Tag: Azure Machine Configuration

Enforce security configuration of Azure-managed servers by using Azure Machine Configuration (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for servers and virtual machines (VMs)
      --> Enforce security configuration of Azure-managed servers by using Azure Machine Configuration


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Azure Machine Configuration is an Azure governance capability that allows organizations to audit and enforce operating-system settings as code on Azure virtual machines and Azure Arc-enabled servers.

It extends Azure Policy beyond the configuration of Azure resources and into the guest operating system. This makes it possible to establish consistent security baselines, identify machines that do not comply with those baselines, and—when appropriate—automatically correct noncompliant settings.

Azure Machine Configuration is especially useful when an organization manages a large number of Windows and Linux servers across Azure, on-premises environments, other cloud providers, or edge locations.


Why Azure Machine Configuration Is Important

Traditional Azure Policy evaluates many aspects of Azure resources, such as:

  • Whether a virtual machine uses a particular operating system
  • Whether a resource has required tags
  • Whether a storage account allows public access
  • Whether a virtual machine uses a supported security configuration

However, many important security settings exist inside the guest operating system, including:

  • Password and account policies
  • Windows security options
  • Linux configuration files
  • Services that must be enabled or disabled
  • Required applications or packages
  • File permissions
  • Audit settings
  • Operating-system security baseline settings
  • Organization-specific configuration requirements

Azure Machine Configuration allows these settings to be represented as machine configuration assignments and evaluated through Azure Policy.

This provides a consistent process to:

  1. Define the desired configuration.
  2. Assign the configuration to a scope.
  3. Evaluate machines against the configuration.
  4. Report compliance or noncompliance.
  5. Correct configuration drift when enforcement is enabled.

Azure Machine Configuration and Azure Policy

Azure Machine Configuration works closely with Azure Policy.

Azure Policy determines:

  • Which machines are in scope
  • Which configuration should be evaluated
  • Whether the configuration is audited or enforced
  • How compliance is reported
  • Whether remediation should be deployed

Azure Machine Configuration evaluates the actual operating-system settings on the machine.

The relationship can be summarized as follows:

ComponentPrimary responsibility
Azure PolicyAssigns and governs the configuration
Machine ConfigurationEvaluates or applies guest OS settings
Machine Configuration extensionEnables configuration management on Azure VMs
Azure Arc Connected Machine agentProvides the required capability for Arc-enabled servers
Managed identityAllows the Azure VM to authenticate to the machine configuration service
Azure Policy ComplianceDisplays compliance results

Azure Machine Configuration policies can be assigned at the management group, subscription, or resource-group level. This supports centralized governance across an entire server estate.


Supported Machine Types

Azure Machine Configuration can be used with:

  • Azure virtual machines
  • Azure virtual machine scale sets, where supported
  • Azure Arc-enabled servers
  • Servers running Windows
  • Servers running Linux

For Azure VMs, the Machine Configuration extension and a system-assigned managed identity are required.

For Azure Arc-enabled servers, the required functionality is provided through the Azure Connected Machine agent rather than the Azure VM extension.

This allows an organization to use a similar compliance model for:

  • Azure-hosted servers
  • On-premises servers
  • Servers hosted in another cloud
  • Edge servers connected through Azure Arc

Required Prerequisites

Before assigning machine configuration policies, verify the following prerequisites.

1. Register the Resource Provider

The Microsoft.GuestConfiguration resource provider must be registered for the subscription.

When machine configuration policies are assigned through the Azure portal—or when the subscription is enrolled in Microsoft Defender for Cloud—the provider may be registered automatically. It can also be registered manually through the Azure portal, Azure PowerShell, or Azure CLI.

2. Deploy the Machine Configuration Extension

Azure virtual machines require the Machine Configuration or Guest Configuration extension.

The extension:

  • Downloads applicable machine configuration assignments
  • Retrieves configuration dependencies
  • Evaluates the guest operating system
  • Applies configuration settings when enforcement is enabled
  • Reports configuration results

The extension can be deployed individually or at scale by assigning the prerequisite policy initiative:

Deploy prerequisites to enable Guest Configuration policies on virtual machines

The exact policy initiative name may vary slightly as Microsoft updates the service and terminology.

3. Enable a Managed Identity

Azure VMs require a system-assigned managed identity for machine configuration.

The identity allows the VM to authenticate to the machine configuration service without requiring administrators to store credentials on the server.

The prerequisite initiative can automatically create a system-assigned managed identity when one does not already exist.

4. Verify Connectivity

The machine must be able to communicate with the required Azure services.

Network restrictions involving:

  • Network security groups
  • Azure Firewall
  • Proxy servers
  • Outbound filtering
  • Private networking
  • DNS configuration

can prevent the extension from downloading assignments or reporting results.

5. Verify Extension and Agent Versions

For machine configuration packages that apply settings, the Azure VM Guest Configuration extension must meet the supported minimum version. Microsoft currently identifies version 1.26.24 or later for Azure VMs in its custom-policy documentation.


Machine Configuration Enforcement Modes

Azure Machine Configuration supports different ways to manage configuration.

Audit

Audit mode evaluates the machine and reports whether it complies with the desired configuration.

It does not change the machine.

Use Audit mode when:

  • Establishing an initial security baseline
  • Discovering configuration drift
  • Assessing the impact of a new policy
  • Testing a configuration before enforcement
  • Identifying exceptions
  • Preparing for a compliance audit

For example, an audit policy might determine whether Windows servers meet the Azure compute security baseline.

Apply and Monitor

Apply and Monitor applies the configuration and then continues monitoring the machine for changes.

This mode is useful when the organization wants the desired configuration to be established and then monitored for drift.

Apply and AutoCorrect

Apply and AutoCorrect applies the desired configuration and attempts to correct changes that cause the machine to become noncompliant.

This mode is appropriate when a setting must remain consistent and automatic correction is acceptable.

However, automatic correction should be used carefully. Some settings can affect:

  • Application compatibility
  • Network connectivity
  • Authentication
  • System startup
  • Legacy workloads
  • Custom operating-system behavior

Microsoft’s machine configuration tooling supports policy definitions that audit or apply custom configuration packages, including policies generated with the New-GuestConfigurationPolicy PowerShell cmdlet.


Audit First, Enforce Second

A recommended implementation approach is to begin with auditing.

Phase 1: Discover

Identify:

  • Which machines are in scope
  • Which operating systems are used
  • Which applications depend on current settings
  • Which machines are production systems
  • Which machines are exceptions
  • Which security standards must be followed

Phase 2: Audit

Assign the desired baseline in Audit mode.

Review:

  • Overall compliance
  • Individual noncompliant machines
  • Individual failed settings
  • Configuration conflicts
  • Unsupported systems
  • Required exceptions

Phase 3: Remediate

Correct problems manually or through controlled remediation.

For example:

  • Update an insecure configuration
  • Install a required package
  • Disable an unnecessary service
  • Correct file permissions
  • Change a security option
  • Document an approved exception

Phase 4: Enforce

After testing, change the assignment to an enforcement mode.

This reduces the risk that a new configuration will unexpectedly disrupt production workloads.


Built-In Security Baselines

Microsoft provides built-in machine configuration policies for common security requirements.

Examples include:

  • Windows machines should meet requirements for the Azure compute security baseline
  • Linux machines should meet requirements for the Azure compute security baseline
  • Windows machines should use a specified time zone
  • Linux machines should have specified applications installed
  • Other operating-system configuration policies

Built-in definitions can be discovered in:

Azure portal → Policy → Definitions

Use filters such as:

  • Category: Guest Configuration
  • Policy type: Built-in

A policy definition can be inspected to review:

  • Its purpose
  • Supported platforms
  • Parameters
  • Version
  • Policy effect
  • Required resources
  • Configuration details

Built-in security baseline policies can be assigned to Azure VMs and, where supported, Azure Arc-enabled servers.


Azure Compute Security Baselines

Security baselines provide a recommended collection of operating-system settings intended to improve the security posture of Windows and Linux machines.

They may include requirements related to:

  • Account policies
  • Authentication
  • Audit policies
  • Security options
  • Network security
  • System services
  • File permissions
  • Operating-system behavior

The baseline should not automatically be treated as a universal configuration for every workload. Organizations should evaluate whether particular settings are compatible with:

  • Business applications
  • Legacy systems
  • Domain controllers
  • Specialized appliances
  • High-availability systems
  • Custom Linux distributions
  • Regulatory requirements
  • Operational procedures

The current Azure Machine Configuration experience supports customizable security baselines. Administrators can select, exclude, or modify rules and export the resulting settings as a reusable JSON artifact.


Custom Machine Configurations

Built-in policies may not satisfy every organizational requirement.

A custom machine configuration can be used when an organization needs to enforce settings such as:

  • A required registry value
  • A specific Linux configuration-file value
  • A required service state
  • A required package or application
  • A particular file permission
  • A specific security option
  • An organization-specific hardening requirement

A custom configuration generally involves the following process:

  1. Define the desired configuration.
  2. Create a machine configuration package.
  3. Test the package.
  4. Publish the package to an accessible location.
  5. Create a machine configuration policy definition.
  6. Assign the policy.
  7. Review compliance results.
  8. Remediate or enforce as required.

The configuration package must be accessible to the target machine. When a package is stored in Azure Storage, the appropriate identity and permissions must be configured so that the machine can retrieve it securely.

Custom machine configuration policy definitions commonly use effects such as:

  • AuditIfNotExists
  • DeployIfNotExists

The DeployIfNotExists effect can be used to deploy a machine configuration assignment when the required assignment does not exist.


Policy Assignment Scope

A machine configuration policy can be assigned at different scopes.

Management Group

Use a management-group assignment when the configuration should apply across multiple subscriptions.

Subscription

Use a subscription assignment when all or most machines in a subscription should follow the same baseline.

Resource Group

Use a resource-group assignment when the policy should apply to a specific workload or server group.

Exclusions

Exclusions may be necessary for:

  • Unsupported operating systems
  • Development machines
  • Legacy applications
  • Specialized servers
  • Disaster-recovery systems
  • Approved exceptions

Exclusions should be documented and reviewed periodically. An exclusion should not become a permanent way to avoid addressing a known security issue.


Compliance Reporting

After a policy is assigned, compliance information can be reviewed through Azure Policy.

Administrators can identify:

  • Compliant machines
  • Noncompliant machines
  • Machines that have not yet evaluated
  • Failed configuration settings
  • Policy assignment status
  • Remediation status

Machine configuration can also provide per-setting results through the machine’s guest assignments or through the compliance details associated with the Azure Policy assignment.

Compliance reporting is useful for:

  • Security operations
  • Internal audits
  • Regulatory reporting
  • Vulnerability remediation
  • Configuration-drift management
  • Executive security dashboards

Azure Machine Configuration Compared with Other Security Controls

Azure Machine Configuration is not a replacement for every security service.

Security controlPrimary purpose
Azure Machine ConfigurationAudit and enforce operating-system configuration
Azure PolicyGovern Azure resource configuration and policy compliance
Microsoft Defender for CloudAssess security posture and provide recommendations
Microsoft Defender for ServersProvide server protection, vulnerability assessment, and threat detection capabilities
Azure VM disk encryptionProtect data stored on VM disks
Just-in-time VM accessReduce exposure of management ports
Azure BastionProvide managed remote access without exposing public RDP or SSH ports
Azure Update ManagerManage operating-system updates
Microsoft SentinelCollect, analyze, and respond to security events

A secure VM strategy normally combines several of these controls rather than relying on Machine Configuration alone.


Common Implementation Mistakes

Mistake 1: Enforcing Before Auditing

Applying a baseline immediately can cause unexpected application or connectivity issues.

Better approach: Begin with Audit mode, review failures, test remediation, and then enforce.

Mistake 2: Assuming Azure Policy Automatically Changes Guest Settings

Not every Azure Policy definition changes the operating system.

Better approach: Confirm whether the policy audits configuration, deploys a configuration assignment, or applies settings inside the guest OS.

Mistake 3: Forgetting the Extension

An Azure VM may be in policy scope but still be unable to evaluate guest configuration if the required extension is missing.

Better approach: Deploy the machine configuration prerequisites before assigning configuration policies.

Mistake 4: Forgetting Managed Identity

The VM needs an appropriate identity to communicate with the machine configuration service.

Better approach: Verify that the required system-assigned managed identity is enabled.

Mistake 5: Ignoring Network Restrictions

Outbound network controls can prevent configuration downloads and compliance reporting.

Better approach: Verify DNS, outbound connectivity, firewall rules, proxy settings, and required service access.

Mistake 6: Treating Every Baseline Setting as Universally Appropriate

A baseline may contain settings that conflict with a specialized application.

Better approach: Test settings, document exceptions, and customize the baseline when necessary.

Mistake 7: Confusing Configuration Compliance with Threat Detection

Machine Configuration determines whether settings match a desired state. It does not replace endpoint detection and response or malware protection.

Better approach: Combine configuration enforcement with Defender for Cloud, Defender for Servers, patching, network security, and monitoring.


Recommended Implementation Pattern

A practical enterprise implementation can follow this sequence:

  1. Register Microsoft.GuestConfiguration.
  2. Identify Azure VMs and Arc-enabled servers.
  3. Deploy the machine configuration prerequisites.
  4. Enable required managed identities.
  5. Select a built-in Windows or Linux security baseline.
  6. Customize the baseline if necessary.
  7. Assign the baseline in Audit mode.
  8. Review compliance results.
  9. Remediate failed settings.
  10. Document approved exceptions.
  11. Test enforcement on a pilot group.
  12. Enable Apply and Monitor or Apply and AutoCorrect.
  13. Monitor compliance continuously.
  14. Review baseline versions and update policies as requirements change.

Exam-Focused Summary

For the SC-500 exam, remember these key points:

  • Azure Machine Configuration manages guest operating-system settings.
  • Azure Policy provides the assignment and governance framework.
  • Azure VMs require the Machine Configuration extension and a managed identity.
  • Azure Arc-enabled servers use the Arc Connected Machine agent.
  • Machine Configuration supports both Azure and hybrid servers.
  • Audit mode reports configuration state without changing the machine.
  • Apply and Monitor applies configuration and monitors for drift.
  • Apply and AutoCorrect attempts to restore the desired configuration.
  • Built-in security baselines are available for Windows and Linux.
  • Custom configurations can address organization-specific requirements.
  • Audit before enforcing.
  • Network connectivity and identity configuration are common troubleshooting areas.
  • Machine Configuration is complementary to Defender for Cloud, disk encryption, JIT VM access, and other security controls.

Practice Exam Questions

Question 1

An organization wants to determine whether its Azure Windows VMs comply with a required operating-system security baseline. The organization does not want to change any settings yet.

Which approach should be used?

A. Apply and AutoCorrect
B. Audit mode
C. Azure VM disk encryption
D. Just-in-time VM access

Answer: B

Explanation: Audit mode evaluates the machine and reports compliance without changing the operating system. This is the recommended starting point before enforcing a new baseline.


Question 2

An administrator wants to manage guest operating-system configuration on Azure virtual machines. Which combination is required for Azure VMs?

A. Azure Bastion and a public IP address
B. Microsoft Sentinel and a Log Analytics workspace
C. Defender for Servers and Azure Firewall
D. Machine Configuration extension and a system-assigned managed identity

Answer: D

Explanation: Azure VMs require the Machine Configuration extension and a system-assigned managed identity. The extension evaluates or applies configuration, while the identity allows the VM to authenticate to the machine configuration service.


Question 3

A company needs to apply the same operating-system security baseline to Azure VMs and on-premises servers connected through Azure Arc.

Which service provides this capability?

A. Azure Machine Configuration
B. Azure Bastion
C. Azure Load Balancer
D. Azure VM Image Builder

Answer: A

Explanation: Azure Machine Configuration supports guest operating-system auditing and enforcement across Azure VMs and Azure Arc-enabled servers.


Question 4

An organization wants a configuration assignment to correct a server setting and continue monitoring the machine for future configuration drift.

Which enforcement mode is most appropriate?

A. Audit
B. Disabled
C. Apply and Monitor
D. Deny

Answer: C

Explanation: Apply and Monitor applies the desired configuration and then monitors the machine for changes. Audit only reports the state, while Deny is an Azure Policy effect and not a Machine Configuration enforcement mode.


Question 5

A security team wants to assign a built-in Windows security baseline to all applicable virtual machines in a subscription.

Where should the team locate the built-in policy definition?

A. Azure portal → Virtual Machines → Extensions
B. Azure portal → Policy → Definitions
C. Azure portal → Microsoft Entra ID → Enterprise applications
D. Azure portal → Network Watcher → Topology

Answer: B

Explanation: Built-in Machine Configuration policies can be discovered under Azure Policy → Definitions. The Guest Configuration category can be used to filter relevant definitions.


Question 6

A custom machine configuration package is published and assigned to a VM, but the VM cannot retrieve the package.

Which issue should be investigated first?

A. Outbound connectivity, identity permissions, and package accessibility
B. Whether the VM has a public IP address
C. Whether Azure Bastion is deployed
D. Whether the VM uses a load balancer

Answer: A

Explanation: The machine must be able to access the configuration package and authenticate appropriately. Network restrictions, missing identity permissions, or an inaccessible package location can prevent evaluation or enforcement.


Question 7

An organization wants to apply a custom configuration assignment automatically when a target machine does not already have the assignment.

Which Azure Policy effect is commonly used for this purpose?

A. Audit
B. Deny
C. Disabled
D. DeployIfNotExists

Answer: D

Explanation: DeployIfNotExists can deploy a machine configuration assignment when the required assignment is missing. This is different from auditing whether the configuration is compliant.


Question 8

An administrator enables a machine configuration policy, but the VM never reports compliance. The VM is in scope and has the required policy assignment.

Which configuration is most likely to require verification?

A. The VM’s display resolution
B. The VM’s managed identity and Machine Configuration extension
C. The VM’s backup retention period
D. The VM’s DNS label

Answer: B

Explanation: The Machine Configuration extension and managed identity are essential for Azure VMs. If either is missing or incorrectly configured, the VM may not be able to retrieve assignments or report results.


Question 9

A security baseline contains a setting that would disrupt a legacy application. The organization still wants to enforce the rest of the baseline.

What is the best approach?

A. Disable all machine configuration policies
B. Ignore the failed compliance results
C. Customize the baseline or document an approved exception for the specific setting
D. Replace Azure Machine Configuration with Azure Bastion

Answer: C

Explanation: Baselines should be tested and adapted to workload requirements. Organizations can customize supported baseline settings or document approved exceptions rather than disabling the entire security program.


Question 10

Which statement best describes Azure Machine Configuration?

A. It replaces endpoint detection and response
B. It encrypts all data stored on Azure VM disks
C. It provides remote desktop access without exposing management ports
D. It audits and enforces desired operating-system configuration on supported machines

Answer: D

Explanation: Azure Machine Configuration focuses on guest operating-system configuration and compliance. It complements, but does not replace, endpoint protection, disk encryption, remote-access security, patching, and threat monitoring.


Go to the SC-500 Exam Prep Hub main page