Index

A

access control, 77

checking, 8283

configuring for storage accounts, 234237

RBAC, 7778

VMs (virtual machines) and, 159

access keys

manually rotating, 245246

regenerating, 246

storage account, 243245

access policies, 275276

access reviews, 45

account SAS (Shared Access Signatures), 255257

ACR (Azure Container Registry), 163165

activity log

Azure Firewall, 126129

Azure Monitor, 204205

Add-AzVirtualNetworkPeering cmdlet, 102

adding

administrative units, 21

group members, 9

ADE (Azure Data Encryption), 174175

administrative units, 21

adding, 21

roles, 23

AKS (Azure Kubernetes), 166167

logical isolation, 166

Microsoft Defender for Cloud and, 168169

nodes, 168

physical isolation, 166

alerts

analytics, 221222

creating, 205210

Microsoft Defender for Storage, 242243

rules, 210

simulating, 192193

viewing, 194195

Always Encrypted, 266

configuring, 267268

deterministic encryption, 266267

randomized encryption, 267

API management policies, 76

application gateways, 44. See also Azure Application Gateway

application objects, 2

applications

assigning a role to, 34

registering with Azure AD, 2

apps

assigning users to, 7073

configuring registration permission scopes, 7374

managing access, 70

managing registration permission consent, 7475

registrations, 6870

architecture

Contoso network diagram, 92

Microsoft Sentinel, 215217

ASGs (application security groups), 117118

associating with the VM, 119120

creating, 118119

assigning

Azure AD roles

built-in, 8386

custom, 8689

permissions to service principals, 35

users to apps, 7073

assigning, RBAC roles to storage accounts, 234237

auditing a database, 259262

authentication

Azure AD, 247

Domain Services, 251252

domain services for Azure files, 247248

enabling, 248250

share-level permissions, configuring, 250251

Azure App Service, 171173

certificate-based, 6667

database, 258259

Federation Services, 61

multifactor

account lockout, 37

block/unblock users, 3738

fraud alert settings, 38

implementing, 30

OATH tokens, 3839

performing a bulk reset, 3536

phone call settings, 39

setting up on Azure AD, 3034

user administration, 3437

utilization reports, 40

pass-through, 61

passwordless, 4345

SAS (Shared Access Signatures), configuring, 253254

service principals, 7677

VPN, 107108

az ad group create command, 9

az storage account update command, 256

AzNetworkSecurityRuleConfig cmdlet, 117

Azure AD (Active Directory), 14, 247, 250

adding and removing members, 9

administrative units, 21

application object, 2

apps

assigning users, 7073

managing access, 70

managing registration permission consent, 7475

registrations, 6870

authentication, 6366

certificate-based, 6667

database, 258259

Domain Services, 251252

enabling, 248250

file and folder permissions, configuring, 251

share-level permissions, configuring, 250251

B2B (business-to-business) accounts, creating, 1417

built-in roles, 8386

configuring domain services authentication for Azure files, 247248

External Collaboration settings, 2021

Federation Services, 61

groups, 67

creating, 79

nested, 911

guest accounts, creating, 1719

identities, 1

Identity Protection, 4043

MFA (multifactor authentication)

account lockout, 37

block/unblock users, 3738

fraud alert settings, 38

OATH tokens, 3839

performing a bulk reset, 3536

phone call settings, 39

setting up, 3034

utilization reports, 40

pass-through authentication, 61

password synchronization, 6061

PIM (Privileged Identity Management, 2326

access review, 4547

monitoring privileged access for, 4749

RBAC (role-based access control), 78

custom roles, 8689

delegating admin rights, 7980

interpreting role and resource permissions, 81

permissions, 8182

resource group permissions, 80

registering applications with, 2

resource audit history, viewing, 4849

self-service password reset, 6163, 67

service principals, 23

assigning permissions through roles, 35

authentication, 7677

certificate-based authentication, 77

creating, 3

UPN suffixes, 5960

user accounts

administration tasks, 13

creating, 1213

managing, 1213

user principals, 2

Azure AD Connect, 50, 5960

installing, 5259

pass-through authentication, 61

password synchronization, 6061

requirements, 50

connectivity, 5051

deployment accounts, 52

SQL server, 51

UPN suffixes, 5960

Azure App Service, 169, 173

advantages and limitations, 170171

authentication, 171173

CDS (Common Data Service), 173

encryption

ADE (Azure Data Encryption), 174175

certificates, 175178

firewall, 146147

identity providers, 173

security recommendations, 171

Azure Application Gateway

modes, 140

WAF (web application firewall) and, 139140

Azure Bastion, 93

Azure CLI

commands for backup and recovery, 298

commands for management Key Vault certifications, 287288

commands for managing Key Vault secrets, 290291

configuring access policies, 277

creating user delegation SAS, 255

key management commands, 293294

Azure DDoS protection, 151

basic versus standard tiers, 151

configuring, 152153

diagnostic logging, 154155

DoS attack mitigation report, 153154

Azure Defender for Servers, 159

Azure ExpressRoute, 94

encryption, 109

Microsoft Defender for Storage, 242243

Azure Firewall, 120121

activity log, 126129

configuring, 122124

Premium tier, 122

rules, 121

application, 124125

network, 126

Standard tier, 121122

Azure Firewall Manager, 129130

Firewall policy, 130

hub virtual network deployment, 131

policies, 130

use cases, 130131

Azure Front Door, 131

capabilities, 132

configuring, 133138

Azure Key Vault, 243, 278. See also encryption

backup and recovery, 296299

certificate policies, 281

certificate-issuance providers, 282

cmdlets for managing certifications, 286

configuring access to, 275

configuring firewalls and virtual networks, 64

creating, 274

firewall, 145146

key management, 291294

Azure CLI commands, 293294

cmdlets, 293

key rotation, 294295

manage permissions to secrets, certificates, and keys, 275277

network access rules, 279

RBAC, 277278

secrets, 288291

cmdlets, 290

viewing, 289

X509 certificates, managing, 281

Azure Monitor, 201

Activity Log, 204205

alerts

creating, 205210

rules, 210

architecture diagram, 202203

logs

diagnostic, 211213

security, 213215

metrics, 203

resources and, 203

Azure Policy, 186189

Azure portal, creating administrative units, 21

Azure Private Link, isolating data solutions, 270

Azure SQL

Always Encrypted, 266

configuring, 267268

deterministic encryption, 266267

randomized encryption, 267

auditing, 259262

database authentication, 258259

database encryption, 264266

dynamic masking, 262263

firewall, 143145

masking functions, 263

Microsoft Defender for SQL, configuring, 271272

vulnerability assessment, 198199

Azure Storage. See also storage accounts

access keys, 243

manually rotating, 245246

viewing, 244245

Azure AD authentication, 247

encryption, 237239

infrastructure, 239240

key management, 239

scopes, 240242

firewall, 141143

B

B2B (business-to-business) accounts

creating, 1417

external sharing, 1921

backup and recovery, Key Vault items, 296299

blobs

authorizing access to data, 247

Azure Storage encryption, 237239

Microsoft Defender for Storage, 242243

user delegation SAS, 254

BYOK (‘Bring Your Own Key’), 264

C

CDS (Common Data Service), 173

centralized policy management, 181

certificate-based authentication, 6667, 77

certificates

cmdlets, 286

creating, 282285

importing, 285286

X509, 281

cloning, roles, 8789

cloud computing, shared responsibility model, 91

cmdlets, 299. See also PowerShell

Add-AzVirtualNetworkPeering, 102

AzNetworkSecurityRuleConfig, 117

Debug-AzStorage AccountAuth, 250

Get-AzureADTrustedCertificateAuthority, 67

Get-AzureKeyVaultSecret, 289

for group management, 7

key management, 293

for managing Azure Key Vault certificates, 286

New-AzRoleAssignment, 5

New-AzureADMSAdministrativeUnit PowerShell, 21

New-AzureADTrustedCertificateAuthority, 67

New-AzVirtualNetwork, 97

Set-AzKeyVaultAccessPolicy, 276277

Set-AzStorageAccount, 256

Set-AzVmDiskEncryptionExtension, 175

commands

az ad group create, 9

az storage account update, 256

for backup and recovery of Key Vault items, 298

certificate-management, 287288

for managing Key Vault secrets, 290291

Revoke-AzStorageAccountUserDelegationKeys, 254

conditional access policies, 2629

configuring, 5960

access to Azure Key Vault, 275

Always Encrypted, 267268

API management policies, 76

app registration permission scopes, 7374

Azure AD, 247248

Azure DDoS protection, 152153

Azure Firewall, 122124

Azure Front Door, 133138

endpoint protection, 155158

firewalls

Azure App Service, 146147

Azure Key Vault, 145146

Azure SQL, 145

Azure Storage, 141143

MFA (multifactor authentication), 3034

account lockout, 37

block/unblock users, 3738

fraud alert settings, 38

OATH tokens, 3839

phone call settings, 39

utilization reports, 40

Microsoft Defender for SQL, 200201, 271272

NSGs (network security groups), 114117

SAS (Shared Access Signatures), 253254

account, 255257

user delegation, 254255

service endpoints, 149150

share-level permissions, 250251

storage accounts, access control, 234237

UPN suffixes, 5960

VNets (virtual networks), 9496, 99102

VPNs (virtual private networks), authentication, 107108

connectivity, Azure AD Connect, requirements, 5051

connectors, Microsoft Sentinel, 217221

containers. See also storage accounts

ACR (Azure Container Registry), 163165

storage accounts

access keys, 243

assigning RBAC roles to, 234237

configuring access control, 234237

encryption key management, 239

encryption scopes, 240242

infrastructure encryption, 239240

manually rotating access keys, 245246

Microsoft Defender for Storage, 242243

viewing access keys, 244245

user delegation SAS, 254255

creating

administrative units, 21

alerts, 205210

application rules, 124125

ASGs (application security groups), 118119

Azure AD user accounts, 1213

Azure Key Vault, 274

B2B (business-to-business) accounts, 1417

certificates, 282285

conditional access policies, 2729

groups, 79

guest accounts, 1719

incidents, 226227

keys, 292

NAT gateway, 104105

network rules, 126

NSGs (network security groups), 114117

policy initiative, 182185

service principals, 3

VNets (virtual networks), 97

custom

roles, assigning, 8689

routes, creating, 99

D

data solutions, isolating, 269

using IP firewall rules, 270

using service endpoints, 269

database(s). See also Azure SQL

auditing, 259262

authentication, 258259

encryption, 264266

isolating, using Azure Private Link, 270

Debug-AzStorage AccountAuth cmdlet, 250

deterministic encryption, 266267

diagnostic logging, 211213

dynamic masking, 262263

E

encryption

Azure ExpressRoute, 109

Azure Storage, 237239

infrastructure, 239240

key management, 239

scopes, 240242

BYOK (‘Bring Your Own Key’), 264266

database, 264266

deterministic, 266267

IPSec, 109

MACsec, 109

randomized, 267

in transit, 175177

VMs (virtual machines), 159

endpoint

protection, 155158

service, isolating data solutions, 269

enforcing, policies, 186189

external identities

B2B (business-to-business), creating, 1417

guest accounts, creating, 1719

F

Federation Services, 61

FIDO2 security key, 43

file shares

Azure AD DS authentication, configuring, 247248

file and folder permissions, configuring, 251

share-level permissions, configuring, 250251

Firewall policy, 130

firewalls. See also Azure Firewall

Azure App Service, 146147

Azure Key Vault, 145146

Azure SQL, 143145

Azure Storage, 141143

Key Vault, 279281

WAF (web application firewall), 121, 138140

folder permissions, configuring, 251

G

Get-AzureADTrustedCertificateAuthority cmdlet, 67

Get-AzureKeyVaultSecret cmdlet, 289

groups, 67

adding and removing members, 9

creating, 79

nested, 911

guest accounts, creating, 1719

H

hub virtual network, Azure Firewall Manager deployment, 130131

hybrid networks, VPNs (virtual private networks), 106107

authentication, 107108

types of, 107

I

IaaS (Infrastructure as a Service), 91

identities, 1. See also external identities

PIM (Privileged Identity Management, 2326

access review, 4547

monitoring privileged access for, 4749

Identity Protection, 4043

implementing, MFA (multifactor authentication), 30

importing, certificates, 285286

inbound rules, NSGs (network security groups), 113

incidents

creating, 226227

evaluating, 229230

infrastructure, Azure Storage encryption, 239240

installing, Azure AD Connect, 5259

IP addressing, NAT (network address translation), 102103

IP firewall rules, isolating data solutions, 270

IPSec, 109

isolating data solutions, 269

using Azure Private Link, 270

using IP firewall rules, 270

using service endpoints, 269

J-K

Kerberos, creating a storage account key, 248249

key management

Azure Key Vault, 276

Azure Key Vault and, 291294

Azure Storage encryption, 239

BYOK (‘Bring Your Own Key’), 264266

cmdlets, 293

key rotation, 294295

L

licensing, PIM (Privileged Identity Management, 2526

Linux

Microsoft Defender for Servers, 191192

VMs, ADE (Azure Data Encryption) and, 175

logs

diagnostic, 211213

security, 213215

M

MACsec, 109

managing

access to apps, 70

groups, 7

security updates, 162163

user accounts, 1213

manually rotating access keys, 245246

members, adding and removing from groups, 9

MFA (multifactor authentication), 107

account lockout, 37

block/unblock users, 3738

fraud alert settings, 38

implementing, 30

OATH tokens, 3839

performing a bulk reset, 3536

phone call settings, 39

setting up on Azure AD, 3034

user administration, 3437

utilization reports, 40

Microsoft 365

external sharing, 19

groups, 6. See also groups

Microsoft Authenticator app, 44

Microsoft Defender for Cloud and, 168169

Microsoft Defender for Servers, 190191

for Linux, 191192

vulnerability assessment, 195197

for Windows, 191

Microsoft Defender for SQL

configuring, 200201, 271272

vulnerability assessment, 198199

Microsoft Defender for Storage, 242243

Microsoft Sentinel, 201

analytics, 221222

architecture, 215217

connectors, 217221

incidents

creating, 226227

evaluating, 229230

Log Analytics workspace, 228

scheduled query rule, creating, 222226

threat hunting, 230231

Workbooks, 228229

Microsoft Threat Intelligence, 121

mobile devices

apps

configuring registration permission scopes, 7374

managing access, 70

managing registration permission consent, 7475

registrations, 6870

MFA (multifactor authentication) and, 30

passwordless authentication, 4345

N

NAT (network address translation), 102105

nested groups, 911

network rules, 126

network segmentation, 94

New-AzRoleAssignment cmdlet, 5

New-AzureADMSAdministrativeUnit PowerShell cmdlet, 21

New-AzureADTrustedCertificateAuthority cmdlet, 67

New-AzVirtualNetwork cmdlet, 97

nodes, AKS (Azure Kubernetes), 168

NSGs (network security groups), 93, 111112

creating, 114117

inbound rules, 113

outbound rules, 113114

O

OATH tokens, MFA (multifactor authentication), 3839

OneDrive, external sharing, 19

outbound rules, NSGs (network security groups), 113114

OWASP (Open Web Application Security Project), 139140

P

PaaS (Platform as a Service), 91

pass-through authentication, 61

passwordless authentication, 4345

password(s)

self-service reset, 6163

synchronization, 6061

writeback, 67

peering, 94, 99102

permissions, 8182

app registration, 7375

assigning to service principals, 35

Azure Key Vault, 276

file and folder, configuring, 251

resource group, 80

share-level, configuring, 250251

PIM (Privileged Identity Management, 2326

access reviews, 4547

monitoring privileged access for, 4749

point-to-site VPNs, 110

advantages and limitations, 110

policy(ies), 158, 181182, 186

access, 275276

API management, 76

certificate, 281

conditional access, 2629

definition, 185

dynamic masking, 263

enforcement, 186189

Firewall, 130

initiatives, creating, 182185

risk, 4143

stored access, 257

PowerShell

AzFilesHybrid module, 249250

cmdlets

Add-AzVirtualNetworkPeering, 102

AzNetworkSecurityRuleConfig, 117

for backup and recovery of Key Vault items, 299

Debug-AzStorage AccountAuth, 250

Get-AzureADTrustedCertificateAuthority, 67

Get-AzureKeyVaultSecret, 289

for group management, 7

key management, 293

for managing Azure Key Vault certificates, 286

for managing Key Vault secrets, 290

New-AzRoleAssignment, 5

New-AzureADMSAdministrativeUnit PowerShell, 21

New-AzureADTrustedCertificateAuthority, 67

New-AzVirtualNetwork, 97

Set-AzStorageAccount, 256

Set-AzVmDiskEncryptionExtension, 175

creating user delegation SAS, 254255

regenerating storage account access keys, 246

on-premises Active Directory. See also Azure AD (Active Directory)

pass-through authentication, 61

password synchronization, 6061

UPN suffixes, 5960

pricing, ACR (Azure Container Registry), 163

private endpoints, 150151

Private Link service, 151

Q-R

RADIUS, 108

randomized encryption, 267

RBAC (role-based access control), 7778

administrative units and, 23

assigning roles to storage accounts, 234237

configuring in Azure Key Vault, 277278

delegating admin rights, 7980

interpreting role and resource permissions, 81

permissions, 8182

resource group permissions, 80

roles, 78, 8386

scopes, 78

regenerating access keys, 246

registering, apps, 6870

removing, group members, 9

requirements, Azure AD Connect, 50

connectivity, 5051

deployment accounts, 52

SQL server, 51

resources, 203

API management policies, 76

audit history, viewing, 4849

permissions, 81

updating tags, 187

restoring Key Vault items, PowerShell cmdlets, 299

Revoke-AzStorageAccountUserDelegationKeys command, 254

revoking, user delegation SAS, 254

risk policies, 4143

roles, 78

access review, 4547

administrative units and, 23

assigning to applications, 34

built-in, 8386

cloning, 8789

custom, 8689

for passwordless authentication, 44

permissions, 81

PIM (Privileged Identity Management, 2326

verifying, 5

viewing, 7980

routing, 9799

creating custom routes, 99

resource audit history, viewing, 4849

routing table, 9899

rules

alert, 210

Azure Firewall, 121

application, 124125

network, 126

S

SAS (Shared Access Signatures)

account, 255257

configuring, 253254

stored access policies, 257

token parameters, 256

user delegation, 254255

scheduled query rule, creating, 222226

scopes, 78, 240242

secrets

cmdlets for managing, 290

Key Vault, 288291

viewing, 289

Security Alert dashboard, 192195

Security Center, 155, 159, 160

security groups, 6. See also groups

adding and removing members, 9

nested groups, 911

security updates

managing, 162163

VMs, 160162

segmentation, 94

self-service password reset, 6163, 67

serverless compute, AKS (Azure Kubernetes), 166167

isolation, 166167

logical isolation, 166

Microsoft Defender for Cloud and, 168169

nodes, 168

physical isolation, 166

service endpoints, 147148

advantages of, 148149

configuring, 149150

service endpoints, isolating data solutions, 269

service principal, 2

service principals, 23

assigning permissions through roles, 35

authentication, 7677

certificate-based authentication, 77

creating, 3

roles, verifying, 5

Set-AzKeyVaultAccessPolicy cmdlet, 276277

Set-AzStorageAccount cmdlet, 256

Set-AzVmDiskEncryptionExtension cmdlet, 175

shared responsibility model, 91

share-level permissions, configuring, 250251

SharePoint Online, external sharing, 1921

sign-in risk policies, 41

site-to-site VPNs, 111

SQL, Azure AD Connect requirements, 51. See also Azure SQL

storage accounts

access keys, 243

manually rotating, 245246

regenerating, 246

viewing, 244245

assigning RBAC roles, 234237

authentication, SAS (Shared Access Signatures), 253254

Azure-supported, 234

configuring access control, 234237

encryption, 237239

infrastructure, 239240

key management, 239

scopes, 240242

Microsoft Defender for Storage, 242243

stored access policies, 257

subnetting, NSGs (network security groups), 93

subscriptions, API management policies, 76

T

TDE (transparent data encryption), 264266

threat

detection, 190191

for Linux, 191192

for Windows, 191

hunting, 230231

protection, 190

TLS (Transport Layer Security), 140

token parameters, SAS (Shared Access Signatures), 256

U

Update Management, 160163

UPN suffixes, 5960

user accounts. See also permissions

assigning to apps, 7073

Azure AD (Active Directory)

administration tasks, 13

creating, 1213

setting up MFA, 3034

blocking/unblocking, 3738

checking access, 8283

fraud alert settings, 38

managing, 1213

PIM (Privileged Identity Management, 2326

requirements for Azure AD Connect deployment, 52

roles, viewing, 7980

UPN suffixes and, 5960

user delegation SAS

configuring, 254255

revoking, 254

user principals, 2

user-risk policies, 41

utilization reports, MFA (multifactor authentication), 40

V

verifying, service principal roles, 5

viewing

access keys, 244245

alerts, 194195

guest accounts, 18

resource audit history, 4849

roles, 7980

secrets, 289

virtual hubs, Azure Firewall Manager deployment, 130

virtual network gateway, 93

VMs (virtual machines), 93

access control, 159

ADE (Azure Data Encryption), 174175

ASGs (application security groups), 117118

associating with the VM, 119120

creating, 118119

disk encryption, 159

endpoint protection, 155158

security updates, 160162

threat detection, 159

Update Management, 160163

vulnerability assessment, 195197

VNets (virtual networks), 9293

configuring, 9496

creating, 97

Key Vault, 279281

NAT (network address translation), 102105

NSGs (network security groups), 111112

creating, 114117

inbound rules, 113

outbound rules, 113114

peering, 94, 99102

private endpoints, 150151

routing, 9799

routing table, 9899

segmentation, 94

service endpoints, 147148

advantages of, 148149

configuring, 149150

service endpoints, isolating data solutions, 269

subnets, 9293

VPNs (virtual private networks), 106

authentication, 107108

point-to-site, 110

site-to-site, 111

types of, 107

vulnerability assessment

for SQL, 198199

for VMs, 195197

W

WAF (web application firewall), 121, 138140

Windows

Hello for Business, 43

Microsoft Defender for Servers, 191

X-Y-Z

X509 certificates

importing, 285286

managing, 281

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
13.59.217.167