Software Secure Workload
Activity Configure

Set Up Microsegmentation for Cloud-Based Workloads

Procedure

1

Install agents on your cloud-based workloads, if required.

Cloud connectors provide VPC/VNet level granularity in policy discovery and enforcement. Install agents on supported platforms if you require policy discovery and enforcement at a more granular level.

Install agents based on the operating system on which your cloud service is running. For more information, see Deploying Software Agents.

2

Set up cloud connectors to gather labels and flow data.

For more information, see:

3

Create workspaces for the scopes created by the connector. For more information, see Workspaces.

4

Automatically discover policies.

Discover policies for each VPC/VNet-defined scope, and if applicable, for more granular scopes.

For more information, see Automatic Policy Discovery.

5

Review and analyze the suggested policies.

See Review and Analyze Policies and subtopics.

6

Iteratively discover policies as needed.

See Iteratively Revise Policies and subtopics.

7

Approve and enforce policies for each scope.

You must enable enforcement in the applicable workspace and in the connector for each VPC or VNet, and for any agents installed on individual workloads.