Refresh five stale SCI security articles (Managed Grafana, App Configuration, IoT Hub, App Service, Container Apps) (#319443)
* Refresh five stale SCI articles to canonical structure
Refresh the Secure your <service> articles for Managed Grafana, App
Configuration, IoT Hub, App Service, and Container Apps:
- Set SCI authorship (author: msmbaldwin, ms.author: mbaldwin) and ms.date
- Add/relocate the Zero Trust banner to sit immediately before the first H2
(added where missing on IoT Hub and App Service)
- Move Service-specific security to the front per canonical section order
- Remove links to outdated MCSB per-service baselines (superseded by these
SCI articles) and replace with service-specific or cross-cutting targets
- Normalize link phrasing to "For more information, see ..."
- App Service: set ms.topic to best-practice and add ai-usage
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
* Apply validation pass-1 fixes to five SCI articles
Grafana: relocate Service-specific section first; remove no-link and
enforced bullets; correct Azure Policy claim; move recovery bullet to Backup.
App Config: fix Conditional Access URL; correct activity-log path; reframe
soft-delete bullet around purge protection; fix tagging link.
IoT Hub: fix device-encryption link/claim; correct root CA anchor; Entra
branding; site-relative SDK link; strip trailing whitespace.
App Service: correct HTTPS-only default claim; soften FTPS default claim;
reframe app-settings secrets bullet; add link to recovery bullet.
Container Apps: fix Key Vault secrets and Application Insights links;
Conditional Access URL; reliability DR link; NSG link text.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
* Apply second validation round fixes to five SCI articles
App Service: fix broken backup and RBAC anchors; normalize link wording.
Container Apps: fix reliability anchor; replace CAF redirect links with
Container Apps IaC and ACR geo-replication targets; name real Container Apps
RBAC roles.
Grafana: reference service-account tokens instead of service principals.
App Config: reframe redundant Key Vault bullet around secret-rotation reload.
IoT Hub: contextualize access-audit bullet to IoT Hub roles/policies; reframe
diagnostic-settings bullet to compliance retention; drop unverifiable
SDK-version-monitoring and misplaced micro-segmentation bullets.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
* Apply third validation round fixes to four SCI articles
Grafana: correct Azure Policy claim (drop nonexistent private-link policy);
remove duplicate API-endpoints and dashboard-sharing bullets.
App Config: remove duplicate Azure Policy and secret-reload bullets; reframe
audit bullet to log-retention for compliance.
App Service: contextualize security-assessment, regulatory-compliance, and
secure-DevOps bullets with App Service-specific targets.
Container Apps: correct Container Apps Operator role capability description.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
* Apply fourth validation round fixes
Grafana: add Grafana 12+ caveat to CSRF bullet; name Grafana roles in access
reviews; correct/soften Azure Policy built-ins list.
App Service: retarget regulatory-compliance bullet to a distinct doc; make
DDoS bullet single-link.
Container Apps: retarget image-storage, Application Insights, and IaC bullets
to service-specific/topic-specific docs.
IoT Hub: add Backup and recovery section with manual-failover DR bullet.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
* Apply fifth validation round fixes
App Config: relabel network security perimeter as private preview and note
enrollment/ARM-CLI caveat.
Grafana: add terminal period to access-review bullet.
Container Apps: narrow built-in secrets bullet to remove overlap with the
Key Vault secrets bullet.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
* Apply sixth validation round fixes
App Config: fix misplaced (NSGs) acronym in private-endpoint NSG bullet.
Container Apps: update authentication link text to Microsoft Entra ID;
retarget DR-testing bullet to the custom-multiregion resiliency anchor.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
* Apply Learn Authoring Assistant style suggestions
Address all 38 LAA style/grammar suggestions across the five refreshed SCI
articles (contractions, 'by using', explicit antecedents, multiregion,
punctuation). No technical claims changed.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
* Apply style backstop fixes beyond LAA inline suggestions
Fix issues the automated LAA scan missed (it only inspects changed lines):
- Repair verbless fragment introduced when LAA deleted 'provides'
- Active voice for management-plane operations; spell out Azure Resource Manager/Azure CLI
- 'leverage' -> 'use'; 'bi-directional' -> 'bidirectional'; 'multi-region' -> 'multiregion'
- Lowercase generic 'network security groups'
- Comma before nonrestrictive 'which'; avoid sentence-initial numeral (HTTP 401/403)
- Remove redundant 'certificates'/'capabilities' repetition
No technical claims changed.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
* Wire up Security TOC nodes per SCI standard §12
For App Configuration, Container Apps, App Service, and IoT Hub: list the
SCI article first in the top-level Security node and remove the MCSB
per-service baseline entry. Managed Grafana already complied.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 715951b9-019e-4a26-bcc6-16d002ecb832
* Fix broken pen-testing link in App Service security article
Update /security/engineering/pen-testing to the correct
/azure/security/fundamentals/pen-testing path.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Remove em dashes from App Service security article
Replace three em dashes with commas, a colon, and a sentence split.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Fix Container Apps TOC Compliance node structure
Dropping the MCSB per-service baseline left the Compliance node with
only two items, below the 3-12 range required by toc-node-structure.
Reference the SCI security article (the baseline's replacement) in that
node to restore a valid structure.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: d0e8c645-5c56-4cc5-bea5-e3641821b729
Copilot-Session: 715951b9-019e-4a26-bcc6-16d002ecb832