Azure Storage Basics: How to configure security

แชร์
ฝัง
  • เผยแพร่เมื่อ 15 ก.ค. 2024
  • AZURE STORAGE BASICS: HOW TO CONFIGURE SECURITY - Learn how to make your Azure storage more secure while still easily accessible in the places you need it.
    Do you ever wonder what happens to all those bits and bytes you send to the cloud? Most of them end up in Azure Storage. In this episode of KnowOps, Dana shows us how to make things much safer for all those little bits and keep them from floating off into someone else’s possession.
    --
    Microsoft blog post on moving Storage Analytics data into Log Analytics : azure.microsoft.com/en-us/blo...
    Want to learn more about Kusto Query Language (KQL)?
    www.auditwolf.com/blog/recon-...
    --
    Continue the conversation on social media using the hashtag #knowops. Or join our private LinkedIn group at / 13754782
    We 💖 #azops
    #azure #itops #knowops
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 35

  • @DanaEpp
    @DanaEpp 4 ปีที่แล้ว +10

    Notice a pattern in the last few episodes? Just because you have Cloud IT doesn't mean you should leave your ass(ets) open to the Internet without applying security controls. 🤣

  • @manasr3969
    @manasr3969 2 หลายเดือนก่อน

    This man is a legend. Thanks

  • @sau002
    @sau002 2 ปีที่แล้ว +1

    Nice one.

  • @04chavez
    @04chavez 2 หลายเดือนก่อน

    Great video.

  • @sonasharma7631
    @sonasharma7631 2 ปีที่แล้ว

    Good content. Thanks for sharing

  • @VBH8888
    @VBH8888 2 ปีที่แล้ว

    Who gives this video thumbs down???? As far as I can tell this man is doing more for people than the guy who gave it thumbs down. Who probably isn't doing anything !!!

  • @davidespano8674
    @davidespano8674 3 ปีที่แล้ว +1

    This is an extremely good tutorial on storage accounts. Short, complete, and accurate.

  • @vamsiB13
    @vamsiB13 4 ปีที่แล้ว +2

    Big fan of this channel.

  • @Deekudla
    @Deekudla ปีที่แล้ว

    Awesome video, keep posting Azure cloud security videos.

  • @Deepak9728
    @Deepak9728 3 ปีที่แล้ว

    Really helpful , short , simple and concise.

  • @AttieHeunis
    @AttieHeunis 4 ปีที่แล้ว

    Thanks for another great tutorial. Very useful.

  • @pavantej9666
    @pavantej9666 4 ปีที่แล้ว

    Your really rocking. I like the way you explain and its crystal clear.

  • @sidzhang
    @sidzhang 4 ปีที่แล้ว

    I love your channel, it's really great.

  • @SPPH91
    @SPPH91 2 ปีที่แล้ว

    Thank you so much for the great content. It was very helpful for me.

  • @prodoman3945
    @prodoman3945 ปีที่แล้ว

    Great vid

  • @MarianaWolter
    @MarianaWolter 3 ปีที่แล้ว

    thanks for your advice!

  • @heroics_failed387
    @heroics_failed387 4 ปีที่แล้ว +2

    Loving these videos so far! Can you cover AKS and some tips to keep that secure?

  • @pritomdasradheshyam2154
    @pritomdasradheshyam2154 2 ปีที่แล้ว

    Good content on Azure Storage security essentials!

  • @gtnshgarg76
    @gtnshgarg76 3 ปีที่แล้ว

    Helpful video. You deserve a lot more subscribers. Thanks

  • @mmiltenburg
    @mmiltenburg 3 ปีที่แล้ว

    Great video. Clear fast and full of handy tips.
    Thanks!

    • @KnowOps
      @KnowOps  3 ปีที่แล้ว

      Glad it was helpful!

  • @starmole5000
    @starmole5000 3 ปีที่แล้ว

    This is amazing thanks!

  • @soucianceeqdamrashti8175
    @soucianceeqdamrashti8175 2 ปีที่แล้ว

    Very nice tip to use Azure Automation to create SAS tokens and update secret in KeyVault. I normally use Azure RBAC for accessing storage and disable access keys completely but good to know about this fully automated approach too.

  • @stefanforest7582
    @stefanforest7582 3 ปีที่แล้ว +1

    Only 2500 views :( ... the channel is great, I love it.

  • @hillelcohen3878
    @hillelcohen3878 2 ปีที่แล้ว

    Thanks for this and all your other videos. Do you by any chance have a video on generating a sas key in key vault as you mentioned in this video?
    Thanks

  • @sadhu39
    @sadhu39 2 ปีที่แล้ว

    Great tutorial! Can you please help on how to achieve folder security within a container.

  • @rizsyedvoice
    @rizsyedvoice 4 ปีที่แล้ว

    Awesome work Dana … Can you do a video for this scenario -- Have a windows VM and have few files in storage account--- When I run a PS script in VM, it should access the storage account using Manage Identity .. right now we are using Keyvault for this procedure.

  • @sid0000009
    @sid0000009 4 ปีที่แล้ว +1

    hello, may be you could possibly add something related to the difference btw ACL and RBAC ways of providing access to Gen2. Something which interests to a administrator as well.. thanks

  • @Shravan_Reddy
    @Shravan_Reddy ปีที่แล้ว

    To your point on MSFT managed keys. How does microsoft encrypt/decrypt storage if we use user-managed keys? Thanks in advance.

  • @Shravan_Reddy
    @Shravan_Reddy ปีที่แล้ว

    Can you make more Azure videos please?

  • @gbuad3964
    @gbuad3964 2 ปีที่แล้ว

    Thanks for this video. My issue with the Azure Storage tutorials I have followed so far, is that my server side code (the API) is running with full admin priviledges to the storage account and uses code to hand out SAS keys to clients. This must be bad practise! I want the code to run with minimal priviledges.
    You address this at 5:40 - 6:10 in the video. Could you please point me towards info on how to actually implement this?

  • @prodoman3945
    @prodoman3945 ปีที่แล้ว +1

    why did you stop uploading

  • @BluesOverdrive
    @BluesOverdrive 4 ปีที่แล้ว

    Hi Dana, great channel I watched all of your videos. Would you mind to comment on the following extract from Microsoft: "Authorizing requests against Azure Storage with Azure AD provides superior security and ease of use over Shared Key authorization. Microsoft recommends using Azure AD authorization with your blob and queue applications when possible to minimize potential security vulnerabilities inherent in Shared Key." Source: docs.microsoft.com/en-gb/azure/storage/common/storage-auth-aad. From my understanding when talking about "Shared Key", MS is referring to SAS, am I getting this right? It seems that by using AAD authentication developers would not need an Access Key or SAS to access the storage as the application or VM can get direct access with RBAC permission using a Managed Identity.

  • @James-sc1lz
    @James-sc1lz 2 ปีที่แล้ว +1

    Do not use disk based encryption or at least be really, really careful with It. If you have a file server it rules out file restores and you can only restore the vm and there is no turning back when done. I find it completely unacceptable Microsoft have It in the advisory with out any mention of the risks but that’s typical Microsoft. Microsoft are absolutely dreadful at communicating issues and gotchas like this. You need to,do your own research. Don’t just listen to what people say.Do your research and don’t rely on one person or one article, especially just relying on Microsoft docs. A lot of them are poorly written, out of date or lacking in informing people of potential risks. Can you imagine having a Few TBs file server and using disk based encryption and then not being able to revert back?