Azure

Hacker vs Azure: 5 Attacks, 5 Defences

Each attack, matched to the Azure feature that stops it.

What you'll learn

  • Which Azure service stops which specific attack, by name
  • Why a valid token from a real user is still an attack you must block
  • Why "allow Azure services" is far broader than it sounds
Azure Security 8 steps 25 seconds views

Was this useful?

Share

Understand it one step at a time

The short runs these in order in about 25 seconds. Here they are written out — pick any step to jump the short straight to it.

1 Step 1 of 8

One attacker, one target

He wants your customer data. Five defences stand between him and it — skip any one and the rest don’t cover for it.

Frequently asked questions

Which Azure service stops which kind of attack?
Front Door's WAF blocks junk traffic and injection at the edge, Microsoft Entra ID proves identity, an owner check inside your API blocks a valid token being used against someone else's data, Key Vault plus managed identity removes the value of a leaked key, and a private endpoint removes a database's public address entirely.
What does "allow Azure services" actually permit on a firewall?
Far more than it sounds — it permits any resource in any Azure subscription in the world, not just your own, including one an attacker can create in minutes. Leave it off and use specific service tags or private endpoints instead.

Free app · no app store

These are built for a phone

Every short is drawn at full portrait height, the shape a phone already is. Installed, it opens full-bleed with no address bar across the top — and the whole library reads offline.

How it works

Read deeper on Azure

Twenty seconds gets the shape of an idea across. These go into how it behaves in production.

More shorts

Get new posts by email

New technical articles, Azure AI and GitHub Copilot updates, and upcoming events. No spam, unsubscribe anytime.

navigate open