Service Endpoint
Resource Policy Contributor
User Access Administrator
SQL Managed Instance Subnet
HSM-Protected KeyVault Fips-140 level
level 2
Key Vault => Level 1
Managed HSM => Level 3
Cloud App Security Administrator
Manages Defender for Cloud Apps
Application Developer
Azure Storage Access Queue
Azure Storage Access Tables
Azure Storage Access Files / share
SMB Access
- AD DS (Kerberos)
- Entra Domain Services
- Entra Kerberos
- shared Key
Rest
- over API with RBAC
- Account and Service SAS
- Shared Key
Azure Storage Access Blob
Azure AKS Kubenet vs CNI
Kubenet Replaced by CNI-Overlay
CNI-Overlay
Private Overlay CIDR
low IP consumption
NAT
CNI
Direct VNet Subnet
High IP consumption
Native
Azure SQL Groups and Entra ID
Customer-Managed Encryption for Log-Analytics
1) Create AKV
2) Create a Log-Analytics dedicated Cluster
3) Configure Key Vault
Get, Unwrap, Wrap
or
Cryptic Service Encryption Use
4) Assign Key to Cluster
5) link Cluster with Log-Analytics
Managed vs Dedicated HSM
AKV select dedicated HSM if:
1) legacy app
2) appliance level control
3) Migration from on-prem
What types of B2B Collaboration exist?
B2B Collaboration
-> invite external as guest
-> internal guest user
B2B Direct Connect
-> Mutual trust, share resources
-> trust external tenant
User - Signin - Risk levels
high: strong evidence of compromise
medium: suspicious and abnormal behaviour
low: minor anomaly
Vnet - Manager Configuration - Routing
How to invite B2B users?
What to change for fast onboarding?
When to use: - Private Endpoint - Vnet Peering - Service Endpoint
OAuth Authorization Flows
Vnet Manager Features
Azure Function Networking
Inbound
- IP Restriction
- IP/Vnet/Service Endpoint
- deploy is Vnet
- Private Endpoint
- Service Endpoint
Outbound
- Vnet Integration
Routes outbound through Vnet
- Hybrid Connection
- Agent connects to Azure (outbound)