Day 06: Azure Resource Manager (Resources & Resource Groups & Management Groups) and Compliance in Azure

Day 06: Azure Resource Manager (Resources & Resource Groups & Management Groups) and Compliance in Azure

Azure Resource Manager (Resources & Resource Groups & Management Groups)

Azure Resource

  • Anythings you create in an Azure subscription
  • E.g. virtual machines, Application Gateways, and CosmosDB instances
  • ?? Good to have consistent naming convention e.g.: cloudarchitecture-prod-infrastructure-rg
  • Provides fine-grained access management through role-based access control (RBAC)
  • ?? You can move some resources that supports move to a new resource group or subscription if they support move operation.

Tagging

  • Helps you better search, filter, and organize these resources
  • Name/value pairs of text data that you can apply to resources and resource groups
  • E.g.
  • ???? Good way to group your billing data
  • ?? Help with monitoring
  • ?? Help with automation
  • ?? Help with automation Governance through Policies
  • ? Limitations:

Resource locks

  • ?? Blocks modification (Read-only) or deletion (Delete) of the resource.
  • Read-only allows only HTTP GET requests
  • ?? You must remove the lock in order to perform forbidden activity.
  • Apply regardless of RBAC permissions
  • ?? Protects against accidental deletion
  • ?? Use to protect key resources that could have a large impact if they were removed or modified
  • Only "Owner" and "User Access Administrator" can create/delete locks

Azure Resource Group

  • Also an Azure resource so it can have locks, tags, RBAC permissions etc.
  • Logical container for resources deployed on Azure.
  • Tied to a region & subscription itself.
  • Helps you organize resources
  • ?? If you delete a resource group, all resources contained within are also deleted.
  • Authorization
  • ? All resources must be in a resource group and a resource can only be a member of a single resource group.
  • ? Some services has specific limitations or requirements to move from one resource group to another
  • ? Can't be nested.
  • Can see history of the deployments to a resource group

Organizing resource groups

  • By type (virtual networks, virtual machines, cosmos dbs)
  • By environment (prod, qa, dev)
  • By department (marketing, finance, human resources)
  • Combining strategies e.g. environment and department:
  • By authorization
  • By life cycle
  • By billing

Management Groups

  • ?? Groups multiple subscriptions.
  • ?? Can have RBAC assignments and policies
  • Good for enterprises
  • E.g.

Compliance in Azure

Microsoft Privacy Statement

  • privacy.microsoft.com/privacystatement
  • ?? Explains what personal data Microsoft processes, how Microsoft processes it, and for what purposes.
  • Applies to the interactions Microsoft has with you and Microsoft products such as Microsoft services, websites, apps, software, servers, and devices.

Microsoft Trust Center

  • microsoft.com/trust-center
  • ?? In-depth information about security, privacy, compliance offerings, policies, features, and practices across Microsoft cloud products.
  • Recommended resources in the form of a curated list of the most applicable and widely used resources for each topic.
  • Direct guidance and support

Service Trust Portal

Compliance Manager

Azure Security Center

  • ?? Global service in Azure that includes regulatory compliance dashboard of your services.
  • Insights into your compliance posture based on continuous assessments
  • Analyzes risk factors in your hybrid cloud environment according to security best practices
  • Overall security score, assessment against e.g. CIS, PCI DSS 3.2.1, SOC, ISO 27001..

Sathvinder Sardar

||EUC Lead || Incident management || IT Support || Technical Support || IT Helpdesk || Service management || Resource Management || ServiceNow

9 小时前

Title - Sr. Azure Data Engineer (urgent requirement) Client – Based in MA United State Location – 100 % Remote Rate - will discuss over a call Need offshore candidate from India. (candidate with no USA visa can only apply ) 1. Analytical skills (Data & SQL) to resolve data issues / prod tickets 2. Strong Coding skills to code Pyspark and debug existing code on Synapse environment 3. Strong Azure experience to understand the environment and resolve any environmental issues. 4. Devops experience/knowledge to take care of CI/CD migrations 5. Expert knowledge and experience on SQLs 6. Work experience on ADFs & Azure Synapse environment 7. Azure certifications mandatory Mail to: [email protected]

回复
Nataraj V

Founder & CEO of Raj Clould Technologies (Raj Informatica) | Coporate Trainer on Informatica PowerCenter 10.x/9.x/8.x, IICS - IDMC (CDI , CAI, CDQ & CDM) , MDM SaaS Customer 360, IDQ and also Matillion | SME | Ex Dell

14 小时前

?Join the group below to discuss? Azure? real-time projects, certifications, and resolve any issues or errors you encounter during real-time work:?? ?https://chat.whatsapp.com/EnrYBU9IFXG2z4XwHS1ZC9

回复

要查看或添加评论,请登录

Anand Raval的更多文章