This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
--> Implement security for servers and virtual machines (VMs)
--> Enforce security configuration of Azure-managed servers by using Azure Machine Configuration
Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.
Overview
Azure Machine Configuration is an Azure governance capability that allows organizations to audit and enforce operating-system settings as code on Azure virtual machines and Azure Arc-enabled servers.
It extends Azure Policy beyond the configuration of Azure resources and into the guest operating system. This makes it possible to establish consistent security baselines, identify machines that do not comply with those baselines, and—when appropriate—automatically correct noncompliant settings.
Azure Machine Configuration is especially useful when an organization manages a large number of Windows and Linux servers across Azure, on-premises environments, other cloud providers, or edge locations.
Why Azure Machine Configuration Is Important
Traditional Azure Policy evaluates many aspects of Azure resources, such as:
- Whether a virtual machine uses a particular operating system
- Whether a resource has required tags
- Whether a storage account allows public access
- Whether a virtual machine uses a supported security configuration
However, many important security settings exist inside the guest operating system, including:
- Password and account policies
- Windows security options
- Linux configuration files
- Services that must be enabled or disabled
- Required applications or packages
- File permissions
- Audit settings
- Operating-system security baseline settings
- Organization-specific configuration requirements
Azure Machine Configuration allows these settings to be represented as machine configuration assignments and evaluated through Azure Policy.
This provides a consistent process to:
- Define the desired configuration.
- Assign the configuration to a scope.
- Evaluate machines against the configuration.
- Report compliance or noncompliance.
- Correct configuration drift when enforcement is enabled.
Azure Machine Configuration and Azure Policy
Azure Machine Configuration works closely with Azure Policy.
Azure Policy determines:
- Which machines are in scope
- Which configuration should be evaluated
- Whether the configuration is audited or enforced
- How compliance is reported
- Whether remediation should be deployed
Azure Machine Configuration evaluates the actual operating-system settings on the machine.
The relationship can be summarized as follows:
| Component | Primary responsibility |
|---|---|
| Azure Policy | Assigns and governs the configuration |
| Machine Configuration | Evaluates or applies guest OS settings |
| Machine Configuration extension | Enables configuration management on Azure VMs |
| Azure Arc Connected Machine agent | Provides the required capability for Arc-enabled servers |
| Managed identity | Allows the Azure VM to authenticate to the machine configuration service |
| Azure Policy Compliance | Displays compliance results |
Azure Machine Configuration policies can be assigned at the management group, subscription, or resource-group level. This supports centralized governance across an entire server estate.
Supported Machine Types
Azure Machine Configuration can be used with:
- Azure virtual machines
- Azure virtual machine scale sets, where supported
- Azure Arc-enabled servers
- Servers running Windows
- Servers running Linux
For Azure VMs, the Machine Configuration extension and a system-assigned managed identity are required.
For Azure Arc-enabled servers, the required functionality is provided through the Azure Connected Machine agent rather than the Azure VM extension.
This allows an organization to use a similar compliance model for:
- Azure-hosted servers
- On-premises servers
- Servers hosted in another cloud
- Edge servers connected through Azure Arc
Required Prerequisites
Before assigning machine configuration policies, verify the following prerequisites.
1. Register the Resource Provider
The Microsoft.GuestConfiguration resource provider must be registered for the subscription.
When machine configuration policies are assigned through the Azure portal—or when the subscription is enrolled in Microsoft Defender for Cloud—the provider may be registered automatically. It can also be registered manually through the Azure portal, Azure PowerShell, or Azure CLI.
2. Deploy the Machine Configuration Extension
Azure virtual machines require the Machine Configuration or Guest Configuration extension.
The extension:
- Downloads applicable machine configuration assignments
- Retrieves configuration dependencies
- Evaluates the guest operating system
- Applies configuration settings when enforcement is enabled
- Reports configuration results
The extension can be deployed individually or at scale by assigning the prerequisite policy initiative:
Deploy prerequisites to enable Guest Configuration policies on virtual machines
The exact policy initiative name may vary slightly as Microsoft updates the service and terminology.
3. Enable a Managed Identity
Azure VMs require a system-assigned managed identity for machine configuration.
The identity allows the VM to authenticate to the machine configuration service without requiring administrators to store credentials on the server.
The prerequisite initiative can automatically create a system-assigned managed identity when one does not already exist.
4. Verify Connectivity
The machine must be able to communicate with the required Azure services.
Network restrictions involving:
- Network security groups
- Azure Firewall
- Proxy servers
- Outbound filtering
- Private networking
- DNS configuration
can prevent the extension from downloading assignments or reporting results.
5. Verify Extension and Agent Versions
For machine configuration packages that apply settings, the Azure VM Guest Configuration extension must meet the supported minimum version. Microsoft currently identifies version 1.26.24 or later for Azure VMs in its custom-policy documentation.
Machine Configuration Enforcement Modes
Azure Machine Configuration supports different ways to manage configuration.
Audit
Audit mode evaluates the machine and reports whether it complies with the desired configuration.
It does not change the machine.
Use Audit mode when:
- Establishing an initial security baseline
- Discovering configuration drift
- Assessing the impact of a new policy
- Testing a configuration before enforcement
- Identifying exceptions
- Preparing for a compliance audit
For example, an audit policy might determine whether Windows servers meet the Azure compute security baseline.
Apply and Monitor
Apply and Monitor applies the configuration and then continues monitoring the machine for changes.
This mode is useful when the organization wants the desired configuration to be established and then monitored for drift.
Apply and AutoCorrect
Apply and AutoCorrect applies the desired configuration and attempts to correct changes that cause the machine to become noncompliant.
This mode is appropriate when a setting must remain consistent and automatic correction is acceptable.
However, automatic correction should be used carefully. Some settings can affect:
- Application compatibility
- Network connectivity
- Authentication
- System startup
- Legacy workloads
- Custom operating-system behavior
Microsoft’s machine configuration tooling supports policy definitions that audit or apply custom configuration packages, including policies generated with the New-GuestConfigurationPolicy PowerShell cmdlet.
Audit First, Enforce Second
A recommended implementation approach is to begin with auditing.
Phase 1: Discover
Identify:
- Which machines are in scope
- Which operating systems are used
- Which applications depend on current settings
- Which machines are production systems
- Which machines are exceptions
- Which security standards must be followed
Phase 2: Audit
Assign the desired baseline in Audit mode.
Review:
- Overall compliance
- Individual noncompliant machines
- Individual failed settings
- Configuration conflicts
- Unsupported systems
- Required exceptions
Phase 3: Remediate
Correct problems manually or through controlled remediation.
For example:
- Update an insecure configuration
- Install a required package
- Disable an unnecessary service
- Correct file permissions
- Change a security option
- Document an approved exception
Phase 4: Enforce
After testing, change the assignment to an enforcement mode.
This reduces the risk that a new configuration will unexpectedly disrupt production workloads.
Built-In Security Baselines
Microsoft provides built-in machine configuration policies for common security requirements.
Examples include:
- Windows machines should meet requirements for the Azure compute security baseline
- Linux machines should meet requirements for the Azure compute security baseline
- Windows machines should use a specified time zone
- Linux machines should have specified applications installed
- Other operating-system configuration policies
Built-in definitions can be discovered in:
Azure portal → Policy → Definitions
Use filters such as:
- Category: Guest Configuration
- Policy type: Built-in
A policy definition can be inspected to review:
- Its purpose
- Supported platforms
- Parameters
- Version
- Policy effect
- Required resources
- Configuration details
Built-in security baseline policies can be assigned to Azure VMs and, where supported, Azure Arc-enabled servers.
Azure Compute Security Baselines
Security baselines provide a recommended collection of operating-system settings intended to improve the security posture of Windows and Linux machines.
They may include requirements related to:
- Account policies
- Authentication
- Audit policies
- Security options
- Network security
- System services
- File permissions
- Operating-system behavior
The baseline should not automatically be treated as a universal configuration for every workload. Organizations should evaluate whether particular settings are compatible with:
- Business applications
- Legacy systems
- Domain controllers
- Specialized appliances
- High-availability systems
- Custom Linux distributions
- Regulatory requirements
- Operational procedures
The current Azure Machine Configuration experience supports customizable security baselines. Administrators can select, exclude, or modify rules and export the resulting settings as a reusable JSON artifact.
Custom Machine Configurations
Built-in policies may not satisfy every organizational requirement.
A custom machine configuration can be used when an organization needs to enforce settings such as:
- A required registry value
- A specific Linux configuration-file value
- A required service state
- A required package or application
- A particular file permission
- A specific security option
- An organization-specific hardening requirement
A custom configuration generally involves the following process:
- Define the desired configuration.
- Create a machine configuration package.
- Test the package.
- Publish the package to an accessible location.
- Create a machine configuration policy definition.
- Assign the policy.
- Review compliance results.
- Remediate or enforce as required.
The configuration package must be accessible to the target machine. When a package is stored in Azure Storage, the appropriate identity and permissions must be configured so that the machine can retrieve it securely.
Custom machine configuration policy definitions commonly use effects such as:
AuditIfNotExistsDeployIfNotExists
The DeployIfNotExists effect can be used to deploy a machine configuration assignment when the required assignment does not exist.
Policy Assignment Scope
A machine configuration policy can be assigned at different scopes.
Management Group
Use a management-group assignment when the configuration should apply across multiple subscriptions.
Subscription
Use a subscription assignment when all or most machines in a subscription should follow the same baseline.
Resource Group
Use a resource-group assignment when the policy should apply to a specific workload or server group.
Exclusions
Exclusions may be necessary for:
- Unsupported operating systems
- Development machines
- Legacy applications
- Specialized servers
- Disaster-recovery systems
- Approved exceptions
Exclusions should be documented and reviewed periodically. An exclusion should not become a permanent way to avoid addressing a known security issue.
Compliance Reporting
After a policy is assigned, compliance information can be reviewed through Azure Policy.
Administrators can identify:
- Compliant machines
- Noncompliant machines
- Machines that have not yet evaluated
- Failed configuration settings
- Policy assignment status
- Remediation status
Machine configuration can also provide per-setting results through the machine’s guest assignments or through the compliance details associated with the Azure Policy assignment.
Compliance reporting is useful for:
- Security operations
- Internal audits
- Regulatory reporting
- Vulnerability remediation
- Configuration-drift management
- Executive security dashboards
Azure Machine Configuration Compared with Other Security Controls
Azure Machine Configuration is not a replacement for every security service.
| Security control | Primary purpose |
|---|---|
| Azure Machine Configuration | Audit and enforce operating-system configuration |
| Azure Policy | Govern Azure resource configuration and policy compliance |
| Microsoft Defender for Cloud | Assess security posture and provide recommendations |
| Microsoft Defender for Servers | Provide server protection, vulnerability assessment, and threat detection capabilities |
| Azure VM disk encryption | Protect data stored on VM disks |
| Just-in-time VM access | Reduce exposure of management ports |
| Azure Bastion | Provide managed remote access without exposing public RDP or SSH ports |
| Azure Update Manager | Manage operating-system updates |
| Microsoft Sentinel | Collect, analyze, and respond to security events |
A secure VM strategy normally combines several of these controls rather than relying on Machine Configuration alone.
Common Implementation Mistakes
Mistake 1: Enforcing Before Auditing
Applying a baseline immediately can cause unexpected application or connectivity issues.
Better approach: Begin with Audit mode, review failures, test remediation, and then enforce.
Mistake 2: Assuming Azure Policy Automatically Changes Guest Settings
Not every Azure Policy definition changes the operating system.
Better approach: Confirm whether the policy audits configuration, deploys a configuration assignment, or applies settings inside the guest OS.
Mistake 3: Forgetting the Extension
An Azure VM may be in policy scope but still be unable to evaluate guest configuration if the required extension is missing.
Better approach: Deploy the machine configuration prerequisites before assigning configuration policies.
Mistake 4: Forgetting Managed Identity
The VM needs an appropriate identity to communicate with the machine configuration service.
Better approach: Verify that the required system-assigned managed identity is enabled.
Mistake 5: Ignoring Network Restrictions
Outbound network controls can prevent configuration downloads and compliance reporting.
Better approach: Verify DNS, outbound connectivity, firewall rules, proxy settings, and required service access.
Mistake 6: Treating Every Baseline Setting as Universally Appropriate
A baseline may contain settings that conflict with a specialized application.
Better approach: Test settings, document exceptions, and customize the baseline when necessary.
Mistake 7: Confusing Configuration Compliance with Threat Detection
Machine Configuration determines whether settings match a desired state. It does not replace endpoint detection and response or malware protection.
Better approach: Combine configuration enforcement with Defender for Cloud, Defender for Servers, patching, network security, and monitoring.
Recommended Implementation Pattern
A practical enterprise implementation can follow this sequence:
- Register
Microsoft.GuestConfiguration. - Identify Azure VMs and Arc-enabled servers.
- Deploy the machine configuration prerequisites.
- Enable required managed identities.
- Select a built-in Windows or Linux security baseline.
- Customize the baseline if necessary.
- Assign the baseline in Audit mode.
- Review compliance results.
- Remediate failed settings.
- Document approved exceptions.
- Test enforcement on a pilot group.
- Enable Apply and Monitor or Apply and AutoCorrect.
- Monitor compliance continuously.
- Review baseline versions and update policies as requirements change.
Exam-Focused Summary
For the SC-500 exam, remember these key points:
- Azure Machine Configuration manages guest operating-system settings.
- Azure Policy provides the assignment and governance framework.
- Azure VMs require the Machine Configuration extension and a managed identity.
- Azure Arc-enabled servers use the Arc Connected Machine agent.
- Machine Configuration supports both Azure and hybrid servers.
- Audit mode reports configuration state without changing the machine.
- Apply and Monitor applies configuration and monitors for drift.
- Apply and AutoCorrect attempts to restore the desired configuration.
- Built-in security baselines are available for Windows and Linux.
- Custom configurations can address organization-specific requirements.
- Audit before enforcing.
- Network connectivity and identity configuration are common troubleshooting areas.
- Machine Configuration is complementary to Defender for Cloud, disk encryption, JIT VM access, and other security controls.
Practice Exam Questions
Question 1
An organization wants to determine whether its Azure Windows VMs comply with a required operating-system security baseline. The organization does not want to change any settings yet.
Which approach should be used?
A. Apply and AutoCorrect
B. Audit mode
C. Azure VM disk encryption
D. Just-in-time VM access
Answer: B
Explanation: Audit mode evaluates the machine and reports compliance without changing the operating system. This is the recommended starting point before enforcing a new baseline.
Question 2
An administrator wants to manage guest operating-system configuration on Azure virtual machines. Which combination is required for Azure VMs?
A. Azure Bastion and a public IP address
B. Microsoft Sentinel and a Log Analytics workspace
C. Defender for Servers and Azure Firewall
D. Machine Configuration extension and a system-assigned managed identity
Answer: D
Explanation: Azure VMs require the Machine Configuration extension and a system-assigned managed identity. The extension evaluates or applies configuration, while the identity allows the VM to authenticate to the machine configuration service.
Question 3
A company needs to apply the same operating-system security baseline to Azure VMs and on-premises servers connected through Azure Arc.
Which service provides this capability?
A. Azure Machine Configuration
B. Azure Bastion
C. Azure Load Balancer
D. Azure VM Image Builder
Answer: A
Explanation: Azure Machine Configuration supports guest operating-system auditing and enforcement across Azure VMs and Azure Arc-enabled servers.
Question 4
An organization wants a configuration assignment to correct a server setting and continue monitoring the machine for future configuration drift.
Which enforcement mode is most appropriate?
A. Audit
B. Disabled
C. Apply and Monitor
D. Deny
Answer: C
Explanation: Apply and Monitor applies the desired configuration and then monitors the machine for changes. Audit only reports the state, while Deny is an Azure Policy effect and not a Machine Configuration enforcement mode.
Question 5
A security team wants to assign a built-in Windows security baseline to all applicable virtual machines in a subscription.
Where should the team locate the built-in policy definition?
A. Azure portal → Virtual Machines → Extensions
B. Azure portal → Policy → Definitions
C. Azure portal → Microsoft Entra ID → Enterprise applications
D. Azure portal → Network Watcher → Topology
Answer: B
Explanation: Built-in Machine Configuration policies can be discovered under Azure Policy → Definitions. The Guest Configuration category can be used to filter relevant definitions.
Question 6
A custom machine configuration package is published and assigned to a VM, but the VM cannot retrieve the package.
Which issue should be investigated first?
A. Outbound connectivity, identity permissions, and package accessibility
B. Whether the VM has a public IP address
C. Whether Azure Bastion is deployed
D. Whether the VM uses a load balancer
Answer: A
Explanation: The machine must be able to access the configuration package and authenticate appropriately. Network restrictions, missing identity permissions, or an inaccessible package location can prevent evaluation or enforcement.
Question 7
An organization wants to apply a custom configuration assignment automatically when a target machine does not already have the assignment.
Which Azure Policy effect is commonly used for this purpose?
A. Audit
B. Deny
C. Disabled
D. DeployIfNotExists
Answer: D
Explanation: DeployIfNotExists can deploy a machine configuration assignment when the required assignment is missing. This is different from auditing whether the configuration is compliant.
Question 8
An administrator enables a machine configuration policy, but the VM never reports compliance. The VM is in scope and has the required policy assignment.
Which configuration is most likely to require verification?
A. The VM’s display resolution
B. The VM’s managed identity and Machine Configuration extension
C. The VM’s backup retention period
D. The VM’s DNS label
Answer: B
Explanation: The Machine Configuration extension and managed identity are essential for Azure VMs. If either is missing or incorrectly configured, the VM may not be able to retrieve assignments or report results.
Question 9
A security baseline contains a setting that would disrupt a legacy application. The organization still wants to enforce the rest of the baseline.
What is the best approach?
A. Disable all machine configuration policies
B. Ignore the failed compliance results
C. Customize the baseline or document an approved exception for the specific setting
D. Replace Azure Machine Configuration with Azure Bastion
Answer: C
Explanation: Baselines should be tested and adapted to workload requirements. Organizations can customize supported baseline settings or document approved exceptions rather than disabling the entire security program.
Question 10
Which statement best describes Azure Machine Configuration?
A. It replaces endpoint detection and response
B. It encrypts all data stored on Azure VM disks
C. It provides remote desktop access without exposing management ports
D. It audits and enforces desired operating-system configuration on supported machines
Answer: D
Explanation: Azure Machine Configuration focuses on guest operating-system configuration and compliance. It complements, but does not replace, endpoint protection, disk encryption, remote-access security, patching, and threat monitoring.
Go to the SC-500 Exam Prep Hub main page
