Job Details:
Job Title: Microsoft Defender for Servers / Azure Security Architect
Location: 100% Remote
Duration: 3+ Months Contract
Description:
The scope, deliverables, and responsibilities for the design, architecture planning, and pilot deployment of Microsoft Defender for Servers across NRECA''s server infrastructure. This engagement establishes the foundation for transitioning NRECA from Sentinel One to Microsoft Defender for Servers (Plan 2), creating a unified endpoint security posture integrated with the Microsoft security ecosystem.
The primary objectives of this engagement are:
• Design and document a comprehensive deployment architecture for Microsoft Defender for Servers across up to 1,500 servers, predominantly Windows with some Linux, spanning AWS EC2 and on-premises infrastructure
• Establish Azure Arc as the unified management plane for hybrid and multi-cloud server management
• Configure Defender for Servers policies including anti-malware, Attack Surface Reduction (ASR) rules, and threat detection
• Integrate security telemetry with Microsoft Sentinel for centralized monitoring and alerting
• Execute a pilot deployment of 50-75 servers to validate the solution and transfer knowledge to the NRECA security team
2. Project Overview
Armor Defense will execute this engagement in two phases, enabling NRECA to establish a validated design and pilot deployment before committing to a full production rollout. This phased approach minimizes risk, ensures proper knowledge transfer, and provides clear decision points throughout the engagement.
Phase Focus Outcome
Phase 1 Planning, Architecture, Design & Rollout Plan Validated design, documented policies, and approved rollout plan
Phase 2 Pilot Deployment & Knowledge Transfer 50-75 servers onboarded, validated solution, trained operations team
2.1 Approach Overview
The deployment architecture leverages Azure Arc to provide a unified management plane across NRECA''s hybrid environment. For AWS EC2 instances, the solution utilizes the native AWS Connector in Microsoft Defender for Cloud, which automates Azure Arc agent deployment through AWS Systems Manager (SSM). On-premises servers will be onboarded to Azure Arc using automated scripts and Group Policy where applicable.
This architecture ensures consistent policy enforcement, centralized visibility, and unified alerting regardless of where servers are hosted and will be validated during design.
3. Project Details
3.1 Phase 1: Planning, Architecture, Design & Rollout Plan
Purpose: Establish the foundational architecture, security policies, and deployment strategy required for a successful Defender for Servers implementation. This phase ensures all prerequisites are identified and addressed before any agents are deployed.
Tasks:
Environment Discovery & Assessment
• Inventory all servers (up to 1,500) including operating system types, versions, and locations (AWS EC2 vs. on premises)
• Map AWS account structure and identify regions with active workloads
• Validate AWS Systems Manager (SSM) Agent deployment status across EC2 instances
• Audit IAM roles and instance profiles on EC2 instances for SSM compatibility
• Document on premise infrastructure topology and network connectivity requirements
• Identify any unsupported operating system versions requiring exclusion or remediation
• Document EntraID/Active Directory architecture and deployment implications
• Validate Azure Arc agent prerequisites (TLS 1.2, Outbound URL connectivity, proxy config, etc.) across target environments
Current Security Tooling Assessment
• Review existing Sentinel One configuration, policies, and exclusions
• Extract relevant policy settings for consideration in Defender for Servers configuration
• Document coexistence strategy during transition period
Foundation Design
• Design subscription structure aligned with Defender for Cloud licensing model
• Validate licensing for all required components
• Architect Log Analytics workspace configuration for telemetry ingestion
• Define resource group structure and tagging strategy for Arc-enabled servers
• Design RBAC model for Defender for Cloud access and administration
• Plan Microsoft Sentinel integration for security telemetry and alerting
AWS Connector Architecture
• Design AWS Connector configuration (single account vs. management account)
• Review and customize CloudFormation template for IAM role creation
• Configure auto provisioning settings for Azure Arc agent deployment
• Define region selection and scan interval parameters
Policy & Security Configuration Design
• Design anti-malware policies including real-time protection and scheduled scans
• Configure Attack Surface Reduction (ASR) rule set with initial tuning recommendations and validate deployment methodology (Intune vs. GPO), taking into account both Windows and Linux servers and licensing selection (P1 vs P2)
• Define exclusion policies based on Sentinel One configuration review and workload requirements
• Design alerting strategy and notification routing
• Develop policy for ephemeral/temporal instances (auto-scaling workloads, dev/test environments)
Rollout Plan Development
• Define server grouping criteria (criticality, team ownership, workload type)
• Determine restrictive Azure Policy to control deployment as per wave deployment plan
• Determine deployment tooling (Intune vs. LANDesk) and deployment processes
• Create wave-based deployment schedule with team-by-team rollout
• Establish success criteria and go/no-go checkpoints for each wave
• Document rollback procedures
Phase 1 Deliverables:
Deliverable Description
Environment Assessment Report Server inventory, SSM readiness status, network requirements, and gap analysis
Architecture Design Document Azure foundation design, AWS connector architecture, Log Analytics configuration, and Sentinel integration
Security Policy Matrix Anti-malware, ASR rules, exclusions, and alerting configuration specifications
Rollout Plan Wave-based deployment schedule, team assignments, success criteria, and rollback procedures
Ephemeral Instance Policy Guidelines for handling short-lived instances, auto-scaling workloads, and dev/test environments
3.2 Phase 2: Pilot Deployment & Knowledge Transfer
Purpose: Validate the designed solution in a production environment with a representative subset of servers, refine configurations based on real-world results, and transfer operational knowledge to the NRECA security team.
Pilot Scope: 50-75 servers representing a cross-section of the environment, including AWS EC2 instances, on-premises servers, Windows Server, and Linux systems. Pilot servers will be selected from shared services groups and representative workloads.
Tasks:
Azure Foundation Implementation
• Enable Microsoft Defender for Cloud within target Azure subscription
• Enable Defender for Servers Plan 2
• Configure Log Analytics workspace per design specifications
• Establish Microsoft Sentinel data connectors for Defender for Cloud telemetry
AWS Pilot Deployment
• Deploy AWS Connector via CloudFormation template
• Configure autoprovisioning for Azure Arc agent on pilot EC2 instances
• Validate SSM-driven Arc agent deployment and connectivity
• Confirm telemetry flow to Defender for Cloud and Log Analytics
On-Premises Pilot Deployment
• Deploy Azure Arc agent to pilot on-premises servers
• Validate agent connectivity and health status
• Confirm Defender for Endpoint extension installation
Policy Deployment & Tuning
• Deploy anti-malware policies to pilot servers
• Enable ASR rules in audit mode for initial observation
• Analyze ASR audit results and tune rule configuration
• Configure alerting and notification workflows
• Validate security recommendations and remediation guidance
Pilot Validation
• Verify all pilot servers visible in Defender for Cloud inventory
• Confirm agent health status and extension deployment
• Test alert generation and notification delivery
• Validate telemetry in Microsoft Sentinel
• Document any exceptions and remediation actions
• Assess server performance impact
Knowledge Transfer Sessions (4 hours)
• Defender for Cloud administration and navigation
• Policy management, exclusions, and ASR rule tuning
• Azure Arc operations and troubleshooting
• Cost monitoring and optimization
• Incident response workflow
Phase 2 Deliverables:
Deliverable Description
Configured Environment Defender for Cloud, Log Analytics workspace, AWS Connector, and Sentinel integration operational
Onboarded Pilot Servers 50-75 servers onboarded with validated telemetry and policy enforcement
Pilot Completion Report Validation results, exceptions documented, performance observations, and go/no-go recommendation
Operational Runbooks Day-to-day operations procedures, troubleshooting guides, and policy management instructions
Knowledge Transfer Sessions Up to a maximum of 4 hours of hands-on training with recorded sessions