0% found this document useful (0 votes)
18 views21 pages

Microsoft Compliance and Security Tools

The document provides an overview of various Microsoft services, including Compliance Manager, Azure Monitor, and Azure Security Center, detailing their functionalities and purposes. It highlights tools for compliance, monitoring, security management, and application development, along with links for further information. Each service is designed to enhance organizational efficiency, security, and compliance in cloud environments.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
18 views21 pages

Microsoft Compliance and Security Tools

The document provides an overview of various Microsoft services, including Compliance Manager, Azure Monitor, and Azure Security Center, detailing their functionalities and purposes. It highlights tools for compliance, monitoring, security management, and application development, along with links for further information. Each service is designed to enhance organizational efficiency, security, and compliance in cloud environments.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

SERVICE DESCRIPTION URL

Compliance Manager This is a great tool that helps you achieve compliance. It creates [Link]
assessments for different Microsoft services. It shows how compliant
your organization is and how compliant Microsoft is for a particular
area.

Example:
Here’s a GDPR assessment for Office 365. You’ll notice that Microsoft
Managed Actions is at 100%, which is always the case. In this example,
Customer Managed Actions is at 0%.

To find out how to move your organization into compliance, you can
click on the assessment, and it will bring up a list of steps to complete.
In most cases, you’ll need to upload evidence of your compliance.

The main value of the Compliance Manager is that it helps you


organize and track your compliance efforts.
Service Trust Portal The Service Trust Portal is focused specifically on compliance. For [Link]
example, it has links to Azure audit reports for regulatory standards
like SOC, FedRAMP, and ISO27001. These will be helpful if your
organization is going through these compliance audits. There’s also a
link to a site called “Compliance Manager”.
Azure Resource Monitor Azure Monitor is a full stack monitoring service in Azure that provides [Link]
a complete set of features to monitor your Azure resources in addition essentials/monitor-azure-resource
to resources in other clouds and on-premises.

The Azure Monitor data platform collects data into logs and metrics
where they can be analyzed together using a complete set of
monitoring tools.

As soon as you create an Azure resource, Azure Monitor is enabled and


starts collecting metrics and activity logs which you can view and
analyze in the Azure portal.

With some configuration, you can gather additional monitoring data


and enable additional features.
Azure Government If you’re involved in cloud solutions for the US government, then be [Link]
aware that Microsoft provides Azure Government services that are in government/
physically isolated data centers and networks.

Azure Government is available to US government agencies at the


federal, state, and local levels, as well as to their partners.

To use these services, your organization has to meet eligibility


requirements.
Trust Center The Trust Center contains a collection of links to resources about how [Link]
Microsoft handles security, privacy, compliance, and transparency.
Azure Portal The Azure portal is a web-based, unified console that provides an [Link]
alternative to command-line tools. With the Azure portal, you can
manage your Azure subscription using a graphical user interface.

You can build, manage, and monitor everything from simple web apps
to complex cloud deployments. Create custom dashboards for an
organized view of resources. Configure accessibility options for an
optimal experience.

The Azure portal is designed for resiliency and continuous availability.


It has a presence in every Azure datacenter. This configuration makes
the Azure portal resilient to individual datacenter failures and avoids
network slow-downs by being close to users.

The Azure portal updates continuously and requires no downtime for


maintenance activities.
Security Center Azure Security Center is a unified infrastructure security management [Link]
system that strengthens the security posture of your data centers, and
provides advanced threat protection across your hybrid workloads in
the cloud - whether they're in Azure or not - as well as on premises.

Keeping your resources safe is a joint effort between your cloud


provider, Azure, and you, the customer. You have to make sure your
workloads are secure as you move to the cloud, and at the same time,
when you move to IaaS (infrastructure as a service) there is more
customer responsibility than there was in PaaS (platform as a service),
and SaaS (software as a service).

Azure Security Center provides you the tools needed to harden your
network, secure your services and make sure you're on top of your
security posture.

Azure Security Center addresses the three most urgent security


challenges:

 Rapidly changing workloads – It's both a strength and a


challenge of the cloud. On the one hand, end users are
empowered to do more. On the other, how do you make sure
that the ever-changing services people are using and creating
are up to your security standards and follow security best
practices?

 Increasingly sophisticated attacks - Wherever you run your


workloads, the attacks keep getting more sophisticated. You
have to secure your public cloud workloads, which are, in
effect, an Internet facing workload that can leave you even
more vulnerable if you don't follow security best practices.

 Security skills are in short supply - The number of security


alerts and alerting systems far outnumbers the number of
administrators with the necessary background and experience
to make sure your environments are protected. Staying up-to-
date with the latest attacks is a constant challenge, making it
impossible to stay in place while the world of security is an
ever-changing front.

To help you protect yourself against these challenges, Security Center


provides you with the tools to:

 Strengthen security posture: Security Center assesses your


environment and enables you to understand the status of your
resources, and whether they are secure.

 Protect against threats: Security Center assesses your


workloads and raises threat prevention recommendations and
security alerts.
 Get secure faster: In Security Center, everything is done in
cloud speed. Because it is natively integrated, deployment of
Security Center is easy, providing you with auto-provisioning
and protection with Azure services.

Advanced Threat Most hacker attacks are intended to get inside your system, rather [Link]
Protection than take them down.
Azure ATP monitors user activities and looks for anomalies.

Example:
If an attacker seizes control of a user account, they’ll probably try to
gain access to internal resources or other accounts. ATP can spot this
sort of activity and alert administrators.
Azure Information AIP lets you label information as confidential, either manually or using [Link]
Protection rules you create.

You can configure AIP to prevent people from inadvertently sending


confidential information.

Azure Information Protection is used to automatically add a watermark


to Microsoft Word documents that contain credit card information.

You use Azure Information Protection labels to apply classification to


documents and emails. When you do this, the classification is
identifiable regardless of where the data is stored or with whom it’s
shared. The labels can include visual markings such as a header, footer,
or watermark.

Labels can be applied automatically by administrators who define rules


and conditions, manually by users, or a combination where users are
given recommendations. In this question, we would configure a label
to be automatically applied to Microsoft Word documents that contain
credit card information. The label would then add the watermark to
the documents.

Example:
If someone attaches a confidential document to an email and then
tries to send that email to a person outside the company, AIP can stop
the email from being sent.
Azure Policy Service Enforces a wide variety of governance policies. [Link]

Example:
Suppose your company has a European division that is legally required
to store its data only in European data centers.

You could create a policy that only allows SQL Database instances to
be created in European regions and assign that policy to the resource
group for that division of the company.
Initiative Allows to group related policies and then assign that initiative to [Link]
various subscriptions, resource groups, and management groups. concepts/initiative-definition-structure

Example:
Suppose you need to assign the same policies to a number of different
resource groups or subscriptions.
Microsoft Privacy The Microsoft Privacy Statement “explains the personal data Microsoft [Link]
Statement processes, how Microsoft processes it, and for what purposes.” This
actually applies to all of Microsoft’s services, not just Azure.
Subscription Agreement This Microsoft Online Subscription Agreement is between the entity [Link]
for Microsoft Azure you represent, or, if you do not designate an entity in connection with agreement/
a Subscription purchase or renewal, you individually ("you" or "your"),
and Microsoft Corporation ("Microsoft", "we", "us", or "our").

It consists of the terms and conditions below, as well as the Online


Services Terms, the SLAs, and the Offer Details for your Subscription or
renewal (together, the "agreement").

It is effective on the date we provide you with confirmation of your


Subscription or the date on which your Subscription is renewed, as
applicable.
Microsoft Online Service Service-level agreements (SLAs) describe Microsoft’s commitments for [Link]
Level Agreement (SLA) uptime and connectivity. [Link]

Microsoft Online Service [Link]


Terms Mode=3&DocumentTypeId=46&ShowArchived=true
[Link]
DocumentId=17717
Azure AD Role Azure AD roles are used to manage Azure AD resources in a directory [Link]
such as create or edit users, assign administrative roles to others, reset control/rbac-and-directory-admin-roles#azure-ad-roles
user passwords, manage user licenses, and manage domains.
Azure AD Group Azure Active Directory (Azure AD) lets you use groups to manage [Link]
access to your cloud-based apps, on-premises apps, and your fundamentals/active-directory-manage-groups
resources.

Your resources can be part of the Azure AD organization, such as


permissions to manage objects through roles in Azure AD, or external
to the organization, such as for Software as a Service (SaaS) apps,
Azure services, SharePoint sites, and on-premises resources.
Azure App Service Plans In App Service (Web Apps, API Apps, or Mobile Apps), an app always [Link]
runs in an App Service plan. In addition, Azure Functions also has the hosting-plans
option of running in an App Service plan.

An App Service plan defines a set of compute resources for a web app
to run. These compute resources are analogous to the server farm in
conventional web hosting. One or more apps can be configured to run
on the same computing resources (or in the same App Service plan).

When you create an App Service plan in a certain region (for example,
West Europe), a set of compute resources is created for that plan in
that region. Whatever apps you put into this App Service plan run on
these compute resources as defined by your App Service plan.

Each App Service plan defines:

 Region (West US, East US, etc.)


 Number of VM instances
 Size of VM instances (Small, Medium, Large)
 Pricing tier (Free, Shared, Basic, Standard, Premium,
PremiumV2, PremiumV3, Isolated)
Management Groups Management groups are containers that help you manage access, [Link]
policy, and compliance across multiple subscriptions. groups/overview

Create these containers to build an effective and efficient hierarchy


that can be used with Azure Policy and Azure Role Based Access
Controls.

If your organization has many subscriptions, you may need a way to


efficiently manage access, policies, and compliance for those
subscriptions.

Azure management groups provide a level of scope above


subscriptions. You organize subscriptions into containers called
"management groups" and apply your governance conditions to the
management groups.

All subscriptions within a management group automatically inherit the


conditions applied to the management group. Management groups
give you enterprise-grade management at a large scale no matter what
type of subscriptions you might have. All subscriptions within a single
management group must trust the same Azure Active Directory tenant.

For example, you can apply policies to a management group that limits
the regions available for virtual machine (VM) creation. This policy
would be applied to all management groups, subscriptions, and
resources under that management group by only allowing VMs to be
created in that region.
Local Network Gateway The local network gateway is a specific object that represents your on- [Link]
premises location (the site) for routing purposes. You give the site a to-site-portal#LocalNetworkGateway
name by which Azure can refer to it, then specify the IP address of the
on-premises VPN device to which you will create a connection.
Azure Service Bus Azure Service Bus is a messaging service on cloud used to connect any [Link]
applications, devices, and services running in the cloud to any other service-bus-messaging-overview
applications or services. As a result, it acts as a messaging backbone for
applications available in the cloud or across any devices.

Microsoft Azure Service Bus is a fully managed enterprise message


broker with message queues and publish-subscribe topics. Service Bus
is used to decouple applications and services from each other,
providing the following benefits:

 Load-balancing work across competing workers


 Safely routing and transferring data and control across service
and application boundaries
 Coordinating transactional work that requires a high-degree of
reliability
Route Filter A route filter is a new resource that lets you select the list of services [Link]
you plan to consume through Microsoft peering. ExpressRoute routers routefilter-portal
only send the list of prefixes that belong to the services identified in
the route filter.

You must have an active ExpressRoute circuit that has Microsoft


peering provisioned.
Azure Event Hubs Azure Event Hubs is a big data streaming platform and event ingestion [Link]
service. It can receive and process millions of events per second. Data
sent to an event hub can be transformed and stored by using any real-
time analytics provider or batching/storage adapters.

Azure Event Hubs can be used to ingest, buffer, store, and process your
stream in real time to get actionable insights. Event Hubs uses a
partitioned consumer model, enabling multiple applications to process
the stream concurrently and letting you control the speed of
processing.

Azure Event Hubs can be used to capture your data in near-real time in
an Azure Blob storage or Azure Data Lake Storage long-term retention
or micro-batch processing.
Azure Site Recovery Azure Site Recovery helps ensure business continuity by keeping [Link]
business apps and workloads running during outages. Site Recovery overview
replicates workloads running on physical and virtual machines (VMs)
from a primary site to a secondary location.
PowerApps Portal PowerApps lets you quickly build business applications with little or no [Link]
code. It is not used to create Azure virtual machines. Therefore, this portals-powerful-low-code-websites-for-external-users/
solution does not meet the goal.

PowerApps Portals allow organizations to create websites which can


be shared with users external to their organization either anonymously
or through the login provider of their choice like LinkedIn, Microsoft
Account, other commercial login providers.
Azure AD Privileged Privileged Identity Management (PIM) is a service in Azure Active [Link]
Identity Management Directory (Azure AD) that enables you to manage, control, and monitor identity-management/pim-configure
access to important resources in your organization.

These resources include resources in Azure AD, Azure, and other


Microsoft Online Services such as Microsoft 365 or Microsoft Intune.

Privileged Identity Management provides time-based and approval-


based role activation to mitigate the risks of excessive, unnecessary, or
misused access permissions on resources that you care about. Here
are some of the key features of Privileged Identity Management:

 Provide just-in-time privileged access to Azure AD and Azure


resources
 Assign time-bound access to resources using start and end
dates
 Require approval to activate privileged roles
 Enforce multi-factor authentication to activate any role
 Use justification to understand why users activate
 Get notifications when privileged roles are activated
 Conduct access reviews to ensure users still need roles
 Download audit history for internal or external audit
Azure AD Identity Identity Protection is a tool that allows organizations to accomplish [Link]
Protection three key tasks: protection/overview-identity-protection

 Automate the detection and remediation of identity-based


risks.
 Investigate risks using data in the portal.
 Export risk detection data to third-party utilities for further
analysis.
Azure AD Connect Azure AD Connect is the Microsoft tool designed to meet and [Link]
accomplish your hybrid identity goals. It provides the following whatis-azure-ad-connect
features:

 Password hash synchronization - A sign-in method that


synchronizes a hash of a users on-premises AD password with
Azure AD.
 Pass-through authentication - A sign-in method that allows
users to use the same password on-premises and in the cloud,
but doesn't require the additional infrastructure of a federated
environment.
 Federation integration - Federation is an optional part of
Azure AD Connect and can be used to configure a hybrid
environment using an on-premises AD FS infrastructure. It also
provides AD FS management capabilities such as certificate
renewal and additional AD FS server deployments.
 Synchronization - Responsible for creating users, groups, and
other objects. As well as, making sure identity information for
your on-premises users and groups is matching the cloud. This
synchronization also includes password hashes.
 Health Monitoring - Azure AD Connect Health can provide
robust monitoring and provide a central location in the Azure
portal to view this activity.
Azure AD Connect Azure Active Directory (Azure AD) Connect Health provides robust [Link]
Health monitoring of your on-premises identity infrastructure. It enables you whatis-azure-ad-connect#what-is-azure-ad-connect-health
to maintain a reliable connection to Microsoft 365 and Microsoft
Online Services. This reliability is achieved by providing monitoring
capabilities for your key identity components. Also, it makes the key
data points about these components easily accessible.

The information is presented in the Azure AD Connect Health portal.


Use the Azure AD Connect Health portal to view alerts, performance
monitoring, usage analytics, and other information. Azure AD Connect
Health enables the single lens of health for your key identity
components in one place.
Azure Cost Management Azure customers with an Azure Enterprise Agreement (EA), Microsoft [Link]
Customer Agreement (MCA), or Microsoft Partner Agreement (MPA) overview-cost-mgt
can use Azure Cost Management.

Cost management is the process of effectively planning and controlling


costs involved in your business. Cost management tasks are normally
performed by finance, management, and app teams. Azure Cost
Management + Billing helps organizations plan with cost in mind. It
also helps to analyze costs effectively and take action to optimize cloud
spending.
Regulatory Compliance The Security Center blade from the Azure portal includes the [Link]
Dashboard ‘regulatory compliance dashboard’. dashboard-in-azure-security-center-now-available/
The regulatory compliance dashboard provides insight into your
compliance posture for a set of supported standards and regulations,
based on continuous assessments of your Azure environment.
In the Azure Security Center regulatory compliance blade, you can get
an overview of key portions of your compliance posture with respect
to a set of supported standards. Currently supported standards are
Azure CIS, PCI DSS 3.2, ISO 27001, and SOC TSP.

In the dashboard, you will find your overall compliance score, and the
number of passing versus failing assessments with each standard. You
can now focus your attention on the gaps in compliance for a standard
or regulation that is important to you.
Azure Traffic Manager Azure Traffic Manager is a DNS-based load balancing solution. [Link]
overview
Azure Resource Azure Resource Manager is the deployment and management service [Link]
Manager for Azure. It provides a management layer that enables you to create, manager/management/overview
update, and delete resources in your Azure account. You use
management features, like access control, RBAC, locks, and tags, to
secure and organize your resources after deployment.
To learn about Azure Resource Manager templates (ARM templates),
see the template deployment overview.

Azure Stream Analytics Azure Stream Analytics is a real-time analytics and complex event- [Link]
processing engine that is designed to analyze and process high analytics-introduction
volumes of fast streaming data from multiple sources simultaneously.

Patterns and relationships can be identified in information extracted


from a number of input sources including devices, sensors,
clickstreams, social media feeds, and applications.

These patterns can be used to trigger actions and initiate workflows


such as creating alerts, feeding information to a reporting tool, or
storing transformed data for later use.

Also, Stream Analytics is available on Azure IoT Edge runtime, enabling


to process data on IoT devices.
The following scenarios are examples of when you can use Azure
Stream Analytics:

 Analyze real-time telemetry streams from IoT devices


 Web logs/clickstream analytics
 Geospatial analytics for fleet management and driverless
vehicles
 Remote monitoring and predictive maintenance of high value
assets
 Real-time analytics on Point of Sale data for inventory control
and anomaly detection

Azure Analysis services Azure Analysis Services is a fully managed platform as a service (PaaS) [Link]
that provides enterprise-grade data models in the cloud. services-overview

Use advanced mashup and modeling features to combine data from


multiple data sources, define metrics, and secure your data in a single,
trusted tabular semantic data model.

The data model provides an easier and faster way for users to perform
ad hoc data analysis using tools like Power BI and Excel.
Azure Resource Lock As an administrator, you can lock a subscription, resource group, or [Link]
resource to prevent other users in your organization from accidentally manager/management/lock-resources
deleting or modifying critical resources. The lock overrides any
permissions the user might have.

You can set the lock level to CanNotDelete or ReadOnly. In the portal,
the locks are called Delete and Read-only respectively.

 CanNotDelete means authorized users can still read and


modify a resource, but they can't delete the resource.
 ReadOnly means authorized users can read a resource, but
they can't delete or update the resource. Applying this lock is
similar to restricting all authorized users to the permissions
granted by the Reader role.

When you apply a lock at a parent scope, all resources within that
scope inherit the same lock. Even resources you add later inherit the
lock from the parent. The most restrictive lock in the inheritance takes
precedence.

Unlike role-based access control, you use management locks to apply a


restriction across all users and roles. To learn about setting
permissions for users and roles, see Azure role-based access control
(Azure RBAC).

Resource Manager locks apply only to operations that happen in the


management plane, which consists of operations sent
to [Link]

The locks don't restrict how resources perform their own functions.
Resource changes are restricted, but resource operations aren't
restricted.

For example, a ReadOnly lock on a SQL Database logical server


prevents you from deleting or modifying the server. It doesn't prevent
you from creating, updating, or deleting data in the databases on that
server.

Data transactions are permitted because those operations aren't sent


to [Link]

Azure Role-Based Access Azure role-based access control (Azure RBAC) is the authorization [Link]
Control (Azure RBAC) system you use to manage access to Azure resources. To grant access, control/overview
you assign roles to users, groups, service principals, or managed
identities at a particular scope.

When you assign roles, you must specify a scope. Scope is the set of
resources the access applies to. In Azure, you can specify a scope at
four levels from broad to narrow: management group,
subscription, resource group, and resource.

It's a best practice to grant security principals the least privilege they
need to perform their job. Avoid assigning broader roles at broader
scopes even if it initially seems more convenient.
By limiting roles and scopes, you limit what resources are at risk if the
security principal is ever compromised.

Personally Identifiable Personally Identifiable information (PII), is any data that can be used [Link]
Information (PII) – Azure used to identify a individuals such as names, driver’s license number, skill-pii-detection
PII Detection Skill SSNs, bank account numbers, passport numbers, email addresses and
more.

Many regulations from GDPR to HIPPA require strict protection of user


privacy.

The Azure PII Detection skill (Currently in Preview) extracts personally


identifiable information from an input text and gives you the option to
mask it from that text in various ways.

This skill uses the machine learning models provided by Text


Analytics in Cognitive Services.
Azure Service Health Microsoft Azure Service Health is your personalized dashboard in the [Link]
Azure portal for receiving notifications, guidance, and technical health-overview/
support when Azure service issues, updates, or planned maintenance
affect your Azure resources.
Azure Activity Log The Activity log is a platform log in Azure that provides insight into [Link]
subscription-level events. This includes such information as when a activity-log
resource is modified or when a virtual machine is started.

You can view the Activity log in the Azure portal or retrieve entries
with PowerShell and CLI.

For additional functionality, you should create a diagnostic setting to


send the Activity log to Azure Monitor Logs, to Azure Event Hubs to
forward outside of Azure, or to Azure Storage for archiving.
Application Security Application security groups enable you to configure network security [Link]
Group (ASG) as a natural extension of an application's structure, allowing you to application-security-groups
group virtual machines and define network security policies based on
those groups.

You can reuse your security policy at scale without manual


maintenance of explicit IP addresses. The platform handles the
complexity of explicit IP addresses and multiple rule sets, allowing you
to focus on your business logic.
Azure Service Fabric Azure Service Fabric is a distributed systems platform that makes it [Link]
easy to package, deploy, and manage scalable and reliable fabric-overview
microservices and containers. Service Fabric also addresses the
significant challenges in developing and managing cloud native
applications.

A key differentiator of Service Fabric is its strong focus on building


stateful services. You can use the Service Fabric programming model or
run containerized stateful services written in any language or code.

You can create Service Fabric clusters anywhere, including Windows


Server and Linux on premises and other public clouds, in addition to
Azure.

Azure Advisor Advisor is a personalized cloud consultant that helps you follow best [Link]
practices to optimize your Azure deployments. It analyzes your
resource configuration and usage telemetry and then recommends
solutions that can help you improve the cost effectiveness,
performance, Reliability (formerly called High availability), and security
of your Azure resources.

With Advisor, you can:


 Get proactive, actionable, and personalized best practices
recommendations.
 Improve the performance, security, and reliability of your
resources, as you identify opportunities to reduce your overall
Azure spend.
 Get recommendations with proposed actions inline.

You can access Advisor through the Azure portal. Sign in to the portal,
locate Advisor in the navigation menu, or search for it in the All
services menu.

The Advisor dashboard displays personalized recommendations for all


your subscriptions. You can apply filters to display recommendations
for specific subscriptions and resource types.

The recommendations are divided into five categories:

 Reliability (formerly called High Availability): To ensure and


improve the continuity of your business-critical applications.
For more information, see Advisor Reliability
recommendations.

 Security: To detect threats and vulnerabilities that might lead


to security breaches. For more information, see Advisor
Security recommendations.

 Performance: To improve the speed of your applications. For


more information, see Advisor Performance
recommendations.

 Cost: To optimize and reduce your overall Azure spending. For


more information, see Advisor Cost recommendations.

 Operational Excellence: To help you achieve process and


workflow efficiency, resource manageability and deployment
best practices. For more information, see Advisor Operational
Excellence recommendations.

Azure Repos Azure Repos is a set of version control tools that you can use to [Link]
manage your code. started/what-is-repos?view=azure-devops

Azure AD Directories Azure Active Directory (Azure AD) is Microsoft’s cloud-based identity [Link]
and access management service, which helps your employees sign in fundamentals/active-directory-whatis
and access resources in:
 External resources, such as Microsoft 365, the Azure portal,
and thousands of other SaaS applications.
 Internal resources, such as apps on your corporate network
and intranet, along with any cloud apps developed by your
own organization. For more information about creating a
tenant for your organization, see Quickstart: Create a new
tenant in Azure Active Directory (Your new tenant represents
your organization and helps you to manage a specific instance
of Microsoft cloud services for your internal and external
users).

Azure Data Factory It is the cloud-based ETL and data integration service that allows you [Link]
to create data-driven workflows for orchestrating data movement and
transforming data at scale.

Using Azure Data Factory, you can create and schedule data-driven
workflows (called pipelines) that can ingest data from disparate data
stores.

You can build complex ETL processes that transform data visually with
data flows or by using compute services such as Azure HDInsight
Hadoop, Azure Databricks, and Azure SQL Database.

Additionally, you can publish your transformed data to data stores


such as Azure Synapse Analytics for business intelligence (BI)
applications to consume.

Ultimately, through Azure Data Factory, raw data can be organized into
meaningful data stores and data lakes for better business decisions.

Azure Notification Hubs Azure Notification Hubs provide an easy-to-use and scaled-out push [Link]
engine that enables you to send notifications to any platform (iOS, notification-hubs-push-notification-overview
Android, Windows, etc.) from any back-end (cloud or on-premises).
Notification Hubs works great for both enterprise and consumer
scenarios.

Here are a few example scenarios:


 Send breaking news notifications to millions with low latency.
 Send location-based coupons to interested user segments.
 Send event-related notifications to users or groups for
media/sports/finance/gaming applications.
 Push promotional contents to applications to engage and
market to customers.
 Notify users of enterprise events such as new messages and
work items.
 Send codes for multi-factor authentication.

Azure Network Watcher Azure Network Watcher provides tools to monitor, diagnose, view [Link]
metrics, and enable or disable logs for resources in an Azure virtual watcher-monitoring-overview
network. Network Watcher is designed to monitor and repair the
network health of IaaS (Infrastructure-as-a-Service) products which
includes Virtual Machines, Virtual Networks, Application Gateways,
Load balancers, etc.

Note: It is not intended for and will not work for PaaS monitoring or
Web analytics.
Virtual Machine Scale Azure virtual machine scale sets let you create and manage a group of [Link]
Set load balanced VMs. The number of VM instances can automatically sets/overview
increase or decrease in response to demand or a defined schedule.

Scale sets provide high availability to your applications, and allow you
to centrally manage, configure, and update a large number of VMs.

With virtual machine scale sets, you can build large-scale services for
areas such as compute, big data, and container workloads.
Azure Event Grid Azure Event Grid allows you to easily build applications with event- [Link]
based architectures. First, select the Azure resource you would like to
subscribe to, and then give the event handler or WebHook endpoint to
send the event to. Event Grid has built-in support for events coming
from Azure services, like storage blobs and resource groups. Event Grid
also has support for your own events, using custom topics.

You can use filters to route specific events to different endpoints,


multicast to multiple endpoints, and make sure your events are
reliably delivered.

Azure Event Grid is deployed to maximize availability by natively


spreading across multiple fault domains in every region, and across
availability zones (in regions that support them).
Azure Multi-Factor There are three types of factors used to authenticate a user request [Link]
Authentication (MFA) via multi-factor authentication (MFA): solutions/protecting-accounts-1
 A knowledge factor - something the user knows.
 A possession factor - something the user owns, such as an
email address, hardware or software key/token or mobile
device.
 An inheritance factor - something that confirms identity via a
physical characteristic, such as a fingerprint, face scan or other
biometric.

Identity and Access Access control (IAM) is the page that you typically use [Link]
Management (IAM) to assign roles to grant access to Azure resources. It's control/role-assignments-portal#step-2-open-the-add-role-
also known as identity and access management (IAM) assignment-pane
and appears in several locations in the Azure portal.
Azure You use the control plane to manage resources in your [Link]
Control/Management subscription. It includes operations on each Azure manager/management/control-plane-and-data-plane#control-plane
Plane resource in the subscription from the outside (the
management plane), for example creating a new
resource or starting a virtual machine, or any write
operations (PUT, POST, DELETE) taken on the resources
in your subscription.

For example:

 You create a virtual machine through the control


plane.

 You create a storage account through the control


plane.

 You create a Cosmos database through the control


plane.

All requests for control plane operations are sent to the


Azure Resource Manager URL. That URL varies by the
Azure environment.

 For Azure global, the URL is


[Link]

 For Azure Government, the URL is


[Link]
 For Azure Germany, the URL is
[Link]

 For Microsoft Azure China 21Vianet, the URL is


[Link]

Azure Data Plane You use the data plane to use capabilities exposed by [Link]
your instance of a resource type. It includes operations manager/management/control-plane-and-data-plane#data-plane
that are performed within an Azure resource.

For example:

 After a virtual machine is created, you interact


with it through data plane operations, such as
Remote Desktop Protocol (RDP).

 You use the data plane to read and write data in a


storage account.

 To query data in a Cosmos database, you use the


data plane.

Requests for data plane operations are sent to an


endpoint that is specific to your instance. For example,
the Detect Language operation in Cognitive Services is a
data plane operation because the request URL is:

POST {Endpoint}/text/analytics/v2.0/languages

Data plane operations aren't limited to REST API. They


may require additional credentials such as logging in to a
virtual machine or database server.

Features that enforce management and governance


might not applied to data plane operations. You need to
consider the different ways users interact with your
solutions. For example, a lock that prevents users from
deleting a database doesn't prevent users from deleting
data through queries.

You can use some policies to govern data plane


operations. For more information, see Resource Provider
modes (preview) in Azure Policy.

Azure Status Portal The Azure Status Portal allows you to check the current [Link]
Azure health status and view past incidents. It also
allows you to view other issues that might be impacting
your services.

It contains a link to your Azure Service Health service


blade.

You might also like