MicrosoftDocs/azure-docs/articles/security

Last 20 commits touching this section.

b64fe08

20261006 split and create new dedicated Azure Synapse Analytics SQL a… (#321208) * 20261006 split and create new dedicated Azure Synapse Analytics SQL auditing content * 20261006 split and create new dedicated Azure Synapse Analytics SQL auditing content * Apply batched suggestions from code review Co-authored-by: learn-build-service-prod-06[bot] <274430002+learn-build-service-prod-06[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-01[bot] <274427437+learn-build-service-prod-01[bot]@users.noreply.github.com> Co-authored-by: William Assaf MSFT <74387232+WilliamDAssafMSFT@users.noreply.github.com> * Apply suggestion from @learn-build-service-prod-07[bot] Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * 20261006 more LAA edits * 20261006 more LAA edits * Apply suggestion from @learn-build-service-prod-07[bot] Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * 20261006 more LAA edits * Apply suggestion from @learn-build-service-prod-04[bot] Co-authored-by: learn-build-service-prod-04[bot] <274428985+learn-build-service-prod-04[bot]@users.noreply.github.com> * Apply suggestion from @learn-build-service-prod-07[bot] Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * 20261006 more LAA edits * 20261006 copy Synapse versin of vnet-service-endpoint-rule-overview.md * 20261006 move Synapse version out of sql-docs-pr * 20261006 link fixes * 20261006 synapse eviction link fixes * 20261006 synapse eviction link fixes * 20261006 synapse from SQL * 20261006 synapse from SQL * 20261006 synapse from SQL * 20261006 flatten TOC, fix link * 20261007 fix formatting --------- Co-authored-by: learn-build-service-prod-06[bot] <274430002+learn-build-service-prod-06[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-01[bot] <274427437+learn-build-service-prod-01[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-04[bot] <274428985+learn-build-service-prod-04[bot]@users.noreply.github.com>

2f2c6cd

Note symmetric key (oct-HSM) preview for Key Vault Premium (#320826) Update key management comparison and overview articles to reflect the public preview of HSM-protected symmetric (oct-HSM/AES) keys in Azure Key Vault Premium. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

fc82af3

Add Azure Payment HSM v2 (preview) to security fundamentals key-management articles (#320697) * Add Azure Payment HSM v2 (preview) to security fundamentals key-management articles Integrate Azure Payment HSM v2 (preview) across the security fundamentals key-management guidance so customers can discover and compare it alongside existing key-management solutions: - key-management.md: new "Azure Payment HSM v2 (preview)" section; update intro, pricing, service limits, encryption-at-rest, APIs, and next steps. - key-management-choose.md: add an Azure Payment HSM v2 column to both comparison tables; update scenario and industry prose and metadata. - services-technologies.md: add an Azure Payment HSM v2 row. - encryption-overview.md: mention Azure Payment HSM v2 in key management. Related to AZ#633838. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Refine Payment HSM v2 in key-management comparison tables - Remove redundant manual bold from the v2 header cells so the (preview) qualifier isn't half in/out of emphasis (header rows already render bold). - Add availability, DR, and backup doc links for Payment HSM v2 and for the Key Vault columns in the service characteristics table. - Change the v2 budget cell to "N/A (free during preview)". Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Clarify customers retain admin control of Payment HSM v2 cluster Incorporate PM feedback: anchor that customers keep administrative control while Microsoft manages infrastructure, availability, and lifecycle. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

c5db54a

Merge branch 'MicrosoftDocs:main' into master

51667dd

[BULK cpcli] Rebrand Microsoft 365 Copilot to Microsoft Copilot MAXADO-12279337 (#320420) * [BULK cpcli] Rebrand Microsoft 365 Copilot to Microsoft Copilot MAXADO-12279337 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4829db76-3855-456d-a4c0-9931bdb6e163 * remove change from concepts-llm-apis.md --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 4829db76-3855-456d-a4c0-9931bdb6e163

97a5b73

Accept LAA suggestions: allowlist -> allow list (per Microsoft Style Guide) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

2a727f1

Add Managed HSM support for App Configuration

e218d52

Merge remote-tracking branch 'upstream/main' into mbaldwin/ca-details-allowlist-monitoring

3d8ab7b

Learn Editor: Update feature-availability.md

21342c4

Address review: link to certificate pinning article instead of restating guidance Per reviewer feedback, avoid restating the static-pinning recommendation here to prevent discrepancies if the certificate-pinning article changes; point readers to the article instead. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

a024e84

Clarify allowlist maintenance and align certificate pinning guidance - Note that this article is the authoritative source for the AIA, CRL, and OCSP firewall allowlist domains, and that additions/removals are recorded in the change log, so FQDN-restricted customers know where to monitor. - Expand AIA/CRL/OCSP on first use and explain why the endpoints use HTTP/80. - Align the certificate pinning section with the refreshed certificate-pinning article: static pinning is generally not recommended for publicly trusted Azure TLS certificates. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

6681b67

Refresh certificate-pinning guidance: recommend against static pinning (#319931) * Refresh certificate-pinning guidance: recommend against static pinning Updates the certificate pinning article to reflect current industry best practices. Adds guidance that Azure recommends against static pinning of publicly trusted TLS server certificates, sections on when pinning may be appropriate, and risks/limitations of static pinning. Revives the content staged in the closed PR #317646. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Final-review style pass: contractions, active voice, sentence case, term consistency - Apply MSSG word choice (may -> can/might), contractions, and active voice - Sentence-case bold run-in headings; standardize "Web PKI" term - Lowercase "certificate authorities"; "man-in-the-middle" - customers -> you; split semicolon splice; expand description to 100-160 chars - Rename "Additional resources" -> "Related content" Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

0633cb3

Simplify AI platform layer sentence: drop concrete model-service examples The AI platform layer section is explicitly inherited from the AI shared responsibility model, which already carries concrete examples. Dropping the parenthetical (Foundry / Azure OpenAI / Security Copilot / M365 Copilot) tightens the boundary statement, avoids taxonomy drift as Foundry absorbs Azure OpenAI and hosts partner models like Anthropic, and keeps the reader focused on what the article uniquely covers. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

f19d121

PM feedback: add Azure SRE Agent as a PaaS agent example Added Azure SRE Agent to the PaaS agent examples in both the deployment model definition and the 'Configure before you customize' ladder. Per PM guidance, SRE Agent deploys as an Azure resource in your subscription, prices on usage, and provides an agent builder for custom subagents, skills, Python tools, MCP connectors, and hooks, which matches the PaaS agent pattern. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

542a8ee

PM feedback: drop Semantic Kernel from PaaS agent examples Semantic Kernel's role has been absorbed by the Microsoft Agent Framework; listing both together on the PaaS agent line was redundant and slightly misleading. Kept Microsoft Agent Framework as the SDK-based PaaS example. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

e1db35b

PM feedback: drop safety-system examples from AI application layer Removed 'Examples include Azure AI Content Safety and prompt shields' from the AI application layer description. Those are safety systems used by applications, not examples of applications themselves; dropping them avoids confusing the layer's scope. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

b2025db

Add AI agent shared responsibility model article (draft for review) (#317839) * Add AI agent shared responsibility model article Introduces a new fundamentals article covering the agentic layer that sits on top of the existing cloud and AI shared responsibility models. Adds a TOC entry and cross-links from the two sibling articles. Draft for PM/SME review — note block is left in place intentionally. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply LAA style suggestions - Drop 'you should' for a tighter sentence (shared-responsibility.md) - 'split' -> 'division of responsibility' - 'more ownership moves to you' -> 'you take more ownership' - 'This mitigates' -> 'This check mitigates' - 'you remain accountable' -> "you're always accountable" (contraction) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PM review: split, nest under AI shared responsibility - Split risks and security lifecycle into new companion article 'AI agent security considerations'. - Nest both agent articles under 'AI shared responsibility model' in the TOC (subpage framing) rather than as peers. - Remove the 'tool-calling safety' paragraph from the AI platform layer section (that concern is already implicit and was flagged as redundant). - Reformat risks so each mitigation lives on its own line. - Link 'distinct agent identity' to the Entra Agent ID doc. - Add OWASP Top 10 for Agentic AI (2025) alongside the LLM Top 10. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Add v1 SVG diagram for AI agent shared responsibility Draft SVG shows the six agentic layers across IaaS/PaaS/SaaS agent columns, color-coded C/M/S, with NEW badges on the three layers that don't exist in the LLM shared responsibility model. Hand-authored so design can iterate on it later without wrestling with Illustrator exports. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Fix Entra Agent ID link and NEW badge overlap in diagram - Correct Entra Agent ID doc path (build warning learn-site-link-broken): /entra/identity/enterprise-apps/agent-id (does not exist) -> /entra/agent-id/what-is-microsoft-entra-agent-id - Move NEW badges in the diagram from x=164 to x=20 so they no longer collide with the right-aligned layer labels. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply LAA present-tense suggestion - 'requesting user couldn't' -> 'requesting user can't' (use_present_tense) in confused-deputy risk description. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address PM round 2: consolidate, fix matrix, fix diagram - Fold the risks section from the companion article back into the main article as a compact 2-column risk/mitigation table, and drop the security-lifecycle section per PM guidance. - Delete the ai-agent-security-considerations.md companion article and its TOC entry. - Correct four PaaS matrix cells from Customer to Shared to reflect what Azure AI Foundry Agent Service provides today: * Agent identity and delegated token management (C -> S) * Per-action authorization checks (C -> S) * Orchestration guardrails (C -> S) * Multi-agent trust-boundary controls (C -> S) - Update the diagram Agent orchestration PaaS cell from Microsoft to Shared to match the corrected matrix. - Add a solid white background rect to the diagram so it renders correctly on Learn's dark theme (was partially blacked out). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Final review: description length, ai-usage tag, brand normalization, style polish - Shorten description to 147 chars (was 188). - Add ai-usage: ai-assisted; refresh ms.date. - Normalize product names: 'Microsoft Copilot Studio agents' throughout; 'Microsoft Security Copilot' link text (was 'Microsoft Copilot'). - Rewrite 'An agent doesn't just return content' to remove banned 'just'; 'not just at session start' -> 'not only at session start'. - 'biggest delta' -> 'biggest difference'. - Active voice on 'how the agent is consumed'. - Normalize bold-lead-period style across security-considerations bullets for the tools/actions and memory layers. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Rationalize AI security cluster: flatten agent SRM in TOC, cross-link best practices - TOC: promote 'AI agent shared responsibility model' to a peer of the parent AI SRM (was nested as a child). - ai-security-best-practices.md: link agent SRM in intro paragraph and Next steps. - ai-security-best-practices.md: add OWASP Top 10 for Agentic AI alongside MITRE ATLAS and OWASP LLM in the red-teaming reference list. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Improve accessibility of shared-responsibility diagram alt-text Replace generic alt-text ('Diagram showing responsibility zones', etc.) with descriptive text that conveys the diagram's structure and content for screen-reader users. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply aahill review: rebrand Azure AI Foundry to Microsoft Foundry Accept three suggestions from @aahill (Foundry docs team): - Azure AI Foundry Agent Service -> Microsoft Foundry Agent Service (x2) - Azure AI Foundry -> Microsoft Foundry (AI platform layer reference) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Pre-CELA cleanup: remove draft NOTE banner; add matrix disclaimer - Remove draft-review NOTE at top; article is ready for external review. - Add one-line disclaimer above the responsibility matrix noting that specific service responsibilities can vary from the general guide. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply CELA governance/liability caveat and rationalize scope across the three shared-responsibility articles CELA review recommended an optional caveat clarifying that 'responsibility' is used in a governance sense, not a legal one, and doesn't override contract terms. Applied consistently to all three articles so the caveat doesn't imply it applies only to agents. While the three articles were open together, tightened scope: - Cloud SRM: trimmed the 5-line 'AI shared responsibility' subsection down to two pointer sentences (AI SRM + agent SRM) in the intro. Removes a mini-explanation of AI SRM that duplicates the linked article. - AI SRM: removed the generic 'Security lifecycle' section (identify / protect / detect / respond / recover / govern) that doesn't discuss shared responsibility. Moved its AI red team link to Next steps. - AI SRM: added an intro pointer to the agent SRM so the three-article ladder is visible from every rung. - Agent SRM: no scope changes; caveat only. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address LAA feedback: drop draft '(new)' annotations from layer headings Applied accepted LAA suggestions and stripped the parallel '(new)' from 'Agent memory and state layer' for consistency. The rejected suggestions (mult-agent typo x2, contractions in the CELA caveat, and 'allow lists' in place of the one-word 'allowlist') were dismissed via review reply. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Address LAA feedback: 'Configure before you customize' heading Applied LAA suggestion to the agent SRM and propagated the same change to the AI SRM to keep the parallel section headings consistent. Contraction suggestions on the CELA caveats were rejected via review reply to preserve the CELA-reviewed wording. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Apply suggestion for blocking issue from PR review --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Courtney Wales <62625502+Court72@users.noreply.github.com>

a96eb39

Migration redis - 8/17 (#319520) * [migrate-content] Remove files * [migrate-content] Fix links * [migrate-content] Migrate Breadcrumbs. --------- Co-authored-by: Learn-Build-Service <ge-bsc-fte@microsoft.com>

3018333

Expand application DDoS protection guidance (#319387) * Revise DDoS protection article for clarity and detail Updated the title and description for clarity. Added new sections on defense layers and mitigation strategies for DDoS attacks, along with a checklist for baseline configuration. * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Update articles/web-application-firewall/shared/application-ddos-protection.md Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> * Apply suggestions from code review Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com> * Refine application DDoS protection guidance * Refine DDoS article formatting and links * Refine related DDoS links * Add DDoS article applicability * Fix Application Gateway rate limit attribution * Move application DDoS article to WAF root * Refine DDoS article punctuation * Reorder DDoS article applicability * Fix DDoS article heading capitalization --------- Co-authored-by: joeolerich <113947519+joeolerich@users.noreply.github.com> Co-authored-by: learn-build-service-prod-07[bot] <274430390+learn-build-service-prod-07[bot]@users.noreply.github.com> Co-authored-by: learn-build-service-prod-10[bot] <274431553+learn-build-service-prod-10[bot]@users.noreply.github.com>

d4a73b8

R02: Remove routine password-rotation advice