EPISODE · Jan 25, 2019 · 44 MIN
Bill Wilder -- Running Azure Securely
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Moving an application to Azure changes which security controls you operate yourself and which ones the platform can provide. Azure specialist Bill Wilder walks Chris through a practical set of cloud risks, from exposed management ports and missing patches to weak credentials, open database endpoints, and leaked secrets. They examine network protections, serverless and container responsibilities, testing integrations, multifactor authentication, and Azure Key Vault. Bill also explains how managed identities can reduce the need to pass credentials into applications and how Azure’s security monitoring brings configuration and threat signals together. This archive conversation uses the Azure product names and capabilities of its time, while highlighting the enduring questions developers should ask about defaults, shared responsibility, secret handling, and visibility.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Bill Wilder:→ Bill Wilder on LinkedInMentioned in this episode:→ Azure Key Vault→ Azure Kubernetes Service→ Azure Functions→ Microsoft Defender for Cloud (formerly Azure Security Center)→ Azure FridayFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Running Azure securely with Bill Wilder08:18 Protecting exposed RDP and SSH endpoints11:05 Host firewalls, gateways, and defense in depth14:11 Patching responsibilities and serverless16:48 Containers, AKS, and trusted images18:35 Web application protection and testing20:02 Connecting security tools to Azure DevOps23:45 Weak credentials and multifactor authentication26:09 Restricting access to SQL endpoints28:24 Protecting secrets with Azure Key Vault30:03 Hardware security modules and private keys34:44 Reducing credentials with managed identities35:41 Security monitoring and logging40:40 Resources for learning more about Azure
Embed this episode
What this episode covers
Moving an application to Azure changes which security controls you operate yourself and which ones the platform can provide. Azure specialist Bill Wilder walks Chris through a practical set of cloud risks, from exposed management ports and missing patches to weak credentials, open database endpoints, and leaked secrets. They examine network protections, serverless and container responsibilities, testing integrations, multifactor authentication, and Azure Key Vault. Bill also explains how mana...
Ready to play
Bill Wilder -- Running Azure Securely
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.