Microsoft Cybersecurity Architect (SC-100) flashcards
131 free flashcards. Tap a card to flip it.
Azure Key Vault
Flip cardA cloud service for securely storing and accessing secrets, keys, and certificates. It provides a centralized, hardened, high-availability solution for managing cryptographic keys and other secrets.
- Encrypts secrets at rest and in transit.
- Supports automatic secret rotation and versioning.
- Integrates with other Azure services for secure access (e.g., Managed Identities, AAD Pod Identity/Workload Identity).
Memory trick: Key Vault: Your Secret's Safe Haven in the Cloud.
Cosmos DB Client-Side Encryption
Flip cardAn encryption method where sensitive data fields within Cosmos DB documents are encrypted by the client application before being sent to the database, ensuring data is encrypted before it leaves the client and only authorized clients can decrypt it.
- Encryption occurs on the client application side.
- Keys are managed by the client application, not the database service.
- Protects data in transit and at rest from the database perspective.
- Ideal for strong PII protection and regulatory compliance (e.g., GDPR).
Memory trick: Client-side encryption: Your app locks before it sends.
Client-side encryption (Cosmos DB)
Flip cardA method where the client application encrypts sensitive data before sending it to Azure Cosmos DB, ensuring the data remains encrypted from the database service's perspective, protecting it from privileged access within the cloud provider.
- Encryption happens at the client application layer
- Cosmos DB stores only encrypted data
- Keys are managed by the client application
- Provides 'zero-trust' data protection from the backend
Memory trick: Client-side encryption puts the key in YOUR hand.
Application-Level Encryption
Flip cardEncryption performed by the application itself before data is stored in a database or storage service, allowing granular control over which data is encrypted and who holds the keys.
- Protects data even if the underlying storage service is compromised.
- Enables column-level or field-level encryption.
- Requires the application to manage encryption/decryption keys and processes.
Memory trick: App-Level Encryption for Column-Level Secrets.
Always Encrypted with Secure Enclaves
Flip cardA feature in Azure SQL Database that enables data to remain encrypted while being processed in the database engine, using secure enclaves to protect sensitive data from unauthorized access.
- Data is always encrypted, at rest, in transit, and during processing.
- Protects data from database administrators and cloud operators.
- Requires client-side encryption and a secure enclave for computations.
Memory trick: Always Encrypt, even when SQL is doing its sum work!
Private Connectivity for PaaS
Flip cardAzure Private Link and VNet Integration for App Service enable secure, private connectivity between Azure PaaS services and resources within a Virtual Network, ensuring data in transit is isolated from the public internet.
- Azure Private Link creates private endpoints for PaaS services.
- Traffic to private endpoints stays on the Microsoft backbone.
- VNet Integration allows App Service to access VNet resources.
- Ensures data in transit is encrypted and isolated from the public internet.
Memory trick: Private Link and VNet Integration secure your PaaS connections.
Device Management Solution (Zero Trust)
Flip cardA system (e.g., MDM, MAM) used to manage and secure devices accessing corporate resources, ensuring they meet defined security standards and compliance policies.
- Assesses device health (antivirus, patches, encryption).
- Enforces security configurations.
- Integrates with Conditional Access for policy-based access decisions.
- Crucial for securing endpoints in a Zero Trust model.
Memory trick: Devices must be 'Managed' to be 'Trusted'.
Azure AD B2B Collaboration
Flip cardA feature of Azure Active Directory that enables secure sharing of applications and resources with external users from any organization, while maintaining control over corporate data.
- External users sign in with their own identities.
- Managed as guest users in the host tenant.
- Supports Conditional Access policies for guest access.
Memory trick: B2B: Bring Your Own Identity, Get Our Access Control.
Conditional Access Policies
Flip cardAzure AD Conditional Access policies are if-then statements: if a user wants to access a resource, then they must complete an action. These policies enable organizations to enforce specific authentication and authorization requirements based on various conditions, such as user location, device state, or application being accessed.
- If-then statements for access
- Enforce specific requirements based on conditions
- Granular control over access
- Integrates with MFA, device compliance, etc.
Memory trick: Conditions dictate who gets access and how.
Azure Blob Immutability Policy
Flip cardAn Azure Blob Storage feature that allows users to store business-critical data in a Write Once, Read Many (WORM) state, ensuring that data cannot be modified or deleted for a specified retention interval or until a legal hold is removed.
- Prevents deletion and modification of blobs.
- Supports time-based retention and legal hold.
- Protects against accidental deletion, ransomware, and insider threats.
- Compliance with regulatory requirements (e.g., SEC 17a-4(f)).
Memory trick: Immutability Locks Data Down Tight.
Microsoft Sentinel
Flip cardA cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides intelligent security analytics and threat intelligence across the enterprise.
- Ingests data from diverse sources (Azure, AWS, Google Cloud, on-premises, other security solutions).
- Uses AI and machine learning for threat detection.
- Enables automated response to security incidents.
Memory trick: Sentinel Sees All Security, Everywhere.
Azure AD Application Proxy
Flip cardA service that enables secure remote access to on-premises web applications through Azure Active Directory.
- Publishes internal web apps externally.
- Integrates with Azure AD for authentication and Conditional Access.
- Eliminates the need for VPN or DMZ for remote access.
Memory trick: App Proxy bridges the gap, securing legacy apps with cloud identity.
Azure ExpressRoute
Flip cardA service that creates private connections between Azure data centers and on-premises infrastructure or a colocation environment.
- Bypasses the public internet, offering enhanced security.
- Provides higher bandwidth and lower latency than VPNs.
- Ideal for hybrid cloud scenarios with critical workloads.
Memory trick: ExpressRoute is like a private highway, not a public road.
Identity-Based Micro-segmentation (AKS Multi-tenant)
Flip cardA security approach that enforces granular network access policies between individual workloads (e.g., pods) within a shared Kubernetes cluster based on cryptographic identities.
- Enforces 'least privilege' at the workload level.
- Uses cryptographic identities for authentication and authorization.
- Prevents lateral movement and cross-tenant data leakage in shared environments.
Memory trick: Identity micro-segmentation: Each pod has its own secure ID.
Policy Enforcement Point (PEP)
Flip cardA Zero Trust component that sits in the path to a resource, intercepting access requests and enforcing the access decision made by the Policy Decision Point.
- Grants, denies, or revokes access.
- Acts as the 'gatekeeper' to resources.
- Crucial for enforcing policies without modifying applications.
Memory trick: PEP: The Gatekeeper That Enforces Policy.
Azure Private Link for Key Vault
Flip cardA networking service that provides private connectivity to Azure Key Vault from a virtual network, allowing secure access over a private endpoint and isolating the Key Vault from the public internet.
- Creates a private endpoint in your VNet for Key Vault.
- Access to Key Vault via private IP address only.
- Traffic stays on the Microsoft backbone.
- Enhances security by eliminating public internet exposure.
Memory trick: Private Link keeps Key Vault Private from the Public.
Least Privilege Access (Zero Trust)
Flip cardA core Zero Trust principle that dictates users and systems should only be granted the minimum necessary permissions to perform their tasks, and only for the minimum necessary duration.
- Includes Just-in-Time (JIT) and Just-Enough Access (JEA).
- Reduces the attack surface and potential damage from compromise.
- Requires continuous monitoring and periodic review of permissions.
Memory trick: Least Privilege: Just Enough, Just In Time.
Azure Information Protection (AIP) / Microsoft Purview Information Protection
Flip cardA cloud-based solution that helps organizations discover, classify, and protect sensitive documents and emails by applying labels.
- Provides persistent data protection regardless of location.
- Enables manual, recommended, or automatic classification and labeling.
- Supports encryption, visual markings, and usage rights restrictions.
- Integrates with Microsoft 365 services and on-premises solutions.
Memory trick: AIP/Purview: Always Insist on Protecting via Labels.
End-to-End Encryption (Zero Trust)
Flip cardA Zero Trust security capability that ensures all data in transit, regardless of its network location or internal/external status, is cryptographically protected from the source to the destination.
- Protects data even if the network is compromised.
- Supports the 'assume breach' principle.
- Applies to communication within and between network segments.
Memory trick: Encrypt All Data, Everywhere, Always.
SD-WAN Integration (Zero Trust for Hybrid/Multi-Cloud)
Flip cardIntegrating Software-Defined Wide Area Network (SD-WAN) with security services to provide secure, optimized, and centrally managed connectivity for distributed environments.
- Optimizes traffic routing for cloud applications.
- Enables centralized security policy enforcement at the network edge.
- Reduces reliance on backhauling all traffic to a central data center.
- Often combined with SASE (Secure Access Service Edge) for comprehensive security.
Memory trick: SD-WAN: Securely Distribute, With Advanced Networking.
Jump Server with Data Diode (OT Zero Trust)
Flip cardA secure access pattern for Operational Technology (OT) networks using a hardened intermediary server (jump server) combined with a data diode for unidirectional data flow.
- Jump server acts as a controlled access point.
- Data diode enforces one-way communication (e.g., IT to OT only).
- Provides air-gapped security benefits with controlled remote access.
Memory trick: Jump through the Diode to reach the OT safe zone.
Zero Trust Network Enforcement
Flip cardA security model where no user, device, or application is implicitly trusted, regardless of their location. Every access request is authenticated, authorized, and constantly validated, with encryption applied to traffic.
- Verify explicitly, always authenticate and authorize.
- Assume breach, minimize blast radius.
- Least privilege access.
- Encrypt all traffic, inspect all traffic.
Memory trick: Never Trust, Always Verify, Firewall and Private Link make it fly.
Azure Virtual WAN
Flip cardA networking service that provides a unified interface for managing large-scale enterprise networks, connecting branches, data centers, and VNets through a hub-and-spoke architecture with integrated security and routing.
- Centralized network management.
- Integrated security and routing functions.
- Scalable for global deployments.
- Supports various connectivity types (VPN, ExpressRoute).
Memory trick: Virtual WAN Connects Everything Securely and Centrally.
Static Application Security Testing (SAST) & Dynamic Application Security Testing (DAST)
Flip cardSAST analyzes application source code for vulnerabilities without executing it, while DAST tests the running application for vulnerabilities by simulating attacks.
- SAST: 'White-box' testing, ideal for early detection in development.
- DAST: 'Black-box' testing, finds runtime vulnerabilities and configuration issues.
- Both are crucial for a comprehensive DevSecOps security strategy.
- Integrate into CI/CD pipelines for automated and continuous security.
Memory trick: SAST/DAST: Secure Apps, Start Today, Detect Attacks Sooner, Test.
Micro-segmentation (Zero Trust)
Flip cardA security technique that divides data centers and cloud environments into small, isolated network segments down to the workload level, enabling granular security policies to be applied to each segment.
- Limits lateral movement of threats.
- Enforces granular security policies.
- Reduces the attack surface by isolating workloads.
Memory trick: Networks need Micro-segmentation and Policy-based access, not just a perimeter.
Verify Explicitly
Flip cardA core Zero Trust principle requiring all access requests to be authenticated and authorized based on all available data points, rather than implicit trust.
- No implicit trust is granted.
- Evaluates user, device, location, data sensitivity, and other attributes.
- Forms the basis for dynamic access policies.
Memory trick: Trust No One, Verify Everyone, Grant Least.
Verify Explicitly (Zero Trust)
Flip cardA core Zero Trust principle requiring all access requests to be authenticated and authorized based on all available data points, rather than implicit trust.
- No implicit trust is granted.
- Authentication and authorization are continuous.
- Considers user identity, device health, location, data sensitivity, and anomaly detection.
Memory trick: Always Be Explicitly Least Privileged, Assuming Breach.
Identity-Based Multi-Tenant Isolation
Flip cardIn a multi-tenant Zero Trust architecture, logical separation and access control are primarily achieved by rigorously enforcing identity-based policies, ensuring users and applications can only access resources belonging to their assigned tenant.
- Crucial for SaaS providers.
- Leverages tenant IDs and user identities for authorization.
- Applies at the application and data layer, not just network.
Memory trick: Identity Isolates Tenants in Shared Spaces.
Hub-and-Spoke Network Topology
Flip cardA networking model in Azure where a central 'hub' virtual network acts as a core point for connectivity and shared services (like firewalls), and 'spoke' virtual networks peer with the hub to host isolated workloads.
- Centralizes network security services (e.g., Azure Firewall).
- Provides isolation for workloads in spoke VNets.
- Simplifies network management and policy enforcement.
- Commonly used for enterprise cloud deployments and DMZ implementations.
Memory trick: Hub is the Center, Spoke is the Edge, for secure networks.
Microsoft Defender for Cloud (Multi-Cloud CSPM)
Flip cardA unified security management solution that provides security posture management and threat protection across Azure, AWS, and GCP.
- Offers Cloud Security Posture Management (CSPM) capabilities.
- Provides Cloud Workload Protection (CWP) for various resources.
- Supports continuous assessment of security posture against benchmarks.
- Enables automated remediation and integrates with security tools.
Memory trick: Defender for Cloud: Defends All Clouds, Continuously.
Continuous Access Evaluation (CAE)
Flip cardAn Azure AD feature that enables real-time enforcement of Conditional Access policies by allowing immediate revocation of access tokens upon detecting critical events.
- Real-time access policy enforcement.
- Revokes tokens immediately, not waiting for expiration.
- Responds to critical events like location change, device non-compliance, or risk increase.
Memory trick: CAE constantly checks, revoking access if conditions change.
Azure AD PIM
Flip cardAzure Active Directory Privileged Identity Management (PIM) is a service in Azure AD that enables you to manage, control, and monitor access to important resources in your organization.
- Provides just-in-time (JIT) privileged access.
- Facilitates regular access reviews for privileged roles.
- Enables multi-factor authentication for role activation.
Memory trick: PIM protects Privileged Identities, while Conditional Access controls conditions.
Azure Policy for Governance
Flip cardAzure Policy helps to enforce organizational standards and to assess compliance at scale. It provides a centralized way to define rules and apply them to resources, ensuring consistent configurations across environments.
- Enforces organizational standards and assesses compliance.
- Prevents non-compliant resource creation or modification.
- Can be applied at Management Group, subscription, or resource group scope.
- Includes audit, deny, deploy if not exists, and modify effects.
Memory trick: Policy Governs, Management Groups Scope, Compliance Ensured.
Azure AD Privileged Identity Management (PIM)
Flip cardAn Azure AD service that enables management, control, and monitoring of access to important resources in Azure AD, Azure, and other Microsoft Online Services.
- Provides Just-In-Time (JIT) access to privileged roles.
- Enforces Just-Enough-Access (JEA) principles.
- Includes approval workflows for role activation.
- Automates deactivation of privileges after a set time.
Memory trick: PIM: Privileged, In-time, Managed.
Cloud Access Security Broker (CASB)
Flip cardA software tool or service that acts as an intermediary between users and cloud service providers, ensuring security policies are enforced.
- Provides visibility into cloud application usage.
- Enforces data security policies (e.g., DLP, encryption).
- Protects against threats and ensures compliance.
- Can integrate with various identity providers and environments.
Memory trick: CASB: Centralizing Access Security for Broad Reach.
Privileged Access Workstations (PAWs)
Flip cardHighly secured, dedicated workstations used by administrators and other privileged users to perform sensitive tasks. PAWs are hardened, isolated from general-purpose networks, and configured to minimize attack surface, reducing the risk of credential theft and malware compromise.
- Dedicated for privileged users
- Hardened and isolated
- Minimizes attack surface
- Reduces risk of credential theft
Memory trick: PAWs are the king's dedicated, uncompromisable fortress.
Azure Firewall Premium Capabilities
Flip cardAzure Firewall Premium extends the capabilities of Azure Firewall Standard with advanced threat protection, including TLS inspection, URL filtering, and an Intrusion Detection and Prevention System (IDPS).
- TLS inspection for encrypted traffic.
- URL filtering for granular outbound access control.
- IDPS for network-based threat detection.
- Suitable for highly sensitive and regulated environments.
Memory trick: Premium Firewall Inspects Everything before it Exits.
SAST and DAST (DevSecOps Zero Trust)
Flip cardAutomated security testing methods integrated into the DevSecOps pipeline to identify vulnerabilities in source code (SAST) and running applications (DAST).
- SAST: Static analysis, 'white box' testing, early detection.
- DAST: Dynamic analysis, 'black box' testing, finds runtime issues.
- Crucial for 'shifting left' security in Zero Trust development.
Memory trick: SAST and DAST find bugs before they blast.
Azure Front Door with WAF
Flip cardA global, scalable, and secure entry point for web applications and APIs that provides application acceleration, global load balancing, and WAF capabilities to protect against common web exploits and manage traffic.
- Global service, operates at the edge.
- Integrated Web Application Firewall (WAF).
- Protects against common web exploits and bots.
- Supports geo-filtering and IP-based access control.
Memory trick: Front Door guards your global web apps at the very edge.
Microsoft Defender for Cloud
Flip cardA cloud-native solution that provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across multi-cloud (Azure, AWS, GCP) and hybrid environments. It helps organizations strengthen their security posture, protect against threats, and ensure compliance with regulatory standards.
- CSPM and CWP capabilities
- Supports multi-cloud (Azure, AWS, GCP)
- Strengthens security posture
- Protects against threats
Memory trick: Defender for Cloud watches over all your cloud castles.
Azure Blob Storage Tiers
Flip cardAzure Blob Storage offers different access tiers (Hot, Cool, Archive) to optimize costs based on data access patterns and retention needs.
- Hot: Frequently accessed data, higher storage cost, lower access cost.
- Cool: Infrequently accessed data (30+ days), lower storage cost, higher access cost.
- Archive: Rarely accessed data (180+ days), lowest storage cost, highest access cost (latency in hours).
Memory trick: Hot, Cool, Archive: The data temperature zones.
Use Least Privilege Access (Zero Trust)
Flip cardA core Zero Trust principle that mandates granting users and systems only the minimum necessary permissions to perform their tasks, for the shortest possible duration.
- Minimizes the attack surface.
- Limits the impact of a compromised account.
- Often implemented with Just-In-Time (JIT) and Just-Enough-Access (JEA).
- Applies to users, applications, and devices.
Memory trick: Trust No One, Verify Everyone, Grant Least.
Azure Private Link for PaaS
Flip cardAzure Private Link enables you to access Azure PaaS services (like Azure Storage and Azure Key Vault) over a private endpoint in your virtual network. Traffic between your VNet and the service travels across the Microsoft backbone network, eliminating exposure to the public internet.
- Connects to Azure PaaS services privately.
- Traffic stays on the Microsoft backbone network.
- Eliminates public internet exposure.
- Enhances security by providing dedicated private access.
Memory trick: Private Link Leads to Isolated PaaS, Public Endpoints Have Risks.
Azure Information Protection (AIP)
Flip cardA cloud-based solution that helps organizations classify, label, and protect their documents and emails. It applies encryption, rights management, and visual markings, ensuring that protection travels with the data itself, regardless of where it's stored or shared.
- Classifies, labels, and protects documents/emails
- Protection travels with the data
- Uses encryption and rights management
- Supports on-premises and cloud data
Memory trick: AIP puts a secure wrapper directly on your sensitive files.
Microsoft Defender for Cloud (CSPM & CWP)
Flip cardA unified security solution that helps strengthen the security posture of cloud environments and protect workloads running in Azure, AWS, and GCP.
- Combines Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP).
- Provides continuous assessment of security configurations and compliance.
- Detects threats and offers recommendations for remediation.
- Supports multi-cloud and hybrid environments.
Memory trick: Defender for Cloud: Defends All Clouds, Posture and Workloads.
Azure Dedicated Hosts
Flip cardA service that provides physical servers dedicated to a single Azure customer, offering hardware isolation for highly sensitive workloads.
- Single-tenant physical servers for maximum isolation.
- Allows control over server maintenance events and patching.
- Ideal for compliance, licensing, and high-security requirements.
Memory trick: Dedicated Hosts are your own PRIVATE island in the cloud.
Azure AD Conditional Access
Flip cardA feature of Azure Active Directory that enables organizations to enforce policies to control access to resources based on specific conditions.
- Centralized policy enforcement.
- Evaluates conditions like user, device, location, application, and sign-in risk.
- Supports both cloud and hybrid resources integrated with Azure AD.
Memory trick: Conditional Access is the Central Gatekeeper for Hybrid Resources.
SD-WAN Integration (Zero Trust)
Flip cardIntegrating Software-Defined Wide Area Network (SD-WAN) solutions into a Zero Trust architecture provides secure, optimized, and centrally managed network connectivity across hybrid and multi-cloud environments. It enables dynamic routing, encryption, and often integrates with security services for threat inspection at the network edge, extending Zero Trust principles to the network fabric.
- Secure, optimized hybrid/multi-cloud connectivity
- Centralized network management
- Enables dynamic routing and encryption
- Integrates with security services for inspection
Memory trick: SD-WAN weaves a secure fabric across all your locations.
Privileged Access Workstation (PAW)
Flip cardA dedicated, hardened operating system designed for sensitive tasks and privileged accounts, providing a high level of security against compromise.
- Isolated from general corporate networks.
- Enforces strict application whitelisting.
- Prevents data exfiltration and resists malware.
Memory trick: PAW: Protect All Workstations with high privilege.
Dynamic Access Policies (Continuous Access Evaluation)
Flip cardA Zero Trust mechanism that enables the continuous re-evaluation of access during an active session based on real-time signals, such as changes in user location, device posture, or detected risk events. It ensures that trust is never implicit and access can be revoked immediately if risk conditions change.
- Continuous re-evaluation during active session
- Based on real-time signals
- Revokes access immediately if risk changes
- Never implicit trust
Memory trick: Access is a constantly moving target, always re-checked.
Azure Active Directory (Azure AD)
Flip cardMicrosoft's cloud-based identity and access management service, providing identity for users, groups, and applications.
- Central component for Zero Trust implementation in Azure.
- Supports single sign-on (SSO), multi-factor authentication (MFA), and conditional access.
- Integrates with on-premises Active Directory.
Memory trick: Zero Trust: Never Trust, Always Verify, Constantly Monitor.
Customer-Managed Keys (CMK) in Azure
Flip cardA feature that allows customers to manage their own encryption keys for data at rest in Azure services, often using Azure Key Vault. This provides greater control over key lifecycle, including rotation and revocation, for compliance and security.
- Customer controls encryption keys.
- Keys stored securely in Azure Key Vault.
- Enables key rotation and revocation.
- Meets stringent regulatory and compliance requirements.
Memory trick: Customer-Managed Keys in Key Vault give you full control.
Secure Access Service Edge (SASE)
Flip cardA cloud-native architecture that converges network security functions (FWaaS, SWG, CASB, ZTNA) with WAN capabilities into a single, integrated service.
- Combines networking and security.
- Delivered as a cloud service.
- Supports distributed workforces and multi-cloud environments.
Memory trick: SASE: Secure All Services Everywhere.
Azure Policy & Automation for VM Security
Flip cardAzure Policy enforces organizational standards and assesses compliance at scale. Azure Automation helps manage and automate tasks, including the remediation of non-compliant resources identified by Azure Policy.
- Azure Policy defines and enforces resource configurations.
- Monitors for configuration drift.
- Azure Automation executes remediation actions.
- Ensures continuous compliance and security baselines.
Memory trick: Policy sets the rules, Automation fixes the flaws.
Data Diode (Unidirectional Gateway)
Flip cardA cybersecurity device that enforces one-way data transfer, allowing data to flow in only one direction for absolute network separation.
- Physically prevents data from flowing in the reverse direction.
- Used for high-security environments like OT/ICS or classified networks.
- Ensures data integrity and prevents inbound cyberattacks.
- Allows for secure data export (e.g., logs, sensor data) from sensitive networks.
Memory trick: Diode: Data In, Out, Don't reverse, Ever.
Microsoft Defender for Cloud (CSPM)
Flip cardA unified security management platform that provides Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across multi-cloud and hybrid environments.
- Continuous security assessment and recommendations.
- Compliance tracking against industry benchmarks.
- Covers Azure, AWS, GCP, and on-premises resources.
Memory trick: Defender for Cloud: The all-seeing eye for multi-cloud security.
Azure Front Door Premium with WAF
Flip cardA global, scalable entry-point that uses the Microsoft global edge network to create fast, secure, and widely scalable web applications. It includes CDN, WAF, and advanced security features.
- Provides global load balancing and intelligent routing.
- Integrates Web Application Firewall (WAF) for advanced threat protection.
- Offers CDN capabilities for content caching and acceleration.
- Operates at the edge, reducing latency for global users.
Memory trick: Front Door is your global guard, fast and secure for all your web apps.
Cosmos DB CMK with Key Vault
Flip cardAzure Cosmos DB supports customer-managed keys (CMK) for data encryption at rest. This feature allows customers to encrypt their data using encryption keys stored in Azure Key Vault, providing full control over the key lifecycle, including generation, rotation, and revocation.
- Customer retains full control over encryption keys.
- Keys are stored and managed in Azure Key Vault.
- Encrypts data at rest in Cosmos DB.
- Enhances compliance for highly sensitive data.
Memory trick: CMK is Customer's Key, Service Manages its Own, Client Encrypts Before.
Confidential Computing
Flip cardConfidential Computing protects data while it's in use by performing computations within a hardware-based Trusted Execution Environment (TEE), ensuring the data remains encrypted and inaccessible to the host operating system, hypervisor, or other unauthorized entities.
- Protects data in-use (during computation).
- Utilizes hardware-based Trusted Execution Environments (TEEs).
- Prevents unauthorized access to sensitive data even from cloud administrators.
- Examples include secure enclaves for SQL Server Always Encrypted.
Memory trick: Compute Confidentially, Encrypt Everything, Key Control is King.
Azure AD B2B
Flip cardAzure Active Directory B2B (Business-to-Business) collaboration allows you to securely share your applications and services with external users from any organization.
- External users sign in with their own credentials.
- Supports multi-factor authentication from their home tenant.
- Facilitates collaboration across different Azure AD tenants.
Memory trick: B2B for Business, B2C for Consumers.