Book Image

Azure Stack Hub Demystified

By : Richard Young
Book Image

Azure Stack Hub Demystified

By: Richard Young

Overview of this book

Azure Stack Hub is the on-premise offering from Microsoft, which provides Azure Cloud services within a customer's own data center. It provides consistent processes between on-site and the cloud, allowing developers to test locally and deploy to the cloud in exactly the same manner. Azure Stack Hub Demystified provides complete coverage of deploying, configuring, administrating, and running Microsoft Azure Stack Hub efficiently. Firstly, you will learn how to deploy Azure Stack Hub within an organization. As you progress, you'll understand configuration and the different services provided by the platform. The book also focuses on the underlying architecture and connectivity options for the modern data center. Later, you will understand various approaches to DevOps and their implementation, and learn key topics for the AZ-600 exam. By the end of this Azure book, you will have a thorough understanding of Azure Stack Hub and the services that are provided by the platform, along with the confidence and information you need to be able to pass the AZ-600 exam.
Table of Contents (21 chapters)
1
Section 1: Architecture and Deployment
5
Section 2: Identity and Security
9
Section 3: Features
15
Section 4: Monitoring, Licensing, and Billing

Understanding the benefits of a locked system

The benefits of a locked system start from the hardware used to deploy Azure Stack Hub. As we have learned in previous chapters, the Azure Stack Hub solution provided by OEM vendors such as Lenovo, Dell, HPE, and Cisco is an integrated system. This means that the hardware and software is known at deployment time. This gives us a few security advantages, which are detailed as follows:

  • List of software components: Applications are whitelisted, and Device Guard ensures that only Microsoft-signed software is deployed.
  • OS dependencies: Azure Stack Hub includes a customized OS configuration with unnecessary legacy applications removed.
  • Known hardware characteristics: All OEM vendors have data at rest enabled by default.

These properties are the same regardless of which OEM vendor is chosen by the organization and all integrated systems are certified by Microsoft.

The next property that affords a security benefit in this...