Leveraging Azure Monitor and Log Analytics for Operations
摘要
In the previous chapter, we learned how Microsoft Defender for Cloud empowers organizations with threat protection, posture management, and security automation. We learned how to detect, investigate, and respond to threats using tools like Secure Score, Threat Intelligence Reports, security recommendations, and Defender playbooks. These capabilities form the reactive and proactive foundation of a secure cloud environment. However, robust cloud governance and operational resilience require more than threat defense—they demand continuous visibility into system performance, availability, and user activity.