azure:az-500:platform_protection

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
azure:az-500:platform_protection [2022/06/27 20:57] mmuzeazure:az-500:platform_protection [2022/07/22 00:42] (current) mmuze
Line 96: Line 96:
   * **Private Endpoint** allows you to connect your virtual network to services in Azure without a public IP address at the source or destination.   * **Private Endpoint** allows you to connect your virtual network to services in Azure without a public IP address at the source or destination.
   * The key difference between Private Link and Service Endpoints is that with Private Link you are injecting the multi-tenant PaaS resource into your virtual network.   * The key difference between Private Link and Service Endpoints is that with Private Link you are injecting the multi-tenant PaaS resource into your virtual network.
-  * With Service Endpoints, traffic still left you Vnet and hit the public endpoint of the PaaS resource, with Private Link the PaaS resource sits within your Vnet and gets a private IP on your Vnet. When you send traffic to the PaaS resource, it does not leave the virtual network.+  * With Service Endpoints, traffic still leaves your Vnet and hits the public endpoint of the PaaS resource, with Private Link the PaaS resource sits within your Vnet and gets a private IP on your Vnet. When you send traffic to the PaaS resource, it does not leave the virtual network.
  
 {{ :azure:az-500:private-endpoint.png }} {{ :azure:az-500:private-endpoint.png }}
Line 107: Line 107:
  
 ====== Disk Encryption ====== ====== Disk Encryption ======
 +  * Windows uses BitLock for disk encryption
 +  * Linux uses DM-Crypt for disk encryption
 +  * Disks are stored as page blobs in storage accounts
 +  * Customer managed keys can be used and kept in Azure Key Vault
 +
 +====== Container Security ======
 +  * ACR = Azure Container Registry
 +  * [[https://docs.microsoft.com/en-us/azure/container-registry/container-registry-roles|ACR Roles]]
 +
  
  • azure/az-500/platform_protection.1656363452.txt.gz
  • Last modified: 2022/06/27 20:57
  • by mmuze