[email protected]/presentations/Managed...MICROSOFT MAKES NO...

18

Transcript of [email protected]/presentations/Managed...MICROSOFT MAKES NO...

Page 2: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

What is a Secret?

Page 3: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

What is the problem?

Page 4: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft
Page 5: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

Dude, we are serious…

5

Page 6: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

Introducing Managed Identities

Page 7: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

Looking at the bigger picture

Page 8: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

Managed Identity Architecture

AppSvc/VM/…

Azure Service

(e.g., ARM, Key Vault)Your code

Local token

service

Credentials

1

2

3

Azure (inject and roll credentials)

Page 9: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

Azure Services supporting MSI

Page 10: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

Azure Services supporting AAD Auth

Page 11: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

https://github.com/madsd/azmon 11

Page 14: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft
Page 15: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft
Page 17: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft
Page 18: madsd@microsoftazurebootcampdk.azurewebsites.net/presentations/Managed...MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. Microsoft

© 2017 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other

countries.

The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to

changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the

date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.