Microsoft Azure Arc enables you to manage your entire environment, with a single pane of glass, by projecting your existing resources into Azure Resource Manager. You can now manage virtual machines, Kubernetes clusters, and databases as if they are running in Azure. Regardless of where they live, you can use familiar Azure services and management capabilities. Azure Arc enables you to continue using traditional ITOps, while introducing DevOps practices to support new cloud native patterns in your environment.
IT Management with Azure ARC
With Microsoft Windows Admin Center I Build a Microsoft Azure Stack HCI Cluster and the Nodes are connected with Azure Arc Services. In the following steps you will see a security feature of Microsoft Azure Arc Services with remediation of the Risks on the Azure Stack HCI Cluster On-premises.
Azure Arc Security Remediation
Here you see the Azure Arc Servers with Azure Stack HCI
On Skywalker01 Node we have two Security Risks
When you click on the risk, you see the description and the remediation steps to solve this risk issue. Here you can also see the remediation script:
Automatic Remediation Script.
Select the Azure workspace ID and when you don’t have one you can Create new Workspace in Azure.
Select the resource, in my case Skywalker01
Click on remediate resource.
Remediation in progress
The Microsoft Azure Monitor Agent extension in Azure Arc is successfully installed.
I did the same for Skywalker02 Azure Stack HCI Cluster Node.
The Next Medium Risk is a Vulnerability assessment on the Azure Stack HCI Cluster nodes. Just follow the steps of the wizard.
Azure Arc Security Vulnerability Assessment with Azure Defender
Click on remediate.
This one will use Qualys in Azure Defender.
Click on remediate resource.
The vulnerability scanner included with Azure Security Center is powered by Qualys. Qualys’ scanner is one of the leading tools for real-time identification of vulnerabilities. It’s only available with Azure Defender for servers. You don’t need a Qualys license or even a Qualys account – everything’s handled seamlessly inside Security Center.
Here you find more information about Azure Defender’s integrated vulnerability assessment solution for Azure and hybrid machines
Azure Arc Insights Monitor
Azure Arc Insights of the Azure Stack HCI Cluster Node
Because we have installed the Microsoft Azure Monitor extension in Azure Arc on this Azure Stack HCI Node Server, telemetry and analytics will do his job for Monitoring in Azure and data will be collected. In Azure maps you see the connectivity of the Server.
Here you can see the Fired Alerts by severity and Investigate 🙂
You can monitor the Traffic
Here you see the power of Hybrid IT management via Microsoft Azure Arc services and get Azure Cloud services for your On-premises Servers. You have the Free Microsoft Windows Admin Center Tool and integration with Azure Arc for all the innovative tools like Azure Monitor, Azure Security Center, Azure Defender, Update management and more. I hope you see the benefits too, Get started Today !