Book Image

Azure Architecture Explained

By : David Rendón, Brett Hargreaves
Book Image

Azure Architecture Explained

By: David Rendón, Brett Hargreaves

Overview of this book

Azure is a sophisticated technology that requires a detailed understanding to reap its full potential and employ its advanced features. This book provides you with a clear path to designing optimal cloud-based solutions in Azure, by delving into the platform's intricacies. You’ll begin by understanding the effective and efficient security management and operation techniques in Azure to implement the appropriate configurations in Microsoft Entra ID. Next, you’ll explore how to modernize your applications for the cloud, examining the different computation and storage options, as well as using Azure data solutions to help migrate and monitor workloads. You’ll also find out how to build your solutions, including containers, networking components, security principles, governance, and advanced observability. With practical examples and step-by-step instructions, you’ll be empowered to work on infrastructure-as-code to effectively deploy and manage resources in your environment. By the end of this book, you’ll be well-equipped to navigate the world of cloud computing confidently.
Table of Contents (20 chapters)
1
Part 1 – Effective and Efficient Security Management and Operations in Azure
5
Part 2 – Architecting Compute and Network Solutions
12
Part 3 – Making the Most of Infrastructure-as-Code for Azure

Network security

Imagine SpringToys is spread across multiple Azure regions, and their infrastructure includes multiple virtual networks and connections to an on-premises network. The SpringToys IT team is looking for options to protect its assets against malicious actors trying to infiltrate the network and web applications.

In this section, we will discuss the core services available in Azure that help secure network connections and communications. We will highlight the following:

  • Azure DDoS Protection
  • Azure Firewall
  • Azure WAF

Let’s start by reviewing how SpringToys can leverage Azure DDoS Protection to improve its security posture.

Azure DDoS protection

First, let’s set the stage and agree on terminology. DDoS stands for Distributed Denial of Service – a type of cyber-attack in which many devices, often infected with malware, are used to flood a targeted website or server with a huge amount of fake traffic.

The goal of a DDoS...