Supports Identity protection. Centralized view of risks, access to all Cloud, etc. Single tool to provide an easy deployment experience for synchronization and sign-in.

Users can use a single identity to access on-premises applications and cloud services such as Office This can be used by organizations to address complex deployments, such as domain join SSO, enforcement of AD sign-in policy, and smart card or 3rd party MFA.

Azure AD Synchronization This component is responsible for creating users, groups, and other objects. It is also responsible for making sure identity information for your on-premises users and groups is matching the cloud. Identity Protection uses adaptive machine learning algorithms and heuristics to detect anomalies and risk events that may indicate that an identity has been compromised.

Identity is automatically trusted, but als removed when resources are deleted. Azure Key Vault provides a way to securely store credentials and other keys and secrets, but your code needs to authenticate to Key Vault to retrieve them.

Works with a token and time intervals. User does not have to provide username and password to Azure. Considerations regarding Active Directory: My organization has made large investments in on-premises Windows Server Active Directory, but we want to extend identity to the cloud. The most widely used Azure identity solution is hybrid identity.

My business was born in the cloud and we have no investments in on-premises identity solutions. Azure Active Directory is the best choice for cloud-only businesses with no on-premises investments.

I need lightweight Azure VM configuration and control to meet on-premises identity requirements for app development and testing. Azure AD Domain Services is a good choice if you need to use AD DS for lightweight Azure VM configuration control or are looking to develop or migrate legacy, directory-aware on-premises applications to the cloud. Hybrid Identities Hybrid entities: Mixure of cloud and on prem network. Allows one identity regardless where the apps are hosted.

SAML tokens are called claims. SAML tokens are signed. Responsibility is turned over to a 3rd party. No need to have a VPN. Authentication through the proxy. Uses inbound and outbound rules. Default; only allows outbound. No inbound. ARM only. For Block blobs, page blobs and append blobs. Client side encryption is possible as well. Wire encryption, such as SMB 3. Client-side encryption, to encrypt the data before it is transferred into storage and to decrypt the data after it is transferred out of storage.

Encryption at rest: Storage Service Encryption allows you to request that the storage service automatically encrypt data when writing it to Azure Storage. All data written to Azure Storage is encrypted through bit AES encryption, one of the strongest block ciphers available. Storage Service Encryption is enabled for all new and existing storage accounts and cannot be disabled.

Because your data is secured by default, you don't need to modify your code or applications to take advantage of Storage Service Encryption. Client-side Encryption also provides the feature of encryption at rest. The solution is integrated with Azure Key Vault to help you control and manage the disk-encryption keys and secrets in your key vault subscription. Role-Based Security Concept is to give roles access rights and assign the roles to groups and users.

Reader can view existing Azure resources. Access inheritance. Azure subscription belongs to only one AAD. Azure group belongs to only one subscription.

Resource belongs only to one group. Entities can have up to properties columns. Timestamp is always included. Elastic and auto-scales. Azure hosted database. Geo-replication optional. Blob Storage: Container model Containers have security. Block blobs are idea for large binary or text file storage that don't need to be frequently read from or accessed to. Block blobs support up to 50, blocks of up to MB each, or approximately 4.

Cool and Archive options: Cool early deletion period of 30 days. Archive early deletion period of days. Append blobs: Similar to block blobs but optimized for append only log files. Page blobs: Good for random writes, represents harddisk, virtual machine storage. Page blobs are better for Virtual machine VHD files. Queue Storage: Max 64gb in size. Invisibility behavior, read and then becomes invisible for a period of time. Useful for legacy systems. Can create directories. Each file can be up to 1TB.

Files are addressable by a private URL. Needs a license. Assign right roles. Avoid anonymous access. Encryption can use SSL as well. You want to "lift and shift" an application to the cloud which already uses the native file system APIs to share data between it and other applications running in Azure. You want to store development and debugging tools that need to be accessed from many virtual machines. You want your application to support streaming and random access scenarios.

You want to be able to access application data from anywhere. Files within the VHD cannot be accessed. Provides client libraries and a REST interface that allows data to be persistently stored and accessed from an attached virtual hard disk.

You want to lift and shift applications that use native file system APIs to read and write data to persistent disks. You want to store data that is not required to be accessed from outside the virtual machine to which the disk is attached.

Offline Sync: allows to use the mobile app offline and sync mobile client data once it becomes online. Uses implicit push and incremental pull model. Extend Mobile Apps: Services to provide essential functions for mobile apps, such as custom authentication push, notifications, data storage. Security: Two levels: Infrastrcture and platform security, Application Security. Uses single API. Also supports. Can target single user, group or all users.

Allows tagging for sementation. Can security notification, so the app pulls the data secure after receiving the notification. Verifies the request and populates a result based on the model. Integrated with Visual Studio. Scaling Web API: For the vm you can either, upgrade to a higher hosting place, change the tier, instance size and instance count horizontal scaling. Can be used with traffic manager to grow across regions and geos.

Web Jobs: Continuously running jobs or predefined scheduled jobs. Can scale by having more instances. Monitoring or tokens. Audit, logging, validation of inputs, SSL or cryptographic. The Service Bus Relay runs in the cloud accepts the request and securely passes on that request to the WCF service running indside the corp network. Azure Relay has two features: Hybrid Connections - Uses the open standard web sockets enabling multi-platform scenarios.

