Azure Security Services

Covers Azure DDoS Protection, Firewall, Key Vault, NSG, Bastion, and Defender for Cloud.

Azure SC-900: Azure Network Security and Cloud Workload Protection

Think about how you protect a home: on the outside, a fence and gate (firewall); at the entrance, a sturdy lock (access control); and valuables inside are kept in a safe (encryption). Cloud infrastructure requires protection at multiple layers in exactly the same way. This post takes a detailed look at Azure's network security services and cloud workload protection tools.

 

Azure DDoS Protection: Stopping an Overwhelming Flood of Attacks

If hundreds of people line up in front of a popular restaurant, real customers cannot get in. Deliberately creating this kind of situation to paralyze a service is a DDoS (Distributed Denial of Service) attack. Thousands of compromised computers flood a single server with traffic simultaneously, making it impossible for legitimate users to access the service.

DDoS Protection Network (Basic)

This is the default protection automatically applied to all Azure resources. There is no additional cost. It protects the entire Azure infrastructure and automatically detects and mitigates the most common, large-scale DDoS attack types — volumetric attacks and protocol attacks. However, it does not provide customized protection tailored to an individual customer's resources.

DDoS Protection IP/Network (Paid)

Used when more sophisticated protection is needed.

Adaptive tuning: Learns the customer's actual traffic patterns and provides tailored protection. Because it understands what normal traffic looks like for your service, it detects abnormal traffic more accurately.

Attack mitigation reports: When an attack occurs, a detailed report is provided. You can analyze where the attack came from, what type it was, and how large it was.

Cost protection: If an attack causes auto-scaling and costs spike as a result, the additional costs are credited back.

Three Types of DDoS Attacks

Volumetric attacks: Saturate bandwidth with enormous amounts of traffic — ranging from gigabits to terabits per second.

Protocol attacks: Exploit weaknesses in network protocols. SYN flood attacks are a classic example.

Application layer attacks: Appear to be normal HTTP requests but overload the server. The hardest type to block.

!DDoS Protection Basic versus Paid

Azure Firewall: An Intelligent Gatekeeper for Cloud Networks

Think of a security desk in a building lobby. It logs who enters and exits, and stops unauthorized individuals. It also retains context: "That person went up to the conference room earlier, so they need to be checked when they leave." Azure Firewall plays exactly this role.

Core Characteristics of Azure Firewall

Stateful Firewall: Tracks the "state" of traffic. If I sent a request to Google, the response traffic coming back from Google is automatically allowed. It does not merely check whether traffic matches a rule — it understands the context of the conversation.

FQDN Filtering (Fully Qualified Domain Name): Rules can be created using domain names rather than IP addresses. For example: "allow traffic to *.microsoft.com" or "block malicioussite.com." IP addresses change frequently, but domain names are stable, so management is easier.

Fully Managed Service: Microsoft manages the infrastructure. Users only need to configure firewall rules. Availability, scalability, and updates are handled automatically.

Threat Intelligence: Known malicious IPs and domains are automatically blocked. Threat information collected by Microsoft from around the world is reflected in real time.

Azure Firewall Premium

Use the Premium tier when more advanced features are needed.

TLS Inspection: Inspects encrypted HTTPS traffic. Standard firewalls cannot see inside encrypted traffic, but Firewall Premium decrypts it, inspects it, and re-encrypts it.

IDPS (Intrusion Detection and Prevention System): Detects and blocks known attack patterns.

Web Category Filtering: Category-based filtering such as "block gambling sites" or "restrict social media."

 

WAF: A Specialized Firewall Just for Web Applications

If a general firewall is the building entrance security guard, then a WAF (Web Application Firewall) is the dedicated IT security specialist stationed outside the server room. It specifically understands and blocks web attacks.

A standard network firewall filters traffic based on ports and IP addresses. But web attacks come through allowed ports (443, HTTPS). SQL injection or XSS attacks hidden within that traffic cannot be detected by a standard firewall.

Major Attacks WAF Blocks

SQL Injection: Manipulates database queries to steal or delete data. Example: entering code like into a login form to bypass authentication.

XSS (Cross-Site Scripting): Injects malicious scripts into a webpage so they execute in another user's browser.

CSRF (Cross-Site Request Forgery): Tricks a user into performing an action they did not intend.

File Inclusion: Includes internal server files or external malicious files.

OWASP Top 10

OWASP (Open Web Application Security Project) publishes a list of the ten most dangerous web vulnerabilities. Azure WAF has built-in rule sets covering the OWASP Top 10 and other known attack patterns.

Where Azure WAF Is Deployed

Azure Application Gateway: Deployed in front of a specific application to protect it.

Azure Front Door: Provides protection at edge locations distributed globally. Suitable for global services.

Azure CDN: Applies WAF to a content delivery network.

 

NSG: Fine-Grained Traffic Rules for the Network

Like traffic signals in a city, NSG (Network Security Group) controls traffic within an Azure virtual network. It defines rules such as "allow this type of traffic from this subnet to that subnet, block that type."

How NSG Works

NSGs apply rules to both inbound (incoming) and outbound (outgoing) traffic. Each rule specifies: Source: Where is the traffic coming from? (IP range, tag) Destination: Where is the traffic going? Port: Which port? (80 = HTTP, 443 = HTTPS, 22 = SSH, etc.) Protocol: TCP, UDP, etc. Action: Allow or deny. Priority: Lower numbers are applied first.

Default Rules

NSGs include default rules when created. These default rules cannot be deleted and have very low priority (high numbers), so user-defined rules take effect first.

Default inbound allow: Azure Load Balancer traffic and traffic within the virtual network. Default inbound deny: All other inbound traffic is denied.

Where NSGs Are Applied

Subnet level: Applied to the entire subnet. Affects all VMs inside the subnet.

NIC (Network Interface Card) level: Applied to an individual VM. Enables more granular control.

When both are applied: Both NSGs' rules are evaluated. For inbound traffic, subnet NSG → NIC NSG; for outbound, NIC NSG → subnet NSG.

 

Azure Bastion: Securely Connect to VMs Without a Public IP

When you need to connect remotely to a server, the old approach was to assign a public IP address to the server and connect directly over the internet. But this exposes the server to the internet and makes it a target for attacks.

Azure Bastion solves this problem. You can securely connect to a VM through a web browser without assigning a public IP directly to the VM.

Back to blog list