents.
  • Microsoft Defender XDR is a correlation layer unifying Defender for Endpoint, Office 365, Identity, and Cloud Apps into single incidents — not a standalone product.
  • Each specialized Defender product protects a distinct surface: Office 365 (email), Endpoint (devices/EDR), Cloud Apps (SaaS/CASB), Identity (on-prem AD), plus Vulnerability Management (exposure) and Threat Intelligence (external context).
  • The Microsoft Defender portal is the unified interface where all of the above actually get investigated and acted on.

Connecting Forward

Phase 5 shifts from "protecting the infrastructure and detecting threats" to "protecting and governing the data itself" — Microsoft Purview's compliance, information protection, and investigation capabilities. Notice the same continuous-verification theme from GRC (Phase 2.1.5) reappears here as Compliance Manager and compliance score.

Self-Check Questions

  • A company needs to filter traffic based on the destination domain name (FQDN) across many virtual networks centrally. Which service fits, and why wouldn't an NSG alone be sufficient?
  • Why does Sentinel's value come specifically from combining SIEM and SOAR, rather than either capability alone?
  • An attack touches email, an endpoint, and on-premises AD. Which single layer unifies detection across all three, and what does it actually do with the individual products' signals?
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications