๐๐ผ๐ ๐๐ผ ๐๐ฒ๐ฐ๐๐ฟ๐ฒ ๐ฎ ๐๐๐ป๐ฐ๐๐ถ๐ผ๐ป ๐๐ฝ๐ฝ?
๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒโฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ
โก๏ธDefender for Cloud for assessment of potential configuration-related security vulnerabilities
โก๏ธLog and monitor: diagnostic settings to configure streaming export of platform logs and metrics
โก๏ธRequire HTTPS
โก๏ธSecuring keys with Azure key Vault
โก๏ธEnable App Service Authentication/Authorization
โก๏ธUse Azure API Management (APIM) to authenticate requests
โก๏ธRun your function app with the lowest possible permissions
โก๏ธStore data encrypted
๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒโฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ขฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ
โก๏ธDisable FTP
โก๏ธSecure the scm endpoint
๐ฝฬฒ๐ฬฒ๐ฬฒ๐ ฬฒ๐ฬฒ๐ฬฒ๐ฬฒโฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ฬฒ๐ขฬฒ
โก๏ธSet access restrictions
โก๏ธSecure the storage account
โก๏ธPrivate site access with Azure Private Endpoint
โก๏ธDeploy your function app in isolation configuring a Web Application Firewall (WAF) for App Service Environment.
More details: https://learn.microsoft.com/en-us/azure/azure-functions/security-concepts?tabs=v4
#security #azure #cloud #data #management #streaming #functionapp #serverless #waf #appservice #privateendpoint #networksecurity #securedeployment #apim #ftp #keyvault #key #vulnerability #assessment #misconfiguration #encryption #storage #storageaccount #defender #defenderforcloud #cnapp #cspm #cwpp #microsoft #microsoftsecurity #cloudsecurity #cloudnative #siem #monitoring #soc