Table of Contents

Platform Protection

Implement advanced network security

Configure advanced security for compute

Perimeter Security

DDoS Protection

DDoS Protection blocks attack traffic and forwards the remaining traffic to its intended destination. Within a few minutes of attack detection, you’ll be notified with Azure Monitor metrics. By configuring logging on DDoS Protection Standard telemetry, you can write the logs to available options for future analysis. Azure Monitor retains metric data for DDoS Protection Standard for 30 days.

Azure Firewall

Premium SKU

Azure Firewall Manager

Application Gateway

Front Door

Application Gateway vs Front Door

While both Front Door and Application Gateway are layer 7 (HTTP/HTTPS) load balancers, the primary difference is that Front Door is a non-regional service whereas Application Gateway is a regional service.

Network Security Groups (NSGs)

Application Security Groups

Service Endpoints and Private Endpoints

Service Endpoints

Private Endpoint

§

Forced Tunneling

Forced tunneling lets you redirect or “force” all Internet-bound traffic back to your on-premises location via a Site-to-Site VPN tunnel for inspection and auditing.

This is sometimes referred to as back hauling.

Disk Encryption

Container Security