{"id":3228,"date":"2020-06-22T14:28:21","date_gmt":"2020-06-22T14:28:21","guid":{"rendered":"https:\/\/davidpapkin.net\/?p=3228"},"modified":"2020-06-22T14:28:21","modified_gmt":"2020-06-22T14:28:21","slug":"integrate-azure-security-center-with-windows-admin-center","status":"publish","type":"post","link":"https:\/\/davidpapkin.com\/?p=3228","title":{"rendered":"Integrate Azure Security Center with Windows Admin Center"},"content":{"rendered":"<p>This David Papkin post is about \u00a0onboarding a server from Microsoft Windows Admin Center to Azure Security Center.<\/p>\n<p>This post is taken from <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/windows-admin-center-integration\">https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/windows-admin-center-integration<\/a><\/p>\n<p>Windows Admin Center is a management tool for your Windows servers. It&#8217;s a single location for system administrators to access the majority of the most commonly used admin tools. From within Windows Admin Center, you can directly onboard your on-prem servers into Azure Security Center. You can then view a summary of your security recommendations and alerts directly in the Windows Admin Center experience.<\/p>\n<p>Note<\/p>\n<p>Your Azure subscription and the associated Log Analytics workspace both need to have Security Center&#8217;s standard tier enabled in order to enable the Windows Admin Center integration. The standard tier is free for the first 30 days if you haven&#8217;t previously used it on the subscription and workspace. For more information, see the <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/security-center-pricing\">pricing information page<\/a>.<\/p>\n<p>When you&#8217;ve successfully onboarded a server from Windows Admin Center to Azure Security Center, you can:<\/p>\n<ul>\n<li>View security alerts and recommendations inside the Security Center extension in Windows Admin Center<\/li>\n<li>View the security posture and retrieve additional detailed information of your Windows Admin Center managed servers in Security Center within the Azure portal (or via an API)<\/li>\n<\/ul>\n<p>By combining these two tools, Security Center becomes your single pane of glass to view all your security information, whatever the resource: protecting your Windows Admin Center managed on-prem servers, your VMs, and any additional PaaS workloads.<\/p>\n<p><strong>Onboarding Windows Admin Center managed servers into Security Center<\/strong><\/p>\n<p>From Windows Admin Center, select one of your servers, and in the Tools pane, select the Azure Security Center extension:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/media\/windows-admin-center-integration\/onboarding-from-wac.png\" \/><\/p>\n<p>Note<\/p>\n<p>If the server is already onboarded to Security Center, the set-up window will not appear.<\/p>\n<p>Click Sign in to Azure and set up.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/media\/windows-admin-center-integration\/onboarding-from-wac-welcome.png\" \/><\/p>\n<p>Follow the instructions to connect your server to Security Center. After you&#8217;ve entered the necessary details and confirmed, Security Center makes the necessary configuration changes to ensure that all of the following are true:<\/p>\n<p>An Azure Gateway is registered.<br \/>\nThe server has a workspace to report to and an associated subscription.<br \/>\nSecurity Center&#8217;s standard tier Log Analytics solution is enabled on the workspace. This solution provides Security Center&#8217;s Standard tier features for all servers and virtual machines reporting to this workspace.<br \/>\nSecurity Center&#8217;s standard tier pricing for Virtual Machine is enabled on the subscription.<br \/>\nThe Log Analytics agent is installed on the server and configured to report to the selected workspace. If the server already reports to another workspace, it&#8217;s configured to report to the newly selected workspace as well.<br \/>\nNote<\/p>\n<p>It may take some time after onboarding for recommendations to appear. In fact, depending on on your server activity you may not receive any alerts. To generate test alerts to test your alerts are working correctly, follow the instructions in the alert validation procedure.<\/p>\n<p>Viewing security recommendations and alerts in Windows Admin Center<br \/>\nOnce onboarded, you can view your alerts and recommendations directly in the Azure Security Center area of Windows Admin Center. Click a recommendation or an alert to view them in the Azure portal. There, you&#8217;ll get additional information and learn how to remediate issues.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/media\/windows-admin-center-integration\/asc-recommendations-and-alerts-in-wac.png\" \/><\/p>\n<p><strong>Viewing security recommendations and alerts for Windows Admin Center managed servers in Security Center<\/strong><br \/>\nFrom Azure Security Center:<\/p>\n<p>To view security recommendations for all your Windows Admin Center servers, open Compute &amp; Apps and click the VMs and Computers tab. Filter the list by resource &#8220;Server&#8221; as shown here:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/media\/windows-admin-center-integration\/viewing-recommendations-wac.png\" \/><\/p>\n<p>To view security alerts for all your Windows Admin Center servers, open Security alerts. Click Filter and ensure only &#8220;Non-Azure&#8221; is selected:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/media\/windows-admin-center-integration\/filtering-alerts-to-non-azure.png\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/media\/windows-admin-center-integration\/viewing-alerts-wac.png\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>*********<\/p>\n<p>Integrate Azure Security Center with Windows Admin Center<br \/>\n11\/04\/2019<br \/>\n2 minutes to read<\/p>\n<p>Windows Admin Center is a management tool for your Windows servers. It&#8217;s a single location for system administrators to access the majority of the most commonly used admin tools. From within Windows Admin Center, you can directly onboard your on-prem servers into Azure Security Center. You can then view a summary of your security recommendations and alerts directly in the Windows Admin Center experience.<\/p>\n<p>Note<\/p>\n<p>Your Azure subscription and the associated Log Analytics workspace both need to have Security Center&#8217;s standard tier enabled in order to enable the Windows Admin Center integration. The standard tier is free for the first 30 days if you haven&#8217;t previously used it on the subscription and workspace. For more information, see the pricing information page.<\/p>\n<p>When you&#8217;ve successfully onboarded a server from Windows Admin Center to Azure Security Center, you can:<\/p>\n<p>View security alerts and recommendations inside the Security Center extension in Windows Admin Center<br \/>\nView the security posture and retrieve additional detailed information of your Windows Admin Center managed servers in Security Center within the Azure portal (or via an API)<br \/>\nBy combining these two tools, Security Center becomes your single pane of glass to view all your security information, whatever the resource: protecting your Windows Admin Center managed on-prem servers, your VMs, and any additional PaaS workloads.<\/p>\n<p>Onboarding Windows Admin Center managed servers into Security Center<br \/>\nFrom Windows Admin Center, select one of your servers, and in the Tools pane, select the Azure Security Center extension:<\/p>\n<p>Note<\/p>\n<p>If the server is already onboarded to Security Center, the set-up window will not appear.<\/p>\n<p>Click Sign in to Azure and set up.<\/p>\n<p>Follow the instructions to connect your server to Security Center. After you&#8217;ve entered the necessary details and confirmed, Security Center makes the necessary configuration changes to ensure that all of the following are true:<\/p>\n<p>An Azure Gateway is registered.<br \/>\nThe server has a workspace to report to and an associated subscription.<br \/>\nSecurity Center&#8217;s standard tier Log Analytics solution is enabled on the workspace. This solution provides Security Center&#8217;s Standard tier features for all servers and virtual machines reporting to this workspace.<br \/>\nSecurity Center&#8217;s standard tier pricing for Virtual Machine is enabled on the subscription.<br \/>\nThe Log Analytics agent is installed on the server and configured to report to the selected workspace. If the server already reports to another workspace, it&#8217;s configured to report to the newly selected workspace as well.<br \/>\nNote<\/p>\n<p>It may take some time after onboarding for recommendations to appear. In fact, depending on on your server activity you may not receive any alerts. To generate test alerts to test your alerts are working correctly, follow the instructions in the alert validation procedure.<\/p>\n<p>Viewing security recommendations and alerts in Windows Admin Center<br \/>\nOnce onboarded, you can view your alerts and recommendations directly in the Azure Security Center area of Windows Admin Center. Click a recommendation or an alert to view them in the Azure portal. There, you&#8217;ll get additional information and learn how to remediate issues.<\/p>\n<p>Viewing security recommendations and alerts for Windows Admin Center managed servers in Security Center<br \/>\nFrom Azure Security Center:<\/p>\n<p>To view security recommendations for all your Windows Admin Center servers, open Compute &amp; Apps and click the VMs and Computers tab. Filter the list by resource &#8220;Server&#8221; as shown here:<\/p>\n<p>To view security alerts for all your Windows Admin Center servers, open Security alerts. Click Filter and ensure only &#8220;Non-Azure&#8221; is selected:<\/p>\n<p>End of David Papkin post about \u00a0onboarding a server from Microsoft Windows Admin Center to Azure Security Center.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This David Papkin post is about \u00a0onboarding a server from Microsoft Windows Admin Center to Azure Security Center. This post is taken from https:\/\/docs.microsoft.com\/en-us\/azure\/security-center\/windows-admin-center-integration Windows Admin Center is a management tool for your Windows servers. It&#8217;s a single location for&hellip; <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24,8,21],"tags":[48,70,108],"class_list":["post-3228","post","type-post","status-publish","format-standard","hentry","category-azure","category-microsoft","category-windows-microsoft","tag-azure","tag-davidpapkin","tag-microsoft"],"_links":{"self":[{"href":"https:\/\/davidpapkin.com\/index.php?rest_route=\/wp\/v2\/posts\/3228","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/davidpapkin.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/davidpapkin.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/davidpapkin.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/davidpapkin.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3228"}],"version-history":[{"count":0,"href":"https:\/\/davidpapkin.com\/index.php?rest_route=\/wp\/v2\/posts\/3228\/revisions"}],"wp:attachment":[{"href":"https:\/\/davidpapkin.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/davidpapkin.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/davidpapkin.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}