Azure Infrastructure Security Hardening

Job ID: 39999819

Budget: ₹1,500 – ₹12,500 INR

we run a mid-sized SaaS platform built with a .NET back end and an Angular front end. Everything lives in Azure—App Services, SQL, Key Vault, plus one legacy VM—and I want to be certain that the whole stack meets modern security expectations at both the network and application layers.

What I need
• A thorough review of the current Azure environment, including VNets, NSGs, Azure Firewall/WAF rules, identity configuration, and the VM.
• Implementation (or tuning) of Microsoft Defender for Cloud, Azure Monitor, Log Analytics, and, if appropriate, Microsoft Sentinel so that access, error, and audit logs are captured, retained, and easy to query.
• Policies and automated actions that lock an account after repeated failed attempts; alerts can follow, but the lockout must be automatic.
• Written standard operating procedures that future team members can follow for incident response, patch management, and new-resource onboarding.
• A final verification step—PenTest or Security Center score improvement—showing the hardening is effective.

Acceptance criteria
1. All access, error, and audit logs flow into a single Log Analytics workspace with a minimum 90-day retention period.
2. Five consecutive failed sign-in attempts trigger an account lock across the app and Azure AD.
3. CIS or Microsoft Benchmark score rises to the “Healthy” band across compute, data, and networking resources.
4. Documentation (SOP + runbooks) is clear enough for a new hire to follow unassisted.

If you have hands-on experience hardening .NET/Angular workloads in Azure using the tools above, I’d like to see how you can make our environment bullet-proof for the long haul.