Data is protected at rest, in transit.
CORS is supported.
Can control access to data and audit this access
256 bit AES cipher.
VM drives are encrypted with AZ disk encryption which uses bit locker for Win and dm-crypt for linux
Key Vault stores the encryption keys and secrets
ALWAYS use https.
Web apps can only load content from authorized sources.
Can be at the subscription, resource group, storage account or container level.
Storage Analytics logs every operation.
Pass keys in the Authorization header in web requests
2 kinds - primary and secondary. These are full control.
- regenerate periodically
- do not store in config files
SAS is a string w/ a security token that can be added to a URI
Service level - allow access to specific resources Account Level - service level + additional abilities
By default storage accounts accept connections from anyone/anywhere.
Under Storage Account > Networking
Azure Defender for Storage provides an extra layer of security intelligence that detects unusual and potentially harmful attempts to access or exploit storage accounts. Works on blob storage, az files and data lake storage gen2.
Storage account > Settings > Advanced Security > Enable Azure Defender
When problems happen you get an email
Very flexible, and integrated into the analytics tools.
