Instiq
Chapter 4 · Infrastructure security·v1.0.0·Updated 6/28/2026·~14 min

What's changed: Created SC-100 Chapter 4 (Domain 3 "Infrastructure security": Defender for Cloud (CSPM/CWPP)/Secure Score/MCSB/Azure Arc/multicloud posture; Security Exposure Management (attack paths/attack-surface reduction/initiatives)/Defender EASM; servers/endpoints (baselines/Defender for Endpoint/Intune/Windows LAPS)/OT-ICS-IoT (Defender for IoT)/containers (Defender for Containers)/Azure AI services security; network (microsegmentation/Private Link/Azure Bastion)/SSE (Entra Internet Access/Entra Private Access/Global Secure Access)).

4.3Securing servers, endpoints, and OT/IoT

Key points

Understand securing servers/client endpoints (multi-OS, mobile, baselines, Windows LAPS), IoT/embedded and OT/ICS (Microsoft Defender for IoT), and security requirements for SaaS/PaaS/IaaS (containers, container orchestration, Azure AI services security).

The "substrate" running workloads—servers, devices, IoT/OT, containers, and AI services—each have security requirements matched to their threats. Architects choose appropriate baselines and products per target rather than one-size-fits-all.

4.3.1Servers/clients and baselines

For servers and clients (multi-OS, including mobile), define security baselines (hardening reference configurations), provide endpoint protection (EDR) with Microsoft Defender for Endpoint, and manage device configuration/compliance with Microsoft Intune. Reused local admin passwords breed lateral movement, so use Windows LAPS (Local Administrator Password Solution) to auto-rotate/store a unique password per device. Architects specify LAPS for "auto-manage a different admin password per device."

4.3.2OT/ICS/IoT and containers/AI services

Factory/infrastructure OT/ICS (industrial control systems) and IoT/embedded often cannot host traditional agents, so use Microsoft Defender for IoT to agentlessly visualize the network and detect anomalies (aligned to MITRE ATT&CK for ICS). For cloud containers and orchestration (Kubernetes), apply image scanning, runtime protection, and least-privilege settings via Defender for Containers. For Azure AI services, design requirements for key/endpoint protection, network restriction, and content safety.

Exam point

Cues: "auto-rotate a unique local admin password per device" = Windows LAPS. "agentlessly visualize/detect OT/ICS/IoT" = Defender for IoT. "endpoint EDR" = Defender for Endpoint; "device config/compliance" = Intune. "container/Kubernetes protection" = Defender for Containers.

Warning

Watch the mix-ups: (1) Defender for Endpoint (EDR) and Intune (device management/compliance) have different roles—use together. (2) Do not assume standard server agents for OT/ICS (use Defender for IoT agentless). (3) LAPS manages "device-local admin"—a different layer from Entra role privileges (PIM).

Diagram of baselines + Defender for Endpoint (EDR) + Intune (config/compliance) + Windows LAPS, OT/ICS/IoT via agentless Defender for IoT, containers via Defender for Containers, and Azure AI services security.
Optimize per target

4.3.3Section summary

  • Servers/devices = baselines + Defender for Endpoint (EDR) + Intune (config/compliance); local admin via Windows LAPS auto-rotation
  • OT/ICS/IoT = Defender for IoT agentless visualization/detection (aligned to ATT&CK for ICS)
  • Containers/Kubernetes = Defender for Containers; design Azure AI services key/network/content-safety requirements

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To avoid reusing local admin passwords and auto-rotate/securely store a unique one per device, which is best?

Q2. You cannot install standard agents on factory OT/ICS. Which is best for threat visualization/detection?

Q3. To apply image scanning and runtime protection to containers on Kubernetes, which is best?

Q4. Which correctly splits roles between endpoint EDR (detection/response) and device configuration/compliance management?

Q5. Which is the most appropriate security requirement for Azure AI services?

Check your understandingPractice questions for Chapter 4: Infrastructure security

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.