Skip to main content
AzureProof Docs
  • Quick start
  • Connecting your Azure tenant
  • Understanding your score
  • Your first audit
  • How SOC2 evidence works
  • Control categories explained
  • Pass / Warn / Fail criteria
  • Evidence retention policy
  • Access controls (CC6.x)
  • Threat detection (CC7.x)
  • Change management (CC8.x)
  • Availability (A1.x)
  • Microsoft Graph
  • Defender for Cloud
  • Activity Log
  • Future: AWS, GCP
  • Our security model
  • Permissions we request
  • Data we store (and don't store)
  • Encryption at rest
  • SOC2 status
  • Responsible disclosure
  • Authentication
  • Endpoints
  • Webhooks

25 pages

controls

Threat detection (CC7.x)

Continuous monitoring, alerting, and incident detection controls.

What we check

  • Defender for Cloud enabled on every subscription
  • Defender for Servers Plan 2 on production
  • Alert workflow automations wired to a ticketing system

How to fix

az security pricing create --name VirtualMachines --tier Standard
Previous
Access controls (CC6.x)
Next
Change management (CC8.x)