Supplement · Microsoft Azure

Entra ID, RBAC, PIM, managed identities và Key Vault

Identity là control plane chính; mục tiêu là quyền tối thiểu, ngắn hạn, có audit và không phân phối secret nếu workload identity làm được.

Authentication và authorization

Microsoft Entra ID xác thực principal; Azure RBAC quyết định data/control-plane action trên scope. Role definition, assignment và scope cùng tạo effective permission. Group-based assignment dễ quản lý hơn user trực tiếp; custom role chỉ dùng khi built-in role không đủ.

Privileged access

PIM biến quyền nhạy cảm thành eligible, time-bound activation với MFA/approval/justification. Break-glass accounts phải tách phụ thuộc thường ngày và được giám sát/test. Access review loại entitlement stale.

Workload identity

System-assigned managed identity gắn lifecycle với resource; user-assigned identity tái sử dụng độc lập. Workload identity federation loại client secret trong CI/CD và AKS. Phân tách identity theo workload/trust boundary để tránh lateral movement.

Key Vault

Dùng RBAC, private access khi cần, purge protection/soft delete, rotation và audit. Key Vault không sửa được ứng dụng giữ secret quá lâu; consumer phải reload an toàn và ownership rotation phải rõ.

Tài liệu: Microsoft Entra ID · Azure RBAC · PIM · Managed identities · Key Vault
← Landing zonesPolicy →