# Key Vault, Azure Policy and Defender for Cloud — Azure

Source: https://www.skillbyai.com/en/azure/p-security

> Protect secrets and enforce guardrails across subscriptions.

## Secrets, guardrails and posture

**Azure Key Vault** stores **secrets** (API keys, connection strings), **cryptographic keys** and **certificates**, with access controlled by Azure RBAC roles such as *Key Vault Secrets User*, plus soft delete and purge protection to prevent accidental loss. App Service and Functions can read secrets through **Key Vault references** in app settings, so code never sees the vault's credentials. **Azure Policy** enforces rules on resources as they are created or changed: effects include **deny** (block non-compliant deployments, such as public storage), **audit** (report only), **modify** and **deployIfNotExists** (fix or add settings automatically). Assign policies at the management-group level so every subscription inherits them. **Microsoft Defender for Cloud** continuously assesses your posture against benchmarks, gives a **secure score** and recommendations, and its paid plans add threat protection for servers, containers, databases and storage.

## Layers of protection

Guardrails stop bad configuration, Key Vault protects secrets, and Defender watches what is running.

![Three concentric rounded rectangles around a core block, each ring a different shade of the accent colour.](assets/figures/azure/section-8-map.svg) — Figure 8.1 — Policy, secret management and posture monitoring around a workload.

## A Key Vault reference in App Service settings

The app reads `DB_PASSWORD` like any environment variable; App Service fetches it with the app's managed identity.

```bash
az keyvault create -g rg-shop-dev-cin -n kv-shop-dev --enable-rbac-authorization true
az keyvault secret set --vault-name kv-shop-dev -n db-password --value "<generated>"

PRINCIPAL=$(az webapp identity assign -g rg-shop-dev-cin -n app-shop-api --query principalId -o tsv)
az role assignment create --assignee "$PRINCIPAL" --role "Key Vault Secrets User" \
  --scope $(az keyvault show -n kv-shop-dev --query id -o tsv)

az webapp config appsettings set -g rg-shop-dev-cin -n app-shop-api --settings \
  DB_PASSWORD="@Microsoft.KeyVault(VaultName=kv-shop-dev;SecretName=db-password)"
```

## Prevent rather than detect

A *deny* policy that blocks public IPs on databases is cheaper than a weekly report listing them. Start new policies in *audit* mode to measure impact, then switch to *deny*.

**Quiz:** Which Azure Policy effect blocks a non-compliant resource from being created?

- [ ] audit
- [ ] append
- [x] deny
- [ ] disabled

*Answer:* deny. The deny effect rejects the request at Resource Manager before the resource is created.
