SlideShare a Scribd company logo
SECURING AZURE
INFRASTRUCTURE
FAUG # 7
12.12.2017
KARL OTS @ KOMPOZURE
• Co-organizer of Finland Azure User Group and
IglooConf
• Working on Azure since 2011
• Patented inventor
• Worked with tens of different customers on full-scale
Azure projects, from startups to Fortune 500
enterprises
Managing Consultant,
Kompozure Ltd
Karl.ots@kompozure.com
Securing Azure Infrastructure
2 Mil
kilometers
intra-datacenter
fiber
72+
Tb per second
Backbone
100+
datacenters
42
Azure regions
Millions
of servers
ACCESS
APPROVAL
Background check
System
check
PERIMETER
One defined
access point
Video
coverage
Perimeter
fencing
BUILDING
Two-factor
authentication with
biometrics
24x7x365
security
operations Verified single
person entry
SERVER
ENVIRONMENT
Employee &
contractor vetting
Inability to identify location
of specific customer data
Secure
destruction bins
Rest assured with layered datacenter security
SECURE YOUR AZURE ENVIRONMENT
Identity & access Encryption Secure hosts &
networking
3rd party
solutions
Unified security
management
✓ RBAC
✓ Strong
Authentication
✓ Monitoring and
Alerting
✓ Encryption Key
Management
✓ Encryption at
Rest and In
Transit
✓ Host AV &
monitoring
✓ Virtual
Networks
✓ Traffic Rules
✓ Secure
Connectivity
✓ Antimalware
✓ Network
Appliances
✓ Encryption
✓ Monitoring
✓ Application
Security
✓ Authentication
✓ Security Policy
✓ Monitoring
✓ Recommendati
ons
✓ Threat
Detection
ENCRYPTION
• At Rest
o Storage: SSE
o VM Disks: ADE
o Azure SQL: TDE
• In Transit
o All traffic between Azure datacenters encrypted
o We can enforce HTTPS connection to Storage
AZURE SECURITY CENTER
• Gain visibility and control
• Integrated security, monitoring, policy
management
• Built in threat detections and alerts
• Leverages global threat intelligence from
Microsoft products and services, Digital Crime
and Incident Response Centers, and third
party feeds
DEMO
SECURITY CENTER
Securing Azure Infrastructure
VNET SUPPORT FOR PAAS
• App Service Web Apps (VNET Integration, ASE and Isolated)
• API Management (Premium)
• Storage Firewall (NEW)
• Azure SQL Managed Instance (NEW)
RESOURCES
• Azure Trust Center
o https://www.microsoft.com/en-us/TrustCenter/
• Microsoft Azure Security - Getting Started (free Pluralsight course):
o https://www.pluralsight.com/courses/microsoft-azure-security-getting-
started?twoid=43eb6e26-b9fd-4aa0-b88f-2604b82e810f
• PCI-DSS Compliant PaaS Blueprint
o aka.ms/pciblueprints
DDOS PROTECTION
• Protection against
o Volumetric attacks (e.g. UDP floods)
o Protocol attacks (e.g. SYN floods)
o Application layer attacks (SQL injections, XSS)
• Simulations available from Azure Networking team
DMZ BETWEEN AZURE AND INTERNET
SO IS AZURE BETTER THAN MY DC?
• “My apps automatically become fully compliant when I run them on Azure”
KOMPOZURE
YOUR AZURE PARTNER

More Related Content

PDF
Protegendo sua cloud
PPTX
Storage Decisions Nirvanix Introduction
PPTX
Microsoft Azure IoT Hub (Sam Vanhoutte @TechdaysNL 2017)
PDF
ciso-platform-annual-summit-2013-5 implications of html5 on security by mherfurt
PDF
Tokyo meetup 20160224
PDF
DOG Meetup 18 November 2021 - Pozyx
PPTX
CipherCloud for Any App
PDF
Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...
Protegendo sua cloud
Storage Decisions Nirvanix Introduction
Microsoft Azure IoT Hub (Sam Vanhoutte @TechdaysNL 2017)
ciso-platform-annual-summit-2013-5 implications of html5 on security by mherfurt
Tokyo meetup 20160224
DOG Meetup 18 November 2021 - Pozyx
CipherCloud for Any App
Chris Swan's CloudExpo Europe presentation "The networking declaration of ind...

What's hot (16)

PDF
打造 AIoT 智慧物聯網時代解決方案
PDF
FIWARE Global Summit - How IoT Companies and Startups are Using FIWARE as the...
PDF
Why NVMe is Changing IoT
PDF
Reconfigure.io - Cloud-based FPGA Acceleration for AI applications
PPTX
DotNetToscana - Azure IoT Hub - Il Concentratore
PPTX
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
PDF
Cisco Connect 2018 Vietnam - hyper flex
PPTX
Open Cloud Storage @ OpenStack Summit Paris
PDF
The Intel Xeon Scalable Processor and IoT
PDF
PDF
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
PDF
Advantech Cutting Edge Compute and Storage for Industrial IoT
PPTX
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
PPTX
GoGrid 3.0 Webinar: Complex Infrastructure Made Easy - Learn About the GoGrid...
PDF
Transformation of IT platform design
PDF
Accelerating incident response in organizations of any size
打造 AIoT 智慧物聯網時代解決方案
FIWARE Global Summit - How IoT Companies and Startups are Using FIWARE as the...
Why NVMe is Changing IoT
Reconfigure.io - Cloud-based FPGA Acceleration for AI applications
DotNetToscana - Azure IoT Hub - Il Concentratore
[Cisco Connect 2018 - Vietnam] Long ton dc pss hyper flex
Cisco Connect 2018 Vietnam - hyper flex
Open Cloud Storage @ OpenStack Summit Paris
The Intel Xeon Scalable Processor and IoT
Cisco Connect 2018 Philippines - cisco sd-wan-next generation wan to power yo...
Advantech Cutting Edge Compute and Storage for Industrial IoT
[Cisco Connect 2018 - Vietnam] 3. rajinder singh cisco sd-wan-next generati...
GoGrid 3.0 Webinar: Complex Infrastructure Made Easy - Learn About the GoGrid...
Transformation of IT platform design
Accelerating incident response in organizations of any size
Ad

Similar to Securing Azure Infrastructure (16)

PDF
Azure security architecture / FAUG JKL 15.2.2018
PDF
Azure security architecture
PPTX
How do you protect a hybrid PaaS-IaaS solution, built entirely in the cloud?
PDF
FAUG #9: Azure security architecture and stories from the trenches
PDF
IglooConf 2020: Best practices of securing web applications running on Azure ...
PPTX
Azure Security: How to protect a hybrid PaaS-IaaS solution built entirely in ...
PPTX
Microsoft Azure News - December 2024 - BAUG
PPTX
Azure security basics
PDF
Microsoft Azure Security Overview
PDF
CloudBurst Malmö: Best practices of securing web applications running on Azur...
PDF
366864108 azure-security
PPTX
Zero Trust Run-time Kubernetes Security made easy with AccuKnox
PDF
CSS17: Houston - Azure Shared Security Model Overview
PPTX
Azure Fundamentals Part 3
 
PPTX
[Toroman/Kranjac] Red Team vs. Blue Team in Microsoft Cloud
PDF
TechDays Finland 2020: Best practices of securing web applications running on...
Azure security architecture / FAUG JKL 15.2.2018
Azure security architecture
How do you protect a hybrid PaaS-IaaS solution, built entirely in the cloud?
FAUG #9: Azure security architecture and stories from the trenches
IglooConf 2020: Best practices of securing web applications running on Azure ...
Azure Security: How to protect a hybrid PaaS-IaaS solution built entirely in ...
Microsoft Azure News - December 2024 - BAUG
Azure security basics
Microsoft Azure Security Overview
CloudBurst Malmö: Best practices of securing web applications running on Azur...
366864108 azure-security
Zero Trust Run-time Kubernetes Security made easy with AccuKnox
CSS17: Houston - Azure Shared Security Model Overview
Azure Fundamentals Part 3
 
[Toroman/Kranjac] Red Team vs. Blue Team in Microsoft Cloud
TechDays Finland 2020: Best practices of securing web applications running on...
Ad

More from Karl Ots (20)

PDF
TechDays Finland 2020: Azuren tietoturva haltuun!
PDF
Building an Enterprise-Grade Azure Governance Model
PDF
IT Camp 19: Top Azure security fails and how to avoid them
PDF
FAUG Jyväskylä 28.5.2019 - Azure Monitoring
PDF
DevSum - Top Azure security fails and how to avoid them
PDF
Techorama Belgium 2019 - Building an Azure Governance model for the Enterprise
PDF
Techorama Belgium 2019: top Azure security fails and how to avoid them
PDF
ISC2 Secure Summit EMEA - Top Microsoft Azure security fails and how to avoid...
PDF
Azure Low Lands 2018: Monitoring real life Azure applications when to use wha...
PDF
IglooConf 2019 Secure your Azure applications like a pro
PDF
UpdateConf 2018: Monitoring real-life Azure applications: When to use what an...
PDF
UpdateConf 2018: Top 18 Azure security fails and how to avoid them
PDF
Top Azure security fails and how to avoid them
PDF
Top 18 azure security fails and how to avoid them
PDF
Monitoring real-life Azure applications: When to use what and why
PDF
Azure Saturday: Security + DevOps + Azure = Awesomeness
PDF
Navigating in the sea of containers in azure when to choose which service and...
PDF
Kubernetes in Azure
PDF
CloudBrew 2017 - Security + DevOps + Azure = Awesomeness
PDF
Monitoring advanced Azure PaaS workloads in the enterprise - Level: 200
TechDays Finland 2020: Azuren tietoturva haltuun!
Building an Enterprise-Grade Azure Governance Model
IT Camp 19: Top Azure security fails and how to avoid them
FAUG Jyväskylä 28.5.2019 - Azure Monitoring
DevSum - Top Azure security fails and how to avoid them
Techorama Belgium 2019 - Building an Azure Governance model for the Enterprise
Techorama Belgium 2019: top Azure security fails and how to avoid them
ISC2 Secure Summit EMEA - Top Microsoft Azure security fails and how to avoid...
Azure Low Lands 2018: Monitoring real life Azure applications when to use wha...
IglooConf 2019 Secure your Azure applications like a pro
UpdateConf 2018: Monitoring real-life Azure applications: When to use what an...
UpdateConf 2018: Top 18 Azure security fails and how to avoid them
Top Azure security fails and how to avoid them
Top 18 azure security fails and how to avoid them
Monitoring real-life Azure applications: When to use what and why
Azure Saturday: Security + DevOps + Azure = Awesomeness
Navigating in the sea of containers in azure when to choose which service and...
Kubernetes in Azure
CloudBrew 2017 - Security + DevOps + Azure = Awesomeness
Monitoring advanced Azure PaaS workloads in the enterprise - Level: 200

Recently uploaded (20)

PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Electronic commerce courselecture one. Pdf
PPTX
A Presentation on Artificial Intelligence
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Modernizing your data center with Dell and AMD
PDF
NewMind AI Monthly Chronicles - July 2025
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PPTX
Cloud computing and distributed systems.
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
Big Data Technologies - Introduction.pptx
PDF
Empathic Computing: Creating Shared Understanding
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Electronic commerce courselecture one. Pdf
A Presentation on Artificial Intelligence
Dropbox Q2 2025 Financial Results & Investor Presentation
Digital-Transformation-Roadmap-for-Companies.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Modernizing your data center with Dell and AMD
NewMind AI Monthly Chronicles - July 2025
The Rise and Fall of 3GPP – Time for a Sabbatical?
Network Security Unit 5.pdf for BCA BBA.
Diabetes mellitus diagnosis method based random forest with bat algorithm
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Cloud computing and distributed systems.
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Big Data Technologies - Introduction.pptx
Empathic Computing: Creating Shared Understanding
“AI and Expert System Decision Support & Business Intelligence Systems”

Securing Azure Infrastructure

  • 2. KARL OTS @ KOMPOZURE • Co-organizer of Finland Azure User Group and IglooConf • Working on Azure since 2011 • Patented inventor • Worked with tens of different customers on full-scale Azure projects, from startups to Fortune 500 enterprises Managing Consultant, Kompozure Ltd Karl.ots@kompozure.com
  • 4. 2 Mil kilometers intra-datacenter fiber 72+ Tb per second Backbone 100+ datacenters 42 Azure regions Millions of servers ACCESS APPROVAL Background check System check PERIMETER One defined access point Video coverage Perimeter fencing BUILDING Two-factor authentication with biometrics 24x7x365 security operations Verified single person entry SERVER ENVIRONMENT Employee & contractor vetting Inability to identify location of specific customer data Secure destruction bins Rest assured with layered datacenter security
  • 5. SECURE YOUR AZURE ENVIRONMENT Identity & access Encryption Secure hosts & networking 3rd party solutions Unified security management ✓ RBAC ✓ Strong Authentication ✓ Monitoring and Alerting ✓ Encryption Key Management ✓ Encryption at Rest and In Transit ✓ Host AV & monitoring ✓ Virtual Networks ✓ Traffic Rules ✓ Secure Connectivity ✓ Antimalware ✓ Network Appliances ✓ Encryption ✓ Monitoring ✓ Application Security ✓ Authentication ✓ Security Policy ✓ Monitoring ✓ Recommendati ons ✓ Threat Detection
  • 6. ENCRYPTION • At Rest o Storage: SSE o VM Disks: ADE o Azure SQL: TDE • In Transit o All traffic between Azure datacenters encrypted o We can enforce HTTPS connection to Storage
  • 7. AZURE SECURITY CENTER • Gain visibility and control • Integrated security, monitoring, policy management • Built in threat detections and alerts • Leverages global threat intelligence from Microsoft products and services, Digital Crime and Incident Response Centers, and third party feeds
  • 10. VNET SUPPORT FOR PAAS • App Service Web Apps (VNET Integration, ASE and Isolated) • API Management (Premium) • Storage Firewall (NEW) • Azure SQL Managed Instance (NEW)
  • 11. RESOURCES • Azure Trust Center o https://www.microsoft.com/en-us/TrustCenter/ • Microsoft Azure Security - Getting Started (free Pluralsight course): o https://www.pluralsight.com/courses/microsoft-azure-security-getting- started?twoid=43eb6e26-b9fd-4aa0-b88f-2604b82e810f • PCI-DSS Compliant PaaS Blueprint o aka.ms/pciblueprints
  • 12. DDOS PROTECTION • Protection against o Volumetric attacks (e.g. UDP floods) o Protocol attacks (e.g. SYN floods) o Application layer attacks (SQL injections, XSS) • Simulations available from Azure Networking team
  • 13. DMZ BETWEEN AZURE AND INTERNET
  • 14. SO IS AZURE BETTER THAN MY DC? • “My apps automatically become fully compliant when I run them on Azure”