Skip to main content
emnode
Learning path

Encrypt across Azure

Encrypt in transit and at rest across Azure SQL, Storage, Redis, VMs and Key Vault.

5 lessons·~68 min total

Lessons in this path

  1. 1
    Compliance AZURE

    Encrypt Azure data at rest, including customer-managed keys

    One capability across SQL databases, Storage accounts and virtual machine disks: make sure every store of data is encrypted at rest, that nothing travels unencrypted between Compute and Storage, and that the regulated workloads which need to hold their own key actually do.

    14 min
  2. 2
    Compliance AZURE

    Encrypt Azure automation and configuration data

    One capability for the secrets that hide inside your automation: make sure every Automation account variable that holds a credential, key or connection string is created as an encrypted secure asset, not a plain-text value anyone with read access can pull back.

    12 min
  3. 3
    Compliance AZURE

    Enforce encryption in transit across Azure services

    One capability across Redis, App Service and Functions: make sure no service answers an unencrypted request, so credentials, tokens and payloads never travel as plaintext that anyone on the path can read.

    14 min
  4. 4
    Compliance AZURE

    Harden Key Vault data protection

    One capability across every Key Vault: make sure a deleted or compromised vault can be recovered rather than lost for good, and that no key lives forever, so the secrets, keys and certificates the estate depends on cannot be wiped, lost or quietly left valid indefinitely.

    14 min
  5. 5
    Compliance AZURE

    Harden Azure SQL encryption

    One capability across Azure SQL Database and SQL Managed Instance: make sure the key that protects your data at rest is one you own and control, not just the platform default, wherever a regulated workload demands it.

    14 min