Instiq
Chapter 4 · Infrastructure security·v1.0.0·Updated 6/28/2026·~14 min

What's changed: Created SC-100 Chapter 4 (Domain 3 "Infrastructure security": Defender for Cloud (CSPM/CWPP)/Secure Score/MCSB/Azure Arc/multicloud posture; Security Exposure Management (attack paths/attack-surface reduction/initiatives)/Defender EASM; servers/endpoints (baselines/Defender for Endpoint/Intune/Windows LAPS)/OT-ICS-IoT (Defender for IoT)/containers (Defender for Containers)/Azure AI services security; network (microsegmentation/Private Link/Azure Bastion)/SSE (Entra Internet Access/Entra Private Access/Global Secure Access)).

4.3Securing servers, endpoints, and OT/IoT

Key points

Understand securing servers/client endpoints (multi-OS, mobile, baselines, Windows LAPS), IoT/embedded and OT/ICS (Microsoft Defender for IoT), and security requirements for SaaS/PaaS/IaaS (containers, container orchestration, Azure AI services security).

The "substrate" running workloads—servers, devices, IoT/OT, containers, and AI services—each have security requirements matched to their threats. Architects choose appropriate baselines and products per target rather than one-size-fits-all.

4.3.1Servers/clients and baselines

For servers and clients (multi-OS, including mobile), define security baselines (hardening reference configurations), provide endpoint protection (EDR) with Microsoft Defender for Endpoint, and manage device configuration/compliance with Microsoft Intune. Reused local admin passwords breed lateral movement, so use Windows LAPS (Local Administrator Password Solution) to auto-rotate/store a unique password per device. Architects specify LAPS for "auto-manage a different admin password per device."

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.