學習、聯繫、建置
Microsoft Reactor
加入 Microsoft Reactor 並與開發人員即時互動
準備好開始使用 AI 和最新技術嗎? Microsoft Reactor 提供活動、訓練和社群資源,協助開發人員、企業家和初創公司建置 AI 技術等等。 加入我們!
學習、聯繫、建置
Microsoft Reactor
加入 Microsoft Reactor 並與開發人員即時互動
準備好開始使用 AI 和最新技術嗎? Microsoft Reactor 提供活動、訓練和社群資源,協助開發人員、企業家和初創公司建置 AI 技術等等。 加入我們!
Governance at Scale: Enforcing Network Security Baselines with Azure Policy & Landing
10 9月, 2026 | 6:00 上午 - 7:00 上午 (UTC) 國際標準時間
主題: 安全性
語言: 英文
This session makes the case for "guardrails, not gates": governance that's built into the platform itself rather than bolted on afterward.
We'll start with Azure Policy fundamentals, including policy definitions, initiatives, and effects (Deny, Audit, DeployIfNotExists, Modify), and explore how each effect type is appropriate for different governance scenarios.
From there, we move into practical network security baselines, covering policies that:
- Deny public IP creation on VMs
- Enforce mandatory NSG association on subnets
- Require specific Azure Firewall routing
- Mandate encryption in transit
The session then zooms out to the Cloud Adoption Framework Landing Zone model, showing how these individual policies are assembled into a coherent governance architecture and applied automatically at subscription vending time. This ensures every new subscription inherits the right guardrails from day one, rather than having security retrofitted later.
We'll also cover:
- Management group hierarchy design
- Policy assignment scope
- Handling policy exemptions for legitimate edge cases without undermining the overall baseline
已經註冊,需要取消嗎? 取消註冊