This is very hard to define. I have all my servers on cloud locked down and can only ssh with keys (No passwords) and everytime I look at the access log, it just makes me sweat seeing all the "drive by" ssh access attempts using standard usernames (which I don't use) and even unstandard user names (like "mother", "suser" etc).
Almost like returning home and seeing unknown footprints outside your home door. You know the door is secure, the window is bolted and you have an alarm. But still it's unnerving.
Basic practices I follow:
Don't run services with a user that has root access.
SSH only with keys
Open up ports on Azure portal only for required services.
Check "last", "uptime" "htop" everytime I login.