Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| azure:az-500:data_and_application_security [2022/06/27 01:33] – [Shared Access Signature (SAS)] mmuze | azure:az-500:data_and_application_security [2022/07/22 00:59] (current) – mmuze | ||
|---|---|---|---|
| Line 4: | Line 4: | ||
| ===== Configure security for storage ===== | ===== Configure security for storage ===== | ||
| + | * [[azure: | ||
| * [[azure: | * [[azure: | ||
| * Configure access control for storage accounts | * Configure access control for storage accounts | ||
| Line 28: | Line 29: | ||
| * Configure backup and recovery of certificates, | * Configure backup and recovery of certificates, | ||
| - | ====== Storage Account Access ====== | ||
| - | * [[https:// | ||
| - | * [[https:// | ||
| - | * [[https:// | ||
| - | * A [[https:// | ||
| - | |||
| - | ===== Shared Access Signature (SAS) ===== | ||
| - | * The only way to revoke a SAS is to revoke (regenerate) the access key that was used to sign it. This is not ideal because that key could be used in other ways and this would be disruptive operation. That is where a **stored access policy** can be of use. | ||
| - | * A **user delegation** SAS is secured with Azure Active Directory (Azure AD) credentials and also by the permissions specified for the SAS. A user delegation SAS applies to Blob storage only. | ||
| - | * A **service SAS** is secured with the storage account key. A service SAS delegates access to a resource in only one of the Azure Storage services: Blob storage, Queue storage, Table storage, or Azure Files. | ||
| - | * An **account SAS** is secured with the storage account key. An account SAS delegates access to resources in one or more of the storage services. All of the operations available via a service or user delegation SAS are also available via an account SAS. | ||
| ===== Azure Key Vault ===== | ===== Azure Key Vault ===== | ||
| Line 124: | Line 114: | ||
| ===== § ===== | ===== § ===== | ||
| * [[azure: | * [[azure: | ||
| + | |||
| + | ====== HDInsight ====== | ||
| + | * To support multiuser access an HDInsight cluster requires AADDS. | ||