Index

A

access control

with Azure Conditional Access, 220221

RBAC (role-based access control), 223227

resource locks, 232235

ACI (Azure Container Instances), 5658

action groups, 168169

actions, 123, 168169

Active Directory. See Azure Active Directory

agility of cloud services, 46

AI (artificial intelligence), 107110

AKS (Azure Kubernetes Service), 5859

alerts in Azure Monitor, 165169

analytics. See data analytics

Apache Spark, 97

API types, 6768

App Service. See Azure App Service

application failures, 3

Application Insights, 3

architectural components, 2642

ARM (Azure Resource Manager), 3842

availability zones, 2831

management groups, 3738

regions, 2628

resource groups, 3133

subscriptions, 3337

ARM (Azure Resource Manager), 3842

Azure portal and, 140

benefits of, 41

RBAC (role-based access control) and, 226

ARM API, 39

ARM templates, 31, 33, 4041, 74, 237

artifacts, 133, 135, 237

Artifical General Intelligence (strong AI), 107

Artifical Narrow Intelligence (weak AI), 107

artificial intelligence (AI), 107110

assignments with Azure Conditional Access, 220

authentication, 214

Azure Active Directory, 214220

MFA (multifactor authentication), 221223

RBAC (role-based access control), 223227

authorization, 214

Azure Active Directory, 214220

Azure Conditional Access, 220221

RBAC (role-based access control), 223227

Auto-Scale, 6

availability

of cloud services, 24. See also fault tolerance

with ExpressRoute, 64

availability sets, 30, 4851

availability zones, 2831

Azure

architectural components, 2642

ARM (Azure Resource Manager), 3842

availability zones, 2831

management groups, 3738

regions, 2628

resource groups, 3133

subscriptions, 3337

core solutions, 82139

Azure Bot Service, 112114

Azure Databricks, 100107

Azure DevOps, 130133

Azure DevTest Labs, 133139

Azure Functions, 115122

Azure Machine Learning, 110111

Azure Sphere, 9596

Azure Synapse, 9698

Cognitive Services, 111112

Event Grid, 129130

HDInsight, 98100

IoT Central, 8795

IoT Hub, 8287

Logic Apps, 123128

serverless computing, 114115

cost management, 253264

Azure Cost Management, 261264

factors affecting costs, 254255

pricing calculator, 256257

total cost of ownership calculator, 258261

governance features, 227242

Azure Blueprints, 237242

Azure Policy, 228232

resource locks, 232235

tags, 236

identity services, 213227

authentication and authorization, 214

Azure Active Directory, 214220

Azure Conditional Access, 220221

MFA (multifactor authentication), 221223

RBAC (role-based access control), 223227

management tools, 139172

Azure Advisor, 159161

Azure CLI, 150152

Azure Cloud Shell, 152156

Azure mobile app, 156159

Azure Monitor, 161169

Azure portal, 140147

Azure PowerShell, 148150

Azure Service Health, 170172

network security, 194209

Azure Firewall, 200207

DDoS Protection, 207209

defense in depth, 194195

NSGs (Network Security Groups), 195200

privacy and compliance resources, 242248

Azure soveriegn regions, 247248

Cloud Adoption Framework for Azure, 244

Microsoft privacy statement, 243244

STP (Service Trust Portal), 245247

Trust Center, 244

security features, 179194

Azure Security Center, 180184

Azure Sentinel, 188194

Key Vault, 184188

service lifecycle, 269271

SLAs (service-level agreements), 264269

workload products, 4275

ACI (Azure Container Instances), 5658

AKS (Azure Kubernetes Service), 5859

Azure App Service, 5255

Azure Database for MySQL, 72

Azure Database for PostgreSQL, 72

Azure Files, 6566

Azure Marketplace, 7275

Azure SQL Database, 6871

container (blob) storage, 64

Cosmos DB, 6668

disk storage, 6465

ExpressRoute, 6364

storage tiers, 66

virtual networks (VNets), 6163

VMs (virtual machines), 4252

Windows Virtual Desktop, 6061

Azure Active Directory, 142, 214220

Azure AD B2B, 216, 219

Azure AD B2C, 219

Azure Advisor, 159161

Azure App Service, 13, 5255

plans, 5254

web apps, 5455

Azure Artifacts, 131, 133

Azure Bastion, 203

Azure blog, 29

Azure Blueprints, 237242

Azure Boards, 131, 132

Azure Bot Service, 112114

Azure China, 248

Azure CLI, 150152

Azure Cloud Shell, 141, 152156

Azure Conditional Access, 220221

Azure Container Instances (ACI), 5658

Azure Cost Management, 261264

Azure Data Lake Storage, 98

Azure Database for MySQL, 72

Azure Database for PostgreSQL, 72

Azure Database Migration Service (DMS), 71

Azure Databricks, 100107

Azure DevOps, 130133

Azure DevTest Labs, 133139

Azure File Sync, 66

Azure Files, 6566

Azure Firewall, 200207

Azure Functions, 115122

Azure Germany, 248

Azure Government, 247248

Azure Kubernetes Service (AKS), 5859

Azure Log Analytics, 189

Azure Machine Learning, 110111

Azure Marketplace, 7275

Azure mobile app, 156159

Azure Monitor, 161169

Azure Pipelines, 131, 133

Azure Policy, 228232

Azure portal, 140147

Azure PowerShell, 148150

Azure Repos, 131, 132133

Azure Resource Manager. See ARM (Azure Resource Manager)

Azure Security Center, 180184

Azure Sentinel, 188194

Azure Service Health, 170172

Azure Sphere, 9596

Azure SQL Database, 6871

Azure Stack, 20

Azure Status page, 30

Azure Storage

Azure Files and, 65

container (blob) storage, 64

Azure Synapse, 9698

Azure Synapse Studio, 98

Azure Test Plans, 131, 133

B

BCDR (Business Continuity and Disaster Recovery) plans, 7

beta offerings, 269270

big data, 97

billing zones, 255

blob storage, 64

blueprints, 237242

Bot Service. See Azure Bot Service

C

C2D (cloud-to-device) messaging, 84

“castle approach” (defense in depth), 194195

channels in Azure Bot Service, 114

chat services with Azure Bot Service, 112114

Clarke, Arthur C.107

Cloud Adoption Framework for Azure, 244

cloud computing, defined, 17

cloud model, 8, 16

hybrid cloud, 1920

private cloud, 1819

public cloud, 1718

cloud services

benefits of, 18

economic benefits, 78

fault tolerance, disaster recovery, 67

high availability, 24

scalability, elasticity, agility, 46

service type comparison, 1516

shared responsibility model, 9

Cloud Shell, 141, 152156

cloud-to-device (C2D) messaging, 84

Cloudyn, 262

clusters

in Azure Databricks, 102

in Azure Synapse, 97

in HDInsight, 98100

Cognitive Services, 111112

column NoSQL database systems, 67

commands

in Azure CLI, 150152

in Azure Cloud Shell, 152156

in PowerShell Az module, 149150

community cloud model, 16

compliance, 242248

Azure soveriegn regions, 247248

Cloud Adoption Framework for Azure, 244

disaster recovery and, 7

Microsoft privacy statement, 243244

STP (Service Trust Portal), 245247

Trust Center, 244

Compliance Manager, 245247

composite SLAs, 268269

compute nodes, 97

Computer Vision, 112

Conditional Access, 220221

connectors, 123, 189192

consumption-based model, 8

containers

in AKS, 5859

blob storage, 64

explained, 56

running, 5658

core solutions, 82139

Azure Bot Service, 112114

Azure Databricks, 100107

Azure DevOps, 130133

Azure DevTest Labs, 133139

Azure Functions, 115122

Azure Machine Learning, 110111

Azure Sphere, 9596

Azure Synapse, 9698

Cognitive Services, 111112

Event Grid, 129130

HDInsight, 98100

IoT Central, 8795

IoT Hub, 8287

Logic Apps, 123128

serverless computing, 114115

Cosmos DB, 6668

cost management, 253264

Azure Cost Management, 261264

factors affecting costs, 254255

pricing calculator, 256257

total cost of ownership calculator, 258261

costs. See also pricing tiers

Azure App Service, 5254

factors affecting, 254255

viewing, 33, 35

VM billing, 48

custom images, 51, 136137

D

D2C (device-to-cloud) messaging, 84

dashboard (in portal)

creating new, 146147

customizing, 146

data analytics

with Azure Synapse, 9698

with HDInsight, 99

Data Box, 64

data lakes, 98

data modeling, 100

Data Movement Service (DMS), 97

data warehouses, 98

database API types, 6768

Database Migration Service (DMS), 71

Database Transaction Unit (DTU), 70

Databricks, 100107

Databricks ML Model Export, 107

Databricks Runtime ML (Databricks Runtime for Machine Learning), 105106

datacenters, 2728

datasets in Azure Databricks, 104

DDoS (distributed denial of service) attacks, 207209

DDoS Protection, 207209

decision APIs, 112

declarative syntax, 40

defense in depth, 194195

deleting resources, 33

desktop virtualization with Windows Virtual Desktop, 6061

device groups in IoT Central, 9395

Device Provisioning Service (DPS), 85

device twins, 84

device-to-cloud (D2C) messaging, 84

DevTest Labs, 133139

Direct Line, 114

directory roles, 214

disaster recovery, 67

in availability zones, 2829

in regions, 2728

disk encryption keys, 187188

disk storage, 6465

distributed denial of service (DDoS) attacks, 207209

DMS (Data Movement Service), 97

DMS (Database Migration Service), 71

Docker, 13, 56

document NoSQL database systems, 67

DoD Impact Level 5 Provisional Authorization, 248

DPS (Device Provisioning Service), 85

DTU (Database Transaction Unit), 70

E

economic benefits of cloud services, 78

edge devices, 63

effects in Azure Policy, 232

elastic pools, 7071

elasticity of cloud services, 46

encryption with Key Vault, 184188

Event Grid, 129130

ExpressRoute, 6364

F

fault domains, 4849

fault tolerance, 67

FIPS (Federal Information Processing Standard) 140, 185

firewalls, 200207

flow record for NSGs, 199

formulas, 136138

Function Apps, 115119, 127

functions

creating, 120121

defined, 118

G

GDPR (General Data Protection Regulation), 243

general availability, 269, 271

geographies, 26, 27

governance, 227242

Azure Blueprints, 237242

Azure Policy, 228232

resource locks, 232235

tags, 236

graph NoSQL database systems, 67

guest users, 216

H

Hadoop, 98

HBase, 98

HDInsight, 98100

high availability

of cloud services, 24. See also fault tolerance

with ExpressRoute, 64

horizontal scaling, 5

HSMs (hardware security modules), 184185

HttpTrigger functions, 122

hub-and-spoke configuration for firewalls, 201202

hybrid cloud model, 16, 1920

I

IaaS (Infrastructure-as-a-Service), 911, 15

identities, 214

identity services, 213227

authentication and authorization, 214

Azure Active Directory, 214220

Azure Conditional Access, 220221

MFA (multifactor authentication), 221223

RBAC (role-based access control), 223227

images, 56

inbound rules for NSGs, 197199

Infrastructure-as-a-Service (IaaS), 911, 15

initiatives, 229

installing

PowerShell Az module, 148

PowerShell on Linux or macOS, 148

Interactive Query, 98

Internet, public cloud model and, 17

invoices, viewing, 35

IoT (Internet of Things)

Azure Sphere, 9596

IoT Central, 8795

IoT Hub, 8287

IoT Central, 8795

IoT Hub, 8287

IP addresses, public, 62

ISO 27001 standard, 243

J

JIT (just-in-time) access, 181184

jobs in IoT Central, 94

jumpboxes, 201

K

Kafka, 98

Key Vault, 184188

keyboard shortcuts in Azure Databricks, 104

key-value NoSQL database systems, 67

Kubernetes, 5859

L

language APIs, 112

lifecycle of services, 269271

limits on subscriptions, 34

locks, 232235

Log Analytics, 189

Logic Apps, 123128, 193

M

machine learning

in Azure Databricks, 100107

with Azure Machine Learning, 110111

with Cognitive Services, 111112

explained, 108110

Machine Learning Studio, 110

managed disks, 65

managed identities, 215, 223

managed instances, 71

management groups, 3738

management tools, 139172

Azure Advisor, 159161

Azure CLI, 150152

Azure Cloud Shell, 152156

Azure mobile app, 156159

Azure Monitor, 161169

Azure portal, 140147

Azure PowerShell, 148150

Azure Service Health, 170172

Markdown, 103

meters, 254

MFA (multifactor authentication), 221223

Microsoft privacy statement, 243244

Microsoft Remote Desktop, 158

Microsoft Threat Intelligence, 181

MLeap, 106

mobile app (Azure), 156159

moving resources, 33

MSEE (Microsoft Enterprise Edge routers), 6364

multifactor authentication (MFA), 221223

multitenant environment, 17

MySQL, 72

N

natural-language understanding, 108

network bandwidth pricing, 255

network outages, 23

network security, 194209

Azure Firewall, 200207

DDoS Protection, 207209

defense in depth, 194195

NSGs (Network Security Groups), 195200

Network Security Groups (NSGs), 63, 195200

NIST 800–53 standard, 243

NoSQL databases, 6667

notebooks in Azure Databricks, 103104

O

OAUTH hardware tokens, 223

on-premises model, 7

outbound rules for NSGs, 199

output bindings, 122

P

PaaS (Platform-as-a-Service), 1114, 15

planned maintenance, 48

planning

with Azure Blueprints, 237242

for cost management, 253264

Azure Cost Management, 261264

factors affecting costs, 254255

pricing calculator, 256257

total cost of ownership calculator, 258261

plans in Azure App Service, 5254

Platform-as-a-Service (PaaS), 1114, 15

Playbooks, 193

policies

in Azure DevTest Labs, 139

in Azure Policy, 228232

portal (Azure), 140147

PostgreSQL, 72

Power Automate, 123

power outages, 4

power supplies for datacenters, 2728

PowerShell, installing on Linux or macOS, 148

PowerShell Az module, 148150

preview offerings, 269270

previewing web apps in Azure Cloud Shell, 154155

pricing calculator, 256257

pricing tiers. See also cost management; costs

Azure Active Directory, 219220

for Azure Security Center, 180

DDoS Protection, 208209

for IoT Hub, 8687

network bandwidth, 255

privacy, 242248

Azure soveriegn regions, 247248

Cloud Adoption Framework for Azure, 244

Microsoft privacy statement, 243244

STP (Service Trust Portal), 245247

Trust Center, 244

private cloud model, 16, 1819

private previews, 269270

productionalizing machine-learning pipeline, 106

“Profiles of the Future” (Clarke), 107

proxies, 118

public cloud model, 16, 1718

public IP addresses, 62

public previews, 270

purchasing models for single database, 70

R

R Server, 98

RBAC (role-based access control), 223227

regional pairs, 27

regions

availability zones, 2831

explained, 2628

factors affecting costs, 254

zones for, 255

relational databases, 66

Azure SQL Database, 6871

MySQL, 72

PostgreSQL, 72

SQL Server, 68

reliant system problems, 4

remote access to IaaS VMs, 10

resource groups, 3133

resource locks, 232235

resource providers, 39

resources. See also ARM (Azure Resource Manager)

costs, viewing, 33, 35

deleting, 33

moving, 33

opening in portal, 144

tags, 236

viewing, 142

role assignments, 224226

role-based access control (RBAC), 223227

roles, 224

in IoT Central, 91

route tables for firewalls, 203206

rules

in Azure Policy, 228232

for firewalls, 205207

in IoT Central, 93

for NSGs, 195200

S

SaaS (Software-as-a-Service), 14, 15

scalability of cloud services, 46

fault tolerance versus, 6

scale sets, 5152

scope, 224

security, 179194

Azure Security Center, 180184

Azure Sentinel, 188194

with Azure Sphere, 9596

identity services

authentication and authorization, 214

Azure Active Directory, 214220

Azure Conditional Access, 220221

MFA (multifactor authentication), 221223

RBAC (role-based access control), 223227

Key Vault, 184188

network security, 194209

Azure Firewall, 200207

DDoS Protection, 207209

defense in depth, 194195

NSGs (Network Security Groups), 195200

resource locks, 232235

Trust Center, 244

security principals, 223, 227

Sentinel, 188194

serverless computing, 114115

service dependencies, 41

service lifecycle, 269271

service principals, 215, 218, 227

service tags for NSGs, 199200

Service Trust Portal (STP), 245247

service-level agreements (SLAs), 2, 264269

“Seven Properties of Highly Secured Devices” (Microsoft white paper), 95

shared responsibility model, 9, 243

SIEM (Security Information and Event Management), 188

signing in to PowerShell Az module, 148149

simulated devices in IoT Central, 90

single databases, 70

single sign-on (SSO), 218

single-tenant environment, 18

SLAs (service-level agreements), 2, 264269

slots, 118

SOAR (Security Orchestration, Automation, and Response), 188

Software-as-a-Service (SaaS), 14, 15

Spark, 98

speech APIs, 112

spoke networks, 201

SQL Data Warehouse, 97

SQL Server, 68

SSO (single sign-on), 218

stateful firewalls, 201

storage tiers, 66

Storm, 98

STP (Service Trust Portal), 245247

strong AI, 107

subscription IDs, 37

subscriptions, 3337

creating, 3637, 43

limits on, 34

management groups, 3738

setting active, 149

types of, 37

Synapse SQL, 97

system outages, 34

T

tags, 236

TCO (total cost of ownership) calculator, 258261

testing with Azure DevTest Labs, 133139

threat intelligence in Azure Firewall, 207

tiers. See pricing tiers

triggers, 121122, 123

Trust Center, 244

U

unexpected downtime, 48

unmanaged disks, 65

unplanned maintenance, 48

update domains, 49

user principals, 227

V

vCore (virtual core), 70

vertical scaling, 5

Video Indexer, 112

viewing

costs, 33, 35

invoices, 35

resources, 142

tags, 236

virtual networks (VNets), 6163

virtual private networks (VPNs), 63

Visual Studio, 39

VMs (virtual machines), 34, 4252

availability sets, 4851

in Azure DevTest Labs, 133139

billing, 48

connecting via Azure mobile app, 158

creating, 4345

deploying, 4546

disk encryption keys, 187188

disk storage, 6465

downtime, 48

JIT access, 181184

scale sets, 5152

VNets (virtual networks), 6163

VPNs (virtual private networks), 63

W

weak AI, 107

web apps

in Azure App Service, 5455

previewing in Azure Cloud Shell, 154155

webhooks, 122

Windows 10 Multi-User, 61

Windows Active Directory, 214

Windows Virtual Desktop (WVD), 6061

workflows in Logic Apps, 123, 128

workload products, 4275

ACI (Azure Container Instances), 5658

AKS (Azure Kubernetes Service), 5859

Azure App Service, 5255

Azure Database for MySQL, 72

Azure Database for PostgreSQL, 72

Azure Files, 6566

Azure Marketplace, 7275

Azure SQL Database, 6871

container (blob) storage, 64

Cosmos DB, 6668

disk storage, 6465

ExpressRoute, 6364

storage tiers, 66

virtual networks (VNets), 6163

VMs (virtual machines), 4252

Windows Virtual Desktop, 6061

Z

zonal services, 30

zone redundant services, 31

zones, regions in, 255

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
13.59.199.250