
Bill Wilder -- Running Azure Securely
Om avsnittet
Moving an application to Azure changes which security controls you operate yourself and which ones the platform can provide. Azure specialist Bill Wilder walks Chris through a practical set of cloud risks, from exposed management ports and missing patches to weak credentials, open database endpoints, and leaked secrets. They examine network protections, serverless and container responsibilities, testing integrations, multifactor authentication, and Azure Key Vault. Bill also explains how managed identities can reduce the need to pass credentials into applications and how Azure’s security monitoring brings configuration and threat signals together. This archive conversation uses the Azure product names and capabilities of its time, while highlighting the enduring questions developers should ask about defaults, shared responsibility, secret handling, and visibility.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Bill Wilder:
→ Bill Wilder on LinkedIn
Mentioned in this episode:
→ Azure Key Vault
→ Azure Kubernetes Service
→ Azure Functions
→ Microsoft Defender for Cloud (formerly Azure Security Center)
→ Azure Friday
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Running Azure securely with Bill Wilder
08:18 Protecting exposed RDP and SSH endpoints
11:05 Host firewalls, gateways, and defense in depth
14:11 Patching responsibilities and serverless
16:48 Containers, AKS, and trusted images
18:35 Web application protection and testing
20:02 Connecting security tools to Azure DevOps
23:45 Weak credentials and multifactor authentication
26:09 Restricting access to SQL endpoints
28:24 Protecting secrets with Azure Key Vault
30:03 Hardware security modules and private keys
34:44 Reducing credentials with managed identities
35:41 Security monitoring and logging
40:40 Resources for learning more about Azure
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.