Skip to content

Security: Kaspanitz/bcdrdemo

Security

security.md

Security (6)

  • Encryption of data in transit and at rest
  • Soft delete (enhanced in preview)
  • RBAC
    • Backup Contributor - Permissions to create and manage backup except deleting Recovery Services vault and giving access to others. "Admin of backup operations"
    • Backup Operator - Contributor permissions except for removing backup and managing backup policies. Can't perform destructive operations such as stop backup with delete data or remove registration of on-premises resources.
    • Backup Reader - View all backup management operations. "Monitoring role"
  • Multi-user authorization
    • Additional protection on Recovery Services vaults and Backup vaults. Azure Backup uses another Azure resource called the Resource Guard to ensure critical operations are performed only with applicable authorization. Resource Guard must be owned by a different user.

  • Immutable vault (preview)
    • Blocks specific operations on the vault and its protected items.
    • Disable/Enable/Enable and Lock (cannot be disabled)
    • Restricted operations e.g., Stop protection with delete data, Modify backup policy to reduce retention, Change backup policy to reduce retention
  • Private endpoints
    • Bring backup service into VNET
    • V1 and
    • V2 experience
      • Create private endpoints without managed identities.
      • No private endpoints are created for the blob and queue services.
      • Use of fewer private IPs. Key enhancements

There aren't any published security advisories