Regain control with Azure Governance

Slides:



Advertisements
Similar presentations
Windows Azure Connect Name Title Microsoft Corporation.
Advertisements

Microsoft Connect /6/ :05 AM
“Introduction to Azure Security Center”
Microsoft Virtual Academy
Providing reliable SMB shares in Microsoft Azure
Azure on Steroids: Full Automation with PowerShell
Education Meetup for schools, colleges or those working in the sector
6/26/2018 5:24 AM THR1083 Enabling Advanced Security Capabilities: Drive consistent authorization across multiple applications Bryan Bolling Solution Architect,
Decoding audit events in Microsoft Office 365
Azure Functions and Automation: The SQL Agent in the Cloud
Danilo Omaljev Microsoft Cloud Solutions Architect.
Azure API Management Jothi Prakash A
Building a Continuous Integration Pipeline using VSTS
Analytics for Apps: Landing and Loading Data into SQL Data Warehouse
Deploy Windows 10 Mobile for the mobile workforce
Azure Service Bus Rajesh Microsoft Connect /15/2018 6:45 AM
F5 WAF in Azure Security Center
Microsoft Connect /17/2018 5:15 AM
Microsoft Azure Do’s and Don’ts
Microsoft Build /19/2018 2:06 AM © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY,
Azure AD Domain Services
Azure Advisor: Optimization in the best way
11/29/ :53 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Discover what’s new and what’s coming to SharePoint Modern Team sites
Microsoft Ignite NZ October 2016 SKYCITY, Auckland
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
12/5/2018 2:50 AM How to secure your front door with real-time risk assessments of your logons Jan Ketil Skanke COO and Principal Cloud Architect CloudWay.
Build /2/ The future of Azure devops: Building and managing cloud applications lifecycle across your teams Bradley Millington Program.
Evolution of the Intake Request Solution from SharePoint to PowerApps
TechEd /3/2018 8:11 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
ARM and Compliance Vishwas Lele & Jason McNutt
Web Development in Visual Studio 2017
12/29/ :48 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Microsoft Build /18/2019 1:15 AM © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY,
Welcome to Azure Notebooks
Azure Functions & Aurelia Serverless SPAs
C++ Productivity Improvements
2/22/2019 1:12 PM The Journey To Provision and Manage a Thousand Machine Cluster for Machine Learning Neil Sant Gat © Microsoft Corporation. All rights.
Microsoft Connect /23/ :38 AM
Microsoft Connect /25/2019 1:20 PM
Zero to Tabular Patrick LeBlanc Data Platform Solution Architect
TechEd /28/2019 7:27 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
4/6/2019 9:47 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
Deploying a Minecraft Server on Windows Azure
4/6/2019 6:34 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS.
4/11/2019 6:29 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
4/9/ :39 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
4/12/2019 5:27 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
4/15/2019 1:57 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
“Hey Mom, I’ll Fix Your Computer”
Discussion Panel: Windows Server MVP Panel
Elevate Access Global Admin Role
5/30/2019 1:59 PM © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION.
Microsoft Connect /29/2019 1:53 AM
System Center Configuration Manager Assessment Results
SQL Server Assessment Results
Active Directory Assessment Results
Exchange Server Assessment Results
SharePoint Online Assessment Results
Skype for Business Online Assessment Results
System Center Operations Manager Assessment Results
Windows Client Assessment Results
Exchange Online Assessment Results
Active Directory Security Assessment Results
Securing ASP.NET in an Azure Environment
Microsoft Data Insights Summit
Microsoft Virtual Academy
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
Microsoft Connect /14/ :11 AM
Presentation transcript:

Regain control with Azure Governance Session Regain control with Azure Governance Sam Cogan

Taking Back Control 6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Taking Back Control

Sam Cogan Solution Architect – Willis Towers Watson © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Sam Cogan Solution Architect – Willis Towers Watson Microsoft Azure MVP samcogan.com @samcogan sam-cogan

Cost Security Compliance Regain Control 6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Regain Control Cost Security Compliance

Regain Control Review Organise Audit Enforce 6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Regain Control Review Organise Audit Enforce

How much are we spending? © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. 6/5/2019 9:30 AM Review How much are we spending? What resources are we spending it on? Where are we out of compliance Where should we focus our effort?

Review Resource Graph Cost Management Security Centre 6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. 6/5/2019 9:30 AM Review Resource Graph Cost Management Security Centre

Create a subscription hierarchy © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. 6/5/2019 9:30 AM Organise Create a subscription hierarchy Classify Subscriptions and Resources Apply access rights consistently

Organise Management Groups Tags RBAC 6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. 6/5/2019 9:30 AM Organise Management Groups Tags RBAC Demo management group setup Apply RBAC to management groups Tag application

Management Groups

Audit the impact of these policies 6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Audit Develop Policies Apply Budgets Audit the impact of these policies Get ready for enforcement Policy creation, show code Policy Type: Deny: generates an event in the activity log and fails the request Audit: generates a warning event in activity log but doesn't fail the request Append: adds the defined set of fields to the request AuditIfNotExists: enables auditing if a resource doesn't exist DeployIfNotExists: deploys a resource if it doesn't already exist Disabled: doesn't evaluate resources for compliance to the policy rule Language - https://docs.microsoft.com/en-us/azure/governance/policy/concepts/definition-structure#policy-rule Initiatives

Audit Cost Management Azure Policy 6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. 6/5/2019 9:30 AM Audit Cost Management Azure Policy

Change policies to enforcement 6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Enforce Change policies to enforcement Add resolution actions Enforce Budgets Create new subscriptions already compliant

Enforce Azure Policy Cost Management Azure Blueprints 6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. 6/5/2019 9:30 AM Enforce Azure Policy Cost Management Azure Blueprints

6/5/2019 9:30 AM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Regain Control Review: Cost Management Resource Graph Security Centre Organise: Management Groups Tags Roles Audit: Policies Budgets Enforce: Policies Blueprints Budgets

Understand what you are spending & why © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. 6/5/2019 9:30 AM Review Understand what you are spending & why Know that only approved resources are deployed Know that you are adhering to security best practice Further improvement!

Sam Cogan Solution Architect – Willis Towers Watson © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Sam Cogan Solution Architect – Willis Towers Watson Microsoft Azure MVP samcogan.com @samcogan sam-cogan