You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/backup/backup-security-controls.md
+21-21Lines changed: 21 additions & 21 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ author: dcurwin
6
6
manager: carmonm
7
7
ms.service: backup
8
8
ms.topic: conceptual
9
-
ms.date: 09/04/2019
9
+
ms.date: 09/23/2019
10
10
ms.author: dacurwin
11
11
12
12
---
@@ -18,43 +18,43 @@ This article documents the security controls built into Azure Backup.
18
18
19
19
## Network
20
20
21
-
| Security control | Yes/No | Notes |
21
+
| Security control | Yes/No | Notes | Documentation
22
22
|---|---|--|
23
-
| Service endpoint support| No ||
24
-
| VNet injection support| No ||
25
-
| Network isolation and firewalling support| Yes | Forced tunneling is supported for VM backup. Forced tunneling is not supported for workloads running inside VMs. |
26
-
| Forced tunneling support| No ||
23
+
| Service endpoint support| No |||
24
+
| VNet injection support| No |||
25
+
| Network isolation and firewalling support| Yes | Forced tunneling is supported for VM backup. Forced tunneling is not supported for workloads running inside VMs. ||
26
+
| Forced tunneling support| No |||
27
27
28
28
## Monitoring & logging
29
29
30
-
| Security control | Yes/No | Notes|
30
+
| Security control | Yes/No | Notes| | Documentation
31
31
|---|---|--|
32
-
| Azure monitoring support (Log analytics, App insights, etc.)| Yes | Log Analytics is supported via diagnostic logs. See [Monitor Azure Backup protected workloads using Log Analytics](https://azure.microsoft.com/blog/monitor-all-azure-backup-protected-workloads-using-log-analytics/) for more information. |
33
-
| Control and management plane logging and audit| Yes | All customer triggered actions from the Azure portal are logged to activity logs. |
34
-
| Data plane logging and audit| No | Azure Backup data plane can't be reached directly. |
32
+
| Azure monitoring support (Log analytics, App insights, etc.)| Yes | Log Analytics is supported via diagnostic logs. See [Monitor Azure Backup protected workloads using Log Analytics](https://azure.microsoft.com/blog/monitor-all-azure-backup-protected-workloads-using-log-analytics/) for more information. ||
33
+
| Control and management plane logging and audit| Yes | All customer triggered actions from the Azure portal are logged to activity logs. ||
34
+
| Data plane logging and audit| No | Azure Backup data plane can't be reached directly. ||
35
35
36
36
## Identity
37
37
38
-
| Security control | Yes/No | Notes|
38
+
| Security control | Yes/No | Notes| | Documentation
39
39
|---|---|--|
40
-
| Authentication| Yes | Authentication is through Azure Active Directory. |
41
-
| Authorization| Yes | Customer created and built-in RBAC roles are used. See [Use Role-Based Access Control to manage Azure Backup recovery points](/azure/backup/backup-rbac-rs-vault) for more information. |
40
+
| Authentication| Yes | Authentication is through Azure Active Directory. ||
41
+
| Authorization| Yes | Customer created and built-in RBAC roles are used. See [Use Role-Based Access Control to manage Azure Backup recovery points](/azure/backup/backup-rbac-rs-vault) for more information. ||
42
42
43
43
## Data protection
44
44
45
-
| Security control | Yes/No | Notes |
45
+
| Security control | Yes/No | Notes | | Documentation
46
46
|---|---|--|
47
-
| Server-side encryption at rest: Microsoft-managed keys | Yes | Using storage service encryption for storage accounts. |
48
-
| Server-side encryption at rest: customer-managed keys (BYOK) | No ||
49
-
| Column level encryption (Azure Data Services)| No ||
50
-
| Encryption in transit (such as ExpressRoute encryption, in VNet encryption, and VNet-VNet encryption)| No | Using HTTPS. |
51
-
| API calls encrypted| Yes ||
47
+
| Server-side encryption at rest: Microsoft-managed keys | Yes | Using storage service encryption for storage accounts. ||
48
+
| Server-side encryption at rest: customer-managed keys (BYOK) | No |||
49
+
| Column level encryption (Azure Data Services)| No |||
50
+
| Encryption in transit (such as ExpressRoute encryption, in VNet encryption, and VNet-VNet encryption)| No | Using HTTPS. ||
51
+
| API calls encrypted| Yes |||
52
52
53
53
## Configuration management
54
54
55
-
| Security control | Yes/No | Notes|
55
+
| Security control | Yes/No | Notes| | Documentation
56
56
|---|---|--|
57
-
| Configuration management support (versioning of configuration, etc.)| Yes||
57
+
| Configuration management support (versioning of configuration, etc.)| Yes|||
0 commit comments