Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| azure:az-500:data_and_application_security [2022/06/27 01:32] – [Shared Access Signature (SAS)] mmuze | azure:az-500:data_and_application_security [2022/07/22 00:59] (current) – mmuze | ||
|---|---|---|---|
| Line 4: | Line 4: | ||
| ===== Configure security for storage ===== | ===== Configure security for storage ===== | ||
| + | * [[azure: | ||
| * [[azure: | * [[azure: | ||
| * Configure access control for storage accounts | * Configure access control for storage accounts | ||
| Line 28: | Line 29: | ||
| * Configure backup and recovery of certificates, | * Configure backup and recovery of certificates, | ||
| - | ====== Storage Account Access ====== | ||
| - | * [[https:// | ||
| - | * [[https:// | ||
| - | * [[https:// | ||
| - | * A [[https:// | ||
| - | |||
| - | ===== Shared Access Signature (SAS) ===== | ||
| - | * The only way to revoke a SAS is to revoke/ | ||
| - | * A **user delegation** SAS is secured with Azure Active Directory (Azure AD) credentials and also by the permissions specified for the SAS. A user delegation SAS applies to Blob storage only. | ||
| - | * A **service SAS** is secured with the storage account key. A service SAS delegates access to a resource in only one of the Azure Storage services: Blob storage, Queue storage, Table storage, or Azure Files. | ||
| - | * An **account SAS** is secured with the storage account key. An account SAS delegates access to resources in one or more of the storage services. All of the operations available via a service or user delegation SAS are also available via an account SAS. | ||
| ===== Azure Key Vault ===== | ===== Azure Key Vault ===== | ||
| Line 124: | Line 114: | ||
| ===== § ===== | ===== § ===== | ||
| * [[azure: | * [[azure: | ||
| + | |||
| + | ====== HDInsight ====== | ||
| + | * To support multiuser access an HDInsight cluster requires AADDS. | ||