पाठ 22 / 25
Key Vault, Azure Policy and Defender for Cloud
Protect secrets and enforce guardrails across subscriptions.
Secrets, guardrails and posture
Azure Key Vault stores secrets (API keys, connection strings), cryptographic keys and certificates, with access controlled by Azure RBAC roles such as Key Vault Secrets User, plus soft delete and purge protection to prevent accidental loss. App Service and Functions can read secrets through Key Vault references in app settings, so code never sees the vault's credentials. Azure Policy enforces rules on resources as they are created or changed: effects include deny (block non-compliant deployments, such as public storage), audit (report only), modify and deployIfNotExists (fix or add settings automatically). Assign policies at the management-group level so every subscription inherits them. Microsoft Defender for Cloud continuously assesses your posture against benchmarks, gives a secure score and recommendations, and its paid plans add threat protection for servers, containers, databases and storage.
Layers of protection
Guardrails stop bad configuration, Key Vault protects secrets, and Defender watches what is running.
A Key Vault reference in App Service settings
The app reads DB_PASSWORD like any environment variable; App Service fetches it with the app's managed identity.
az keyvault create -g rg-shop-dev-cin -n kv-shop-dev --enable-rbac-authorization true
az keyvault secret set --vault-name kv-shop-dev -n db-password --value "<generated>"
PRINCIPAL=$(az webapp identity assign -g rg-shop-dev-cin -n app-shop-api --query principalId -o tsv)
az role assignment create --assignee "$PRINCIPAL" --role "Key Vault Secrets User" \
--scope $(az keyvault show -n kv-shop-dev --query id -o tsv)
az webapp config appsettings set -g rg-shop-dev-cin -n app-shop-api --settings \
DB_PASSWORD="@Microsoft.KeyVault(VaultName=kv-shop-dev;SecretName=db-password)"Prevent rather than detect
A deny policy that blocks public IPs on databases is cheaper than a weekly report listing them. Start new policies in audit mode to measure impact, then switch to deny.
त्वरित जाँच: Which Azure Policy effect blocks a non-compliant resource from being created?
- audit
- append
- deny
- disabled
Answer
deny — The deny effect rejects the request at Resource Manager before the resource is created.