学习、联系、构建
Microsoft Reactor
加入 Microsoft Reactor 并实时与开发人员互动
准备好开始使用 AI 和最新技术了吗? Microsoft Reactor 提供活动、培训和社区资源,帮助开发人员、企业家和初创公司利用 AI 技术等。 快加入我们吧!
学习、联系、构建
Microsoft Reactor
加入 Microsoft Reactor 并实时与开发人员互动
准备好开始使用 AI 和最新技术了吗? Microsoft Reactor 提供活动、培训和社区资源,帮助开发人员、企业家和初创公司利用 AI 技术等。 快加入我们吧!
Governance at Scale: Enforcing Network Security Baselines with Azure Policy & Landing
10 九月, 2026 | 6:00 上午 - 7:00 上午 (UTC) 协调世界时
主题: 安全性
语言: 英语
This session makes the case for "guardrails, not gates": governance that's built into the platform itself rather than bolted on afterward.
We'll start with Azure Policy fundamentals, including policy definitions, initiatives, and effects (Deny, Audit, DeployIfNotExists, Modify), and explore how each effect type is appropriate for different governance scenarios.
From there, we move into practical network security baselines, covering policies that:
- Deny public IP creation on VMs
- Enforce mandatory NSG association on subnets
- Require specific Azure Firewall routing
- Mandate encryption in transit
The session then zooms out to the Cloud Adoption Framework Landing Zone model, showing how these individual policies are assembled into a coherent governance architecture and applied automatically at subscription vending time. This ensures every new subscription inherits the right guardrails from day one, rather than having security retrofitted later.
We'll also cover:
- Management group hierarchy design
- Policy assignment scope
- Handling policy exemptions for legitimate edge cases without undermining the overall baseline
已注册并且需要取消? 取消注册