Lesson 22 / 25

Key Vault, Azure Policy and Defender for Cloud

Protect secrets and enforce guardrails across subscriptions.

Secrets, guardrails and posture

Azure Key Vault stores secrets (API keys, connection strings), cryptographic keys and certificates, with access controlled by Azure RBAC roles such as Key Vault Secrets User, plus soft delete and purge protection to prevent accidental loss. App Service and Functions can read secrets through Key Vault references in app settings, so code never sees the vault's credentials. Azure Policy enforces rules on resources as they are created or changed: effects include deny (block non-compliant deployments, such as public storage), audit (report only), modify and deployIfNotExists (fix or add settings automatically). Assign policies at the management-group level so every subscription inherits them. Microsoft Defender for Cloud continuously assesses your posture against benchmarks, gives a secure score and recommendations, and its paid plans add threat protection for servers, containers, databases and storage.

Layers of protection

Guardrails stop bad configuration, Key Vault protects secrets, and Defender watches what is running.

Three concentric rounded rectangles around a core block, each ring a different shade of the accent colour.
Figure 8.1 — Policy, secret management and posture monitoring around a workload.

A Key Vault reference in App Service settings

The app reads DB_PASSWORD like any environment variable; App Service fetches it with the app's managed identity.

az keyvault create -g rg-shop-dev-cin -n kv-shop-dev --enable-rbac-authorization true
az keyvault secret set --vault-name kv-shop-dev -n db-password --value "<generated>"

PRINCIPAL=$(az webapp identity assign -g rg-shop-dev-cin -n app-shop-api --query principalId -o tsv)
az role assignment create --assignee "$PRINCIPAL" --role "Key Vault Secrets User" \
  --scope $(az keyvault show -n kv-shop-dev --query id -o tsv)

az webapp config appsettings set -g rg-shop-dev-cin -n app-shop-api --settings \
  DB_PASSWORD="@Microsoft.KeyVault(VaultName=kv-shop-dev;SecretName=db-password)"

Prevent rather than detect

A deny policy that blocks public IPs on databases is cheaper than a weekly report listing them. Start new policies in audit mode to measure impact, then switch to deny.

Quick check: Which Azure Policy effect blocks a non-compliant resource from being created?

  • audit
  • append
  • deny
  • disabled
Answer

deny — The deny effect rejects the request at Resource Manager before the resource is created.