Lab 03 — Azure Virtual Machine Security Assessment
Mission Information
Section titled “Mission Information”Objective
Section titled “Objective”Assess Microsoft Azure Virtual Machines from a cloud penetration tester’s perspective by identifying security weaknesses, validating security controls, and documenting findings in an enterprise-style assessment.
Difficulty
Section titled “Difficulty”Intermediate
Estimated Time
Section titled “Estimated Time”90–120 Minutes
Career Alignment
Section titled “Career Alignment”- Cloud Penetration Tester
- Cloud Security Engineer
- Security Consultant
- Red Team Operator
Business Scenario
Section titled “Business Scenario”You are working as a Cloud Penetration Tester at CloudNova Technologies.
A customer has requested a security assessment of their Azure Virtual Machine environment before migrating critical business applications into production.
Your engagement focuses on reviewing Azure VM deployments, configuration, networking, identity integration, and management settings to identify weaknesses that could increase risk.
The assessment is conducted with written authorization and follows the agreed Rules of Engagement.
Learning Objectives
Section titled “Learning Objectives”By completing this lab you will be able to:
- Review Azure Virtual Machine configurations.
- Assess VM deployment architecture.
- Evaluate authentication and identity configuration.
- Review network exposure.
- Assess storage and disk protection.
- Review management access controls.
- Validate monitoring and logging configuration.
- Produce professional assessment documentation.
Prerequisites
Section titled “Prerequisites”Students should complete:
- Module 01 — Azure Offensive Security Foundations
- Lesson 02 — Microsoft Azure Architecture
- Lesson 03 — Microsoft Entra ID Fundamentals
- Lesson 04 — Azure Resource Manager
- Lesson 05 — Azure Networking Fundamentals
Lab Environment
Section titled “Lab Environment”Azure Resources
Section titled “Azure Resources”- Azure Subscription
- Resource Group
- Azure Virtual Machine
- Virtual Network
- Network Security Group
- Azure Bastion (optional)
- Microsoft Entra ID
- Azure Monitor
Assessment Scope
Section titled “Assessment Scope”The assessment includes reviewing:
- Azure VM configuration
- Operating system selection
- Identity integration
- Network configuration
- Storage configuration
- Encryption settings
- Monitoring
- Backup configuration
- Administrative access
- Security hardening
Lab Tasks
Section titled “Lab Tasks”Task 01 — Review the Azure VM Deployment
Section titled “Task 01 — Review the Azure VM Deployment”Review:
- Resource Group
- Region
- VM Size
- Availability configuration
- Tags
- Naming standards
Document observations.
Task 02 — Assess Identity Configuration
Section titled “Task 02 — Assess Identity Configuration”Review:
- Microsoft Entra ID integration
- Administrative accounts
- Managed Identity configuration
- Role assignments
- Least privilege implementation
Document any security observations.
Task 03 — Review Network Configuration
Section titled “Task 03 — Review Network Configuration”Review:
- Virtual Network
- Subnet placement
- Network Security Groups
- Public IP assignment
- Private IP configuration
- Inbound management access
- Outbound connectivity
Record the attack surface identified during the review.
Task 04 — Review Storage Configuration
Section titled “Task 04 — Review Storage Configuration”Review:
- OS Disk
- Data Disks
- Disk encryption
- Snapshot configuration
- Backup configuration
Document the current protection mechanisms.
Task 05 — Review Security Controls
Section titled “Task 05 — Review Security Controls”Assess whether the VM is configured with:
- Microsoft Defender for Cloud recommendations
- Automatic updates
- Endpoint protection
- Secure Boot (where applicable)
- Trusted Launch features
- Just-In-Time (JIT) VM Access (where applicable)
Record any deviations from organisational standards.
Task 06 — Review Monitoring
Section titled “Task 06 — Review Monitoring”Verify the availability of:
- Azure Monitor
- Activity Logs
- Diagnostic Logs
- VM Insights
- Alerting configuration
Document monitoring coverage.
Task 07 — Risk Assessment
Section titled “Task 07 — Risk Assessment”Classify each finding according to organisational risk ratings:
- Critical
- High
- Medium
- Low
- Informational
Provide justification for each rating.
Task 08 — Executive Summary
Section titled “Task 08 — Executive Summary”Prepare an executive summary including:
- Scope
- Methodology
- Key observations
- Business impact
- Recommended remediation priorities
Expected Deliverables
Section titled “Expected Deliverables”At the end of this lab you should have:
- Azure VM assessment notes
- Security observations
- Identified risks
- Supporting evidence
- Executive summary
- Technical findings
- Remediation recommendations
Validation Checklist
Section titled “Validation Checklist”You should be able to explain:
- Azure VM deployment architecture
- Administrative access model
- Identity integration
- Network exposure
- Storage protection
- Monitoring configuration
- Overall security posture
Real-World Skills Developed
Section titled “Real-World Skills Developed”After completing this lab you will have practical experience in:
- Azure Virtual Machine assessments
- Cloud infrastructure reviews
- Azure security validation
- Enterprise documentation
- Technical reporting
- Risk assessment
- Cloud consulting methodology
Lab Summary
Section titled “Lab Summary”Congratulations!
You have completed an enterprise-style Azure Virtual Machine security assessment using the GoHackersCloud cloud penetration testing methodology.
The skills developed in this lab closely mirror activities performed during authorised cloud security reviews and penetration testing engagements.
Next Lab
Section titled “Next Lab”➡️ Lab 04 — Azure Privilege Escalation Assessment
In the next lab, you will assess Azure identity and permission configurations to identify opportunities for privilege escalation and validate least-privilege implementation within an authorised enterprise environment.