Azure Security
Azure Security
SECURITY
OVERVIEW
Tom Quinn
Azure Security Specialist, Microsoft
Microsoft Azure
Security and Compliance
Discussion
Tom Quinn
Azure Security Specialist
Topics
Microsoft and Security
Shared Responsibility
How does Microsoft Secure the Platform
Azure Regions Azure Gov Cloud
Securing Customer environment
Data Security
Encryption
Identity
Network Security
Network isolation
First party and third party controls
Hybrid Cloud - VPN and Express Route Connectivity
Logging, Monitoring, and Operations
Azure Security Center and OMS
Partner Security Solutions
Microsoft Azure
Microsoft industry leading security
capabilities
Visibility Context
Experience Expertise
Client endpoints
Application
Network controls
Operating system
Physical hosts
Cloud service provider responsibility
Physical network
Physical datacenter
Tenant responsibility
Microsoft Customer
Microsoft Cloud Security Practices
Dedicated security expert Global, 24x7 incident
Microsoft makes security a priority at every step, red team that simulate
real-world attacks at
response service that
works to mitigate the
from code development to incident response. network, platform, and effects of attacks and
malicious activity.
application layers, testing
the ability of Azure to
Focus on Identity detect, protect against, and
Controls and tools recover from breaches.
including mitigation of
Extensive threat internal threat
intelligence gathering, throughout stack
modelling, analysis and including operations. Incident
Company-wide,
controls incorporated Response
mandatory development
into systems. Assume
process that embeds Breach
Defense in Depth
security into every phase Simulation
of development process.
Approach across all
cloud services from Identity and Access
Physical to app/data
layers.
Threat Intelligence
Security Development
Lifecycle (SDL)
Defense in Depth
Achieve global scale, in local regions
Trust
42
Azure regions
Scale:
More than 25 trillion stored objects
2.5+ Million requests/sec on average
Networks
Can apply security controls
Can connect to corpnet via DNS Server
Isolated Virtual Networks
VPN or Express Route Isolated Virtual Network
Microsoft Azure
Platform Network Control
Network Security Groups (NSG)
Grouping of network traffic rules as Internet
security group
Microsoft Azure
Azure
What Example
Service Internet
http://news.com
Cross-region
Traffic apac.news.com
redirection & Azure Traffic Manager (DNS Load Balancer)
Manager emea.news.com
availability
us.news.com
In-region emea.news.com
Azure Load AppGw1
scalability &
Balancer AppGw2
availability AppGw2
Application Application Application Application
URL/content- Gateway Gateway Gateway Gateway
Azure news.com/topnews
based routing
Application news.com/sports
& load
Gateway news.com/images VM VM VM VM VM VM VM VM
balancing
Private
WAN
Monitoring & logging
Microsoft Azure
Enable Monitoring Agent
AZURE:
Customer VMs
Performs monitoring & alerting on
security events for the platform
Portal
Guest VM Guest VM Cloud Services
Enables security data collection via
SMAPI
Azure
Monitoring Agent or Windows Event
Event
s Storage HDInsight Forwarding
Customer
Admin Extract event information to SIEM
or other Reporting System
CUSTOMER:
reporting
2002 Machine2 Signature Updated Successfully
4 04/29/2014
Microsoft Azure 20
Azure Security Center
What is the feature?
Prevent, detect and respond to threats with increased visibility
and control over the security of your Azure resources and
advanced analytics, which identify attacks that might otherwise
go unnoticed
Benefits
Understand the security state of Azure resources Automatic Log
Take control of cloud security with policies that enable you to
Collection
recommend and monitor security configurations
Make it easy for DevOps to deploy integrated Microsoft and partner
security solutions
Find threats with advanced analysis of your security-related events
developed using Microsofts vast global intelligence assets and expertise
Respond and recover from incidents faster with real-time security alerts Rome Analytics Engine
Export security events to a SIEM for further analysis Analyzes Windows Security
Events, IIS Logs, AV Logs,
Firewall Logs, Syslog,
Operations Management Suite
Log analytics
Near real time perf. data collection/monitoring Operations
Linux agents including monitoring integrations Management
Mobile Apps in Windows, Android and iOS Suite Windows Windows Linux Linux Linux
Custom fields Server
(VM)
Server
(VM) (VM) (VM) (VM)
SOC1 and SOC2 Type 1 Compliant
Amazon Web
Services
Backup & disaster recovery
Backup >1.6TB support
ASR integration with SQL Always-On public preview
ASR CSP and IaaS V2 support
IaaS v1 & v2 VMs backup
Azure backup server for application workload backups Windows Windows Windows Windows Linux
Server Server Server Server
IT automation (VM) (VM) (VM) (VM) (VM)
Automation DSC
Private clouds
(Azure Stack, Hyper-V, VMware,
Source Control support through GitHub for runbooks OpenStack)
Hybrid support for schedules / test jobs
PowerShell script support on hybrid workers
Linux DSC support
Security & compliance