SlideShare a Scribd company logo
#GlobalAzure
#GlobalAzure
Alberto Diaz Martin
Chief Technology and Innovation Officer
http://blogs.encamina.com/por-una-nube-sostenible/
adiazcan
Alberto Diaz cuenta con más de 14 años de experiencia en la Industria IT, todos ellos trabajando con
tecnologías Microsoft. Actualmente, es Chief Technology Innovation Officer en ENCAMINA, liderando el
desarrollo de software con tecnología Microsoft, y miembro del equipo de Dirección. Para la comunidad,
trabaja como organizador y speaker de las conferencias más relevantes del mundo Microsoft en España, en
las cuales es uno de los referentes en SharePoint, Office 365 y Azure. Autor de diversos libros y artículos en
revistas profesionales y blogs, en 2013 empezó a formar parte del equipo de Dirección de CompartiMOSS,
una revista digital sobre tecnologías Microsoft.
Desde 2011 ha sido nombrado Microsoft MVP, reconocimiento que ha renovado por sexto año consecutivo.
Se define como un geek, amante de los smartphones y desarrollador. Fundador de TenerifeDev
(www.tenerifedev.com), un grupo de usuarios de .NET en Tenerife, y coordinador de SUGES (Grupo de
Usuarios de SharePoint de España, www.suges.es)
Global Azure Bootcamp 2017 - Azure Key Vault
Global Azure Bootcamp 2017 - Azure Key Vault
#GlobalAzure
Qué y por qué Azure Key Vault
• 1.74GB file with 1,286,366 records
• Personal details of 550000 blood donors
• Data was unencrypted and stored on a unsecured website
• Found through scanning public addresses for .sql file
Source: https://www.troyhunt.com/the-red-cross-blood-service-australias-largest-ever-
leak-of-personal-data
Duraba Corporation
Earth Broadcasting in 2011
• PlayStation Network down
• Unencrypted Credit Card details of users
Earth Broadcasting in 2014
• Personal data of employees and families
• Confidential emails and salary information
• A few films (The Interview, Annie)
Source: https://en.wikipedia.org/wiki/2011_PlayStation_Network_outage ;
https://en.wikipedia.org/wiki/Sony_Pictures_hack
Earth Broadcasting Company
• Had a Crypto locker installed
• 350GB of personal data
• Paid $400 to get access back to his Data
My “friend” Nyota Uhura
• 340GB of data
• 228,605 email addresses
• 1.3 million passport numbers and expiry dates
• 15.8 million fingerprint records
• Data was encrypted – Key was in the PHP code of its website
Source: https://en.wikipedia.org/wiki/Commission_on_Elections_data_breach
Galactic Mining Company
Quiz
The quest to securing resources in Azure
Symmetric keys
Asymmetric keys
Keys
Public key Private key
Digital Certificates
Public key in a wrapper
Certificates
Connections strings
Credentials
Other secrets
Secrets
• Secrets and Keys are encrypted at rest 1
• Choice of deployment location 2
• Choice of encryption method
(Software vs Hardware & BOYK) 3
• Security module separation 4
• Easy access and rights control 5
• Low Cost 6
• Secrets and Keys are encrypted at rest 1
• Choice of deployment country 2
• Choice of encryption method
(Software vs Hardware & BOYK) 3
• Security module separation 4
• Easy access and rights control 5
• Low Cost 6
• Low Cost
• Easy access and rights control
• Security module separation
• Secrets and Keys are encrypted at rest
• Choice of deployment country
• Choice of encryption method
(Software vs Hardware & BOYK)
1
2
3
4
5
6
All Data in the KeyVault is encrypted
Price is 0.03$ / 10.000
Management via PS / Azure AD / RBAC
Create as many Key Vaults as you want
Choice of which datacentre and which
resource group we want to deploy to
Standard vs Premium edition
BOYK
Cloud hosted, HSM backed service for managing cryptographic keys and features
using certified FIPS 140-2 Level 2 standards
Encrypt keys and small secrets (up to 10kb)
Import or generate your keys
Simplify and automate tasks for SSL/TLS certificates
All Keys stay in HSM boundary
You cannot retrieve the private key
Key Vault is deployed in minutes
Comes in two flavors – Standard and Premium
With premium Key Vaults all secrets and keys are stored on a HSM
$0.03$/10.000 operations
Certification renewal – 3$ per renew request
HSM protected keys: 1$ per key per month
#GlobalAzure
Cómo y Dónde usar Azure Key Vault
Global Azure Bootcamp 2017 - Azure Key Vault
Key Vault: Workflow
Azure
Admin / Key
Vault Owner
Azure
Active Directory
1. Create service principal
Key Vault
2. Create Key Vault
Configure access for
service principal
Key / Secret
Owner
3. create Key / Secret
Application
or Azure
Resource
5. Configure Application / Azure
resource with the service
principal and Key / Secret URI
6. Authenticate against AAD
7. receive token from AAD
8.Send token to Key Vault
9. Access Key Vault and retrieve
Key / Secret
4. communicate service principal
and Key / Secret URI Application
Owner
•
•
•
•
Usemos Azure Key Vaul para:
No entregar las claves o password de
nuestros servicios
Encriptar las máquinas virtuales, los
Storage, nuestros datos, …
Guardar nuestros certificados
Global Azure Bootcamp 2017 - Azure Key Vault
http://azurebootcamp.es
Global Azure Bootcamp 2017 - Azure Key Vault

More Related Content

PPTX
Azure key vault
PPTX
Securing sensitive data with Azure Key Vault
PPTX
ITProceed 2015 - Securing Sensitive Data with Azure Key Vault
PPTX
Azure Low Lands 2019 - Building secure cloud applications with Azure Key Vault
PPTX
Azure key vault - Brisbane User Group
PPTX
Azure Key Vault - Getting Started
PPTX
The Key to Strong Cloud Security
PPTX
Secret Management Architectures
Azure key vault
Securing sensitive data with Azure Key Vault
ITProceed 2015 - Securing Sensitive Data with Azure Key Vault
Azure Low Lands 2019 - Building secure cloud applications with Azure Key Vault
Azure key vault - Brisbane User Group
Azure Key Vault - Getting Started
The Key to Strong Cloud Security
Secret Management Architectures

What's hot (20)

PDF
Delivering transparent data_encryption_while_centrally_managing_keys_eskm-blo...
PDF
Kubernetes Secrets - The Good, The Bad, and The Ugly - Akeyless
PDF
Identity Security - Azure Active Directory
PPTX
Kubernetes Secrets Management - Securing Your Production Environment
PPTX
The Rise of Secrets Management
PDF
Programming with Azure Active Directory
PPTX
IBM Secret Key management protoco
PDF
Secure Secret Management on a Budget: Reasoning about Scalable SM with Vault ...
PDF
CSF18 - Securing the Cloud - Karim El-Melhaoui
PPTX
Using Vault for your Nodejs Secrets
PPTX
Managing your secrets in a cloud environment
PPTX
Azure security basics
PPTX
Techdays Finland 2018 - Building secure cloud applications with Azure Key Vault
PDF
Automation Patterns for Scalable Secret Management
PDF
Hardening Kubernetes Cluster
PDF
Credential store using HashiCorp Vault
PDF
Access Security - Hybrid Identity
PPTX
Secret Management with Hashicorp Vault and Consul on Kubernetes
PPTX
.NET Fest 2019. Stas Lebedenko. Practical serverless use cases in Azure with ...
PPTX
Let's get started with passwordless authentication using windows hello in you...
Delivering transparent data_encryption_while_centrally_managing_keys_eskm-blo...
Kubernetes Secrets - The Good, The Bad, and The Ugly - Akeyless
Identity Security - Azure Active Directory
Kubernetes Secrets Management - Securing Your Production Environment
The Rise of Secrets Management
Programming with Azure Active Directory
IBM Secret Key management protoco
Secure Secret Management on a Budget: Reasoning about Scalable SM with Vault ...
CSF18 - Securing the Cloud - Karim El-Melhaoui
Using Vault for your Nodejs Secrets
Managing your secrets in a cloud environment
Azure security basics
Techdays Finland 2018 - Building secure cloud applications with Azure Key Vault
Automation Patterns for Scalable Secret Management
Hardening Kubernetes Cluster
Credential store using HashiCorp Vault
Access Security - Hybrid Identity
Secret Management with Hashicorp Vault and Consul on Kubernetes
.NET Fest 2019. Stas Lebedenko. Practical serverless use cases in Azure with ...
Let's get started with passwordless authentication using windows hello in you...
Ad

Similar to Global Azure Bootcamp 2017 - Azure Key Vault (20)

PDF
SharePoint Saturday Ottawa - How secure is my data in office 365?
PDF
All about documents in O365 - aOS Singapore 2019
PPTX
Microsoft Security Advice ISSA Slides.pptx
PPTX
Fundamentals of Microsoft 365 Security , Identity and Compliance
PPTX
Secure Your Cloud Migration - Secureworld 2019 Charlotte
PPTX
[Cluj] Turn SSL ON
PDF
May 2020 Microsoft 365 Need to Know Webinar
PPTX
Symantec SSL Explained
PPTX
SMB Security Product Overview.pptx
PPTX
TechTalksUtah-Sentinel-20191108.pptx
PPTX
Oralce SSL walelt -TCPS_Troubleshooting_PB.pptx
PPTX
Phishing past mail protection controls using azure information
PDF
O365Con19 - A Life Without Passwords Dream or Reality - Sander Berkouwer
PDF
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
PDF
IT Camp 19: Top Azure security fails and how to avoid them
PPTX
Teams Day Online - Microsoft Teams Governance
PPTX
Securely Harden Microsoft 365 with Secure Score
PDF
Office 365 Security, Privacy and Compliance - SMB Nation 2015
PDF
October 2022 CIAOPS Need to Know Webinar
PPTX
Azure sentinel
SharePoint Saturday Ottawa - How secure is my data in office 365?
All about documents in O365 - aOS Singapore 2019
Microsoft Security Advice ISSA Slides.pptx
Fundamentals of Microsoft 365 Security , Identity and Compliance
Secure Your Cloud Migration - Secureworld 2019 Charlotte
[Cluj] Turn SSL ON
May 2020 Microsoft 365 Need to Know Webinar
Symantec SSL Explained
SMB Security Product Overview.pptx
TechTalksUtah-Sentinel-20191108.pptx
Oralce SSL walelt -TCPS_Troubleshooting_PB.pptx
Phishing past mail protection controls using azure information
O365Con19 - A Life Without Passwords Dream or Reality - Sander Berkouwer
aMS Aachen -Personal and confidential data - how to manage them in M365 2022-...
IT Camp 19: Top Azure security fails and how to avoid them
Teams Day Online - Microsoft Teams Governance
Securely Harden Microsoft 365 with Secure Score
Office 365 Security, Privacy and Compliance - SMB Nation 2015
October 2022 CIAOPS Need to Know Webinar
Azure sentinel
Ad

More from Alberto Diaz Martin (20)

PPTX
Microsoft 365 Virtual 2020 Spain - Microsoft Graph Search API
PPTX
DotNet Conf Valencia 2019 - Building cloud native apps with .NRT core 3.0 and...
PPTX
GAB 2019 - Graph as a data store
PPTX
DotNet Conf Madrid 2019 - Whats New in ML.NET
PPTX
DotNet Conf Madrid 2019 - ASP.NET Core 3
PPTX
SQL Saturday Madrid 2019 - Data model with Azure Cosmos DB
PPTX
SharePoint Saturday Madrid 2019 - Productivity based on AI
PPTX
Dynamics Saturday Madrid 2019 - AI to improve productivity
PPTX
TenerifeDev - NLPs and how to develop for Alexa and Google Assistant
PPTX
NetCoreConf Barcelona 2019 - DotNet Assistants
PPTX
Global Integration Bootcamp 2018 - Gobierno de APIs
PPTX
Gab 2018 seguridad y escalado en azure service fabric
PPTX
CrossDvlpu - REACT para desarrolladores de ASP.NET
PPTX
Dynamics 365 Saturday Madrid 2018 - Otro ALM es posible para Dynamics 365
PPTX
Azure4Research - Big Data Analytics con Hadoop, Spark y Power BI
PPTX
ENCAMINA - El flash de Inteligencia Artificial
PPTX
Ai & Data Analytics 2018 - Azure Databricks for data scientist
PPTX
Global AI Bootcamp Madrid - Azure Databricks
PPTX
TenerifeDev - Intro to Microservices
PPTX
TenerifeDev - Azure Service Fabric
Microsoft 365 Virtual 2020 Spain - Microsoft Graph Search API
DotNet Conf Valencia 2019 - Building cloud native apps with .NRT core 3.0 and...
GAB 2019 - Graph as a data store
DotNet Conf Madrid 2019 - Whats New in ML.NET
DotNet Conf Madrid 2019 - ASP.NET Core 3
SQL Saturday Madrid 2019 - Data model with Azure Cosmos DB
SharePoint Saturday Madrid 2019 - Productivity based on AI
Dynamics Saturday Madrid 2019 - AI to improve productivity
TenerifeDev - NLPs and how to develop for Alexa and Google Assistant
NetCoreConf Barcelona 2019 - DotNet Assistants
Global Integration Bootcamp 2018 - Gobierno de APIs
Gab 2018 seguridad y escalado en azure service fabric
CrossDvlpu - REACT para desarrolladores de ASP.NET
Dynamics 365 Saturday Madrid 2018 - Otro ALM es posible para Dynamics 365
Azure4Research - Big Data Analytics con Hadoop, Spark y Power BI
ENCAMINA - El flash de Inteligencia Artificial
Ai & Data Analytics 2018 - Azure Databricks for data scientist
Global AI Bootcamp Madrid - Azure Databricks
TenerifeDev - Intro to Microservices
TenerifeDev - Azure Service Fabric

Recently uploaded (20)

PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PPTX
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
Big Data Technologies - Introduction.pptx
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PDF
Modernizing your data center with Dell and AMD
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Machine learning based COVID-19 study performance prediction
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Electronic commerce courselecture one. Pdf
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
GamePlan Trading System Review: Professional Trader's Honest Take
PPT
Teaching material agriculture food technology
The Rise and Fall of 3GPP – Time for a Sabbatical?
Mobile App Security Testing_ A Comprehensive Guide.pdf
breach-and-attack-simulation-cybersecurity-india-chennai-defenderrabbit-2025....
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
NewMind AI Monthly Chronicles - July 2025
NewMind AI Weekly Chronicles - August'25 Week I
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Big Data Technologies - Introduction.pptx
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
Modernizing your data center with Dell and AMD
The AUB Centre for AI in Media Proposal.docx
Machine learning based COVID-19 study performance prediction
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
Electronic commerce courselecture one. Pdf
Chapter 3 Spatial Domain Image Processing.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Spectral efficient network and resource selection model in 5G networks
GamePlan Trading System Review: Professional Trader's Honest Take
Teaching material agriculture food technology

Global Azure Bootcamp 2017 - Azure Key Vault

  • 2. #GlobalAzure Alberto Diaz Martin Chief Technology and Innovation Officer http://blogs.encamina.com/por-una-nube-sostenible/ adiazcan Alberto Diaz cuenta con más de 14 años de experiencia en la Industria IT, todos ellos trabajando con tecnologías Microsoft. Actualmente, es Chief Technology Innovation Officer en ENCAMINA, liderando el desarrollo de software con tecnología Microsoft, y miembro del equipo de Dirección. Para la comunidad, trabaja como organizador y speaker de las conferencias más relevantes del mundo Microsoft en España, en las cuales es uno de los referentes en SharePoint, Office 365 y Azure. Autor de diversos libros y artículos en revistas profesionales y blogs, en 2013 empezó a formar parte del equipo de Dirección de CompartiMOSS, una revista digital sobre tecnologías Microsoft. Desde 2011 ha sido nombrado Microsoft MVP, reconocimiento que ha renovado por sexto año consecutivo. Se define como un geek, amante de los smartphones y desarrollador. Fundador de TenerifeDev (www.tenerifedev.com), un grupo de usuarios de .NET en Tenerife, y coordinador de SUGES (Grupo de Usuarios de SharePoint de España, www.suges.es)
  • 5. #GlobalAzure Qué y por qué Azure Key Vault
  • 6. • 1.74GB file with 1,286,366 records • Personal details of 550000 blood donors • Data was unencrypted and stored on a unsecured website • Found through scanning public addresses for .sql file Source: https://www.troyhunt.com/the-red-cross-blood-service-australias-largest-ever- leak-of-personal-data Duraba Corporation Earth Broadcasting in 2011 • PlayStation Network down • Unencrypted Credit Card details of users Earth Broadcasting in 2014 • Personal data of employees and families • Confidential emails and salary information • A few films (The Interview, Annie) Source: https://en.wikipedia.org/wiki/2011_PlayStation_Network_outage ; https://en.wikipedia.org/wiki/Sony_Pictures_hack Earth Broadcasting Company • Had a Crypto locker installed • 350GB of personal data • Paid $400 to get access back to his Data My “friend” Nyota Uhura • 340GB of data • 228,605 email addresses • 1.3 million passport numbers and expiry dates • 15.8 million fingerprint records • Data was encrypted – Key was in the PHP code of its website Source: https://en.wikipedia.org/wiki/Commission_on_Elections_data_breach Galactic Mining Company Quiz
  • 7. The quest to securing resources in Azure
  • 8. Symmetric keys Asymmetric keys Keys Public key Private key Digital Certificates Public key in a wrapper Certificates Connections strings Credentials Other secrets Secrets
  • 9. • Secrets and Keys are encrypted at rest 1 • Choice of deployment location 2 • Choice of encryption method (Software vs Hardware & BOYK) 3 • Security module separation 4 • Easy access and rights control 5 • Low Cost 6
  • 10. • Secrets and Keys are encrypted at rest 1 • Choice of deployment country 2 • Choice of encryption method (Software vs Hardware & BOYK) 3 • Security module separation 4 • Easy access and rights control 5 • Low Cost 6
  • 11. • Low Cost • Easy access and rights control • Security module separation • Secrets and Keys are encrypted at rest • Choice of deployment country • Choice of encryption method (Software vs Hardware & BOYK) 1 2 3 4 5 6 All Data in the KeyVault is encrypted Price is 0.03$ / 10.000 Management via PS / Azure AD / RBAC Create as many Key Vaults as you want Choice of which datacentre and which resource group we want to deploy to Standard vs Premium edition BOYK
  • 12. Cloud hosted, HSM backed service for managing cryptographic keys and features using certified FIPS 140-2 Level 2 standards Encrypt keys and small secrets (up to 10kb) Import or generate your keys Simplify and automate tasks for SSL/TLS certificates All Keys stay in HSM boundary You cannot retrieve the private key Key Vault is deployed in minutes Comes in two flavors – Standard and Premium With premium Key Vaults all secrets and keys are stored on a HSM $0.03$/10.000 operations Certification renewal – 3$ per renew request HSM protected keys: 1$ per key per month
  • 13. #GlobalAzure Cómo y Dónde usar Azure Key Vault
  • 15. Key Vault: Workflow Azure Admin / Key Vault Owner Azure Active Directory 1. Create service principal Key Vault 2. Create Key Vault Configure access for service principal Key / Secret Owner 3. create Key / Secret Application or Azure Resource 5. Configure Application / Azure resource with the service principal and Key / Secret URI 6. Authenticate against AAD 7. receive token from AAD 8.Send token to Key Vault 9. Access Key Vault and retrieve Key / Secret 4. communicate service principal and Key / Secret URI Application Owner
  • 17. Usemos Azure Key Vaul para: No entregar las claves o password de nuestros servicios Encriptar las máquinas virtuales, los Storage, nuestros datos, … Guardar nuestros certificados