Lab 24 – Cloud Compliance & Audit Automation
Automate cloud‑compliance monitoring, audit reporting, and security posture management using Azure Monitor, Defender for Cloud, and Log Analytics.
Objective Lab goal
This lab focuses on automating compliance and audit workflows in Azure. You’ll configure Defender for Cloud recommendations, build compliance dashboards, automate audit exports, and integrate alerts into your SIEM.
- Outcome 1: Defender for Cloud recommendations reviewed and automated.
- Outcome 2: Compliance dashboards created in Azure Monitor.
- Outcome 3: Audit logs exported automatically.
- Outcome 4: SIEM integration validated for compliance alerts.
Lab 24: Automating cloud‑compliance monitoring and audit reporting.
Deliverables End‑of‑lab checklist
- DL24.1: Defender for Cloud recommendations reviewed and remediated.
- DL24.2: Compliance dashboard created.
- DL24.3: Automated audit‑log export configured.
- DL24.4: SIEM integration validated.
- DL24.5: Documentation updated with screenshots and findings.
Lab Steps Step‑by‑step instructions
Step 1 – Review Defender for Cloud Recommendations
~45 minutes- Navigate to Defender for Cloud → Recommendations.
- Review:
- Secure Score
- Identity & Access recommendations
- Data & Storage recommendations
- Remediate or document exceptions.
Step 2 – Build Compliance Dashboard
~45 minutes- Open Azure Monitor → Workbooks.
- Create a new workbook with:
- Secure Score trend
- Policy compliance
- Identity risk events
- Resource‑level compliance
- Save and publish dashboard.
Step 3 – Automate Audit Log Export
~60 minutes- Navigate to Azure AD → Audit Logs.
- Configure export to:
- Log Analytics Workspace
- Storage Account
- Event Hub (optional)
- Validate log ingestion.
Step 4 – Integrate Compliance Alerts with SIEM
~45 minutes- Configure alerts for:
- Non‑compliant resources
- Identity risk events
- Policy violations
- Send alerts to SIEM via:
- Log Analytics
- Event Hub
- Validate alert ingestion and correlation.
Reflection What you should understand now
- Compliance: How Azure enforces and monitors cloud standards.
- Automation: How audit logs and alerts can be exported automatically.
- Visibility: How dashboards reveal posture and risk trends.
With this lab, you’ve completed Month 6 and built a strong foundation in cloud security, identity protection, and compliance automation. You’re now ready to move into **Month 7 – Threat Intelligence & Automation**.