Tuesday, 12 May 2020

Use Azure Firewall for secure and cost-effective Windows Virtual Desktop protection

Work from home policies require many IT organizations to address fundamental changes in capacity, network, security, and governance. Many employees aren't protected by the layered security policies associated with on-premises services while working from home. Virtual desktop infrastructure (VDI) deployments on Azure can help organizations rapidly respond to this changing environment.  However, you need a way to protect inbound or outbound internet access to and from these VDI deployments.

Windows Virtual Desktop is a comprehensive desktop and application virtualization service running in Azure. It’s the only VDI that delivers simplified management, multi-session Windows 10, and optimizations for Office 365. You can deploy and scale your Windows desktops and apps on Azure in minutes and get built-in security and compliance features. In this post, we explore how to use Azure Firewall for secure and cost-effective Windows Virtual Desktop protection.

Microsoft Tutorial and Material, Azure Exam Prep, Azure Certification, Azure Guides

The Windows Virtual Desktop service is delivered in a shared responsibility model:

◉ Customer-managed RD clients connect to Windows desktops and applications from their favorite client device from anywhere on the internet.

◉ Microsoft-managed Azure service handles connections between RD clients and Windows Virtual Machines in Azure (including Windows 10 multi-session).

◉ Customer-managed virtual network in Azure hosts Windows 10 multi-session virtual machines in host pools.

Windows Virtual Desktop doesn't require you to open any inbound access to your virtual network. However, to ensure platform connectivity between customer-managed virtual machines and the service, a set of outbound network connections must be enabled for the host pool virtual network. While these dependencies can be configured using Network Security Groups, this configuration is limited to network-level traffic filtering only.

Microsoft Tutorial and Material, Azure Exam Prep, Azure Certification, Azure Guides

Host pool outbound access to Windows Virtual Desktop


Azure Firewall is a cloud-native firewall as a service (FWaaS) offering that allows you to centrally govern and log all your traffic flows using a DevOps approach. The service supports both application and network-level filtering rules and is integrated with the Microsoft Threat Intelligence feed for filtering known malicious IP addresses and domains. Azure Firewall is highly available with built-in auto scaling.

Azure Firewall provides a Windows Virtual Desktop FQDN Tag to simplify host pool outbound access to Windows Virtual Desktop. Use the following steps to allow outbound platform traffic:

◉ Deploy Azure Firewall and configure your Windows Virtual Desktop host pool subnet User Defined Route (UDR) to route all traffic via the Azure Firewall.

◉ Create an application rule collection and add a rule to enable the WindowsVirtualDesktop FQDN tag. The source IP address range is the host pool virtual network, the protocol is https, and the destination is WindowsVirtualDesktop.

Microsoft Tutorial and Material, Azure Exam Prep, Azure Certification, Azure Guides

The set of required storage and service bus accounts for your Windows Virtual Desktop host pool is deployment specific and isn't yet captured in the WindowsVirtualDesktop FQDN tag. Additionally, a network rule collection is needed to allow DNS access from your Active Directory Domain Services (ADDS) deployment and KMS access from your virtual machines to Windows Activation Service.

Host pool outbound access to the internet


Depending on your organization needs, you may want to enable secure outbound internet access for your end users. As Windows Virtual Desktop sessions are running on customer-managed virtual machines, they are also subject to your virtual network security controls. In cases where the list of allowed destinations is well-defined (for example, Office 365 access), you can use Azure Firewall application and network rules to configure the required access. This routes end-user traffic directly to the internet for best performance.

If you want to filter outbound user internet traffic using an existing on-premises secure web gateway, you can configure web browsers or other applications running on the Windows Virtual Desktop host pool with an explicit proxy configuration.

Monday, 11 May 2020

Prepare for Microsoft MS-900 Exam to Be Expert in Microsoft 365 Fundamentals


Fundamental skills in every technical role are essential in helping you find your place in this field. They help you to understand the fundamental requirements of a specific area, particularly if you are completely new in the industry. Learning this basic knowledge will help you evolve your interest in a particular field and obtain prerequisite skills for the higher level. This is why Microsoft has included the Fundamentals category in its certification track. Microsoft 365 Fundamentals MS-900 is one of the exams related to this level. This exam emphasizes the fundamentals of Microsoft 365.

Microsoft 365 Fundamentals MS-900 Exam and Associated Certification

Microsoft provides several certifications, which are split into three categories: Fundamentals, Associate, and Expert. One of the most coveted certifications in the Microsoft 365 Certified Fundamentals certification. Having this certification confirms that you are well-versed with the elements available in Microsoft 365 and the benefits they can fetch to an organization.
MS-900 is the only exam you will be needed to pass to achieve the Microsoft 365 Certified Fundamentals certification. It will gauge if you have the required skills.

The topics you will be examined on in the MS-900 exam will evaluate your understanding of:

  • Cloud concepts (15-20%)
  • Core Microsoft 365 services and concepts (30-35%)
  • Security, compliance, privacy, and trust in Microsoft 365 (25-30%)
  • Microsoft 365 pricing and support (25-30%)
Microsoft MS-900 exam comprises of 40-60 questions and needs to finish in 60 minutes. The exam cost is $99, though the price may differ.
Microsoft MS-900 exam will last for 60 minutes and will cost you $99, though the price varies according to the location you are taking the exam in.
Be prepared to answer different types of questions, among which you can face multiple-choice, short answer, active screen, active screen, amongst many.

Resources for Microsoft MS-900 Exam Preparation

There are a lot of methods you can utilize to prepare for the MS-900 exam.

Microsoft

Microsoft itself presented free online training and paid instructor-led training. The online course is excellent for people who wish to work at their own convenience while Instructor-led one is best for applicants who need more guidelines. Other than the resources given by Microsoft, you can also use many other external resources like:

YouTube

YouTube nowadays the best solution to academic problems for applicants. You can get free videos concerning to just any area covered in the MS-900 exam syllabus. Uploaded the test- takers or IT professionals, they are valuable resources for exam preparation.

Books

If you require a more thorough understanding of different aspects included in the Microsoft 365 Certified Fundamentals certification exam syllabus, books are an excellent option. Learning from the study guides will help you cover all exam topics and help you schedule study time in a correct manner.

Online Communities

There are many communities and forums aimed at the MS-900 exam. If you participate in them, you can interact with other candidates who share their experiences and preparation strategy they used, websites to take advantage of, and prep material to utilize. There can be experienced tutors to help you. You can get answers to your questions and acquire a lot of useful pieces of suggestions from them.

MS-900 Practice Tests

Practice tests help you assess your proficiency level before the real exam. One of the benefits of taking mock tests is that they help you identify your weak areas in the exam preparation. Sometimes you read and think you have learned so much; meantime, you have not. By taking practice tests, you can simply measure your level of understanding of any topic and know the areas you require to study further before you take the Microsoft MS-900 exam.

Tips to Prepare for MS-900 Exam

  • We have discussed different resources you can use to prepare for the MS-900 exam above. Now, let's figure out how you can make your preparation journey more productive.
  • Your first step is to create a study plan. Make a list of tasks you require to do to prepare for the exam and then find out what intervals of time you can commit to those tasks. By doing this, organize yourself more effectively and use your time more constructively.
  • Award yourself after each MS-900 exam topic you complete. This gives you the encouragement to complete the next. Thus, ensuring you go through each task without trouble.
  • As the saying goes "Practice makes perfect." Practice tests are the best way to ensure your brain strongly grasps the concepts learned. You can practice doing questions taking the MS-900 practice tests from a reliable and authentic site.
  • Create short notes. You can use quick notes to help you practice recollecting prolonged understanding utilizing a small clue. They can also be utilized to revive your understanding right before the exam.
  • If you are someone who finds it difficult to concentrate on one task for more than five minutes, then there is a straightforward trick you can practice to help you with it. Set the alarm on your phone for around 25 minutes and begin working on your exam and stop yourself from doing anything else without you hear the alarm go off. This is a technique that has demonstrated to work, so take a chance.
  • Join online forums. By participating in relevant discussions, you will be provoking your brain to think in a broader area. You will realize that you don't have answers to many questions, thus making you search for them and obtaining more information.
Conclusion

Achieving the Microsoft 365 Certified Fundamentals certification is an excellent way to boost your career in IT. To obtain this certification, you have to pass the MS-900 exam. But it is a popular truth that Microsoft exams are a little bit difficult. Irrespective, there are plenty of resources and tricks you can utilize pass your certification exam.

Sunday, 10 May 2020

Microsoft Services is now a Kubernetes Certified Service Provider

Modern applications are increasingly built using containers, which are microservices packaged with their dependencies and configurations. For this reason, many companies are either containerizing their existing applications or creating new complex applications that are composed of multiple containers.

As applications grow to span multiple containers deployed across multiple servers, operating them becomes more complex. To manage this complexity, Kubernetes, an open-source software for deploying and managing those containers at scale, provides an open source API that controls how and where those containers will run.

Kubernetes Certified Service Provider


Microsoft Services is now a Kubernetes Certified Service Provider (KCSP). The KCSP program is a pre-qualified tier of vetted service providers who have deep experience helping enterprises successfully adopt Kubernetes. The KCSP partners offer Kubernetes support, consulting, professional services, and training for organizations embarking on their Kubernetes journey.

We have trained hundreds of consultants on Kubernetes, developed a comprehensive service offering around Kubernetes, and successfully delivered Kubernetes engagements to many customers in all industries, all over the world.

Using our global reach and ecosystem, we empower organizations to put innovation into practice to deliver strategic business outcomes, maximize the value of cloud technology, and drive success through continual support.

Microsoft Services is your partner to enable your organization to leverage container capabilities and frameworks, such as Kubernetes, to adopt modern technologies to increase speed and agility while also maintaining control and good governance.

The Azure Workloads for Containers offering


We recognize a need to help you address your secure infrastructure challenges and requirements. We envision the containers infrastructure to be more than just the containers orchestration layer to include networking, storage, secrets, and Infrastructure as Code (IaC).

Microsoft Services has a full Kubernetes offering, called Azure Workloads for Containers. This offering is composed of several workstreams that focus on the activities and outcomes that are most relevant to our customers. These workstreams provide full flexibility to our customers as each one of them can be selected independently and customized to meet the specific needs of a given project.

Azure Study Materials, Azure Certification, Azure Study Material, Azure Guides

Below are the details of these workstreams.

Kubernetes foundation

◉ Design and plan Azure Kubernetes Service (AKS) cluster and shared services.
◉ Implement AKS cluster and shared services.
◉ Deploy application on AKS.
◉ Test application.
◉ Rollout to production. ​

Containers migration

◉ Assess, design, and plan migration.
◉ Migrate the containers-based application(s).
◉ Test the migrated application(s).
◉ Rollout to production.

Kubernetes security hardening

◉ Refactor your security controls for AKS.
◉ Secure your CI/CD pipeline (DevSecOps).
◉ Harden your AKS environment to meet your compliance obligations.
◉ Assist with third-party security product integration.

Kubernetes threat modeling

◉ Build a threat mo​​del based on the AKS cluster and the apps running on it.
◉ Identify threats and mitigations.
◉ Produce clear actions to mitigate the threats.

Application containerization

◉ Create container image(s) for one or multiple applications.
◉ Test the application(s) running as container.
◉ Deploy the application to an AKS cluster in production​.

Azure Study Materials, Azure Certification, Azure Study Material, Azure Guides

Friday, 8 May 2020

Microsoft 70-466 Certification Paves the Way to A Top Career

70-466, microsoft 70-466, exam 70-466, 70-466 exam, 70-466 certification, microsoft 70-466 exam, microsoft 70-466 certification, Microsoft 70-466 Practice Test, microsoft 70-466 certification exam, Microsoft SQL Server
It is an era of competition in every sphere of life. Survival of the fittest is required, and for that, it is essential for all people whether they belong to the field of 70-466 Information Technology or not to stay alert, updated, and proactive so that they can achieve the wanted results.

It is a golden opportunity for the people relating to the folds of information technology that such a leading organization like Microsoft provides now and then not just a new program but also a 70-466 course to understand the plan and work with it.

If you are looking to implement data models and reports using Microsoft SQL Server and gain faster insights on data, this is the ideal skill enhancement tool for you.

Microsoft SQL Server is a relational database management system with the primary purpose of storing and recovering data as requested by other software applications. Being able to tell a story using data is critical for today's growing businesses who want insight into their customers, products, etc.

Professionals seeking comprehensive knowledge of how to harness Microsoft SQL Server to deliver mission-critical performance will significantly benefit from the Microsoft 70-466 Practice Test. This practice test will prepare you to ace the Microsoft 70-466 certification exam confidently.

Who Should Give the 70-466 Exam?

Anyone who does not needs to shy away from the competition and stay ahead of everyone else should give 70-466 exam. After all, it is all about the continuation of the fittest. Those individuals who want to learn whereby to implement data models, make them and get the most out of their skills as IT Professionals.

Also, all those individuals who require to get certified by the leading organization worldwide this is a golden opportunity that should not be missed. The results will be that when he will receive the stamp of endorsement from Microsoft itself and will guarantee that he gets the best job available.

Why Should You Give the 70-466 Certification?

It is essential to understand that, along with time now. Then several new inventions will be practicing birth all around the world coping to make a place for them in the world of information technology. In such a case, your experience and education, no matter how new it is, and your experience no matter how large it is, will cause burning out.

So you need to have on modernizing and brushing up your skills, and for that, such a course is essential. This 70-466 certification course is necessary for implementing data models and getting a suitable SSAS solution as well as going for business intelligence programs.

The exam it aligns with is intended for business intelligence (BI) developers who focus on creating BI solutions that need implementing multi-dimensional data models, implementing and maintaining OLAP cubes, and creating information displays used in business decision making.

Obtaining 70-466 certification implies that you possess the fundamental knowledge to build an analysis services multidimensional database, manage, maintain. And troubleshoot SQL Server Analysis Services database, create a tabular data model, and make a report with SQL Server Reporting Services.

70-466 Certification Preparation Tips Directly from the Experts

Undoubtedly, experts’ tips can change the way you prepare. Therefore, our experts have joined all tips and tricks that helped them qualify for the 70-466 exam.

To get started, pull yourself together, begin organizing and make a planner and try to stick to it.
Secondly, make sure to follow your preparation daily. Also, do not try to do last minute prep. Further, that will only start to confusion and nothing else.

Further, allow yourself to get enroll in either an online or offline training course as well because training will increase your capability to solve the problem in the exam.
Glimpses of Getting the Microsoft 70-466 Certification
Lastly, always keep in mind that developed a clear understanding of all the topics before appearing for the 70-466 exam.

Self-evaluation Time

Make sure you are going through sample tests only after you have gone through the whole syllabus. All the sample test mock tests are designed in such a way that you encounter the real exam environment around you. After making sample tests, you can easily understand the areas you are lacking behind and work upon them. Practice papers can be from different sources. Remember, the more you test yourself, the better you are going to become.

So, START PRACTICING NOW!

Job Opportunities

There is tremendous scope for Microsoft 70-466 certified people in the market. The certification will add value and a strong base to your resume. Big players of the industry always give the accredited people high paying jobs.

After passing this exam, the candidate will have plenty of job options like:
  • Microsoft system administrator
  • Software developer and architecture
  • Network support specialist/network engineer
  • System analyst/support engineer

In Conclusion

Certainly, addition a Microsoft certification to your resume will aid you to stand out and get hired. So, if you are aspired to advance your career and motivated to follow your dream, then passing the 70-466 exam will be the last step towards being certified.

In other words, certification exams like the 70-466 exam will not only demonstrate that you have the skills required for the job but will also showcase your responsibility towards your dreams and aspirations. Training and certification do affect your profession undoubtedly in terms of financial benefits too. Not to mention, this will also showcase your dedication towards your dream and aspirations.

So, do not doubt your worth, buckle up!  Gear yourself up with all the resources, along with proper use of your time. With these resources, the 70-466 exam is entirely achievable.

So, take your career to the next level!

Thursday, 7 May 2020

How Azure VPN helps organizations scale remote work

In the weeks and months we have all been grappling with the global pandemic, there’s no doubt about the impact it has had on the lives of people everywhere. A shift to remote work is one of the widespread effects of the global pandemic, and we heard from organizations around the world who are looking for ways to enable more of their employees to work remotely for their safety and that of the community. With this shift, we’re working to address common infrastructure challenges businesses face when helping employees stay connected at scale.

Common challenges for businesses expanding secure, remote access


One of the major challenges while setting up remote access is providing workers/employees access to key internal resources, which may reside on-premises or Azure, for example, healthcare or government organizations who have sensitive patient or tax information in on-premises datacenters and other sensitive information in Azure.

Another challenge that the businesses around the world now face is how to quickly scale an existing VPN setup, which is typically targeted at a small portion of an organization’s workforce, to now accommodate all or most workers. Even within Microsoft, we’ve seen our typical remote access at 50,000+ employee spike to as high as 128,000 employees while we’re working to protect staff and our communities during the global pandemic.

How Azure VPN can help with secure, remote work at scale


The Azure network is designed to withstand sudden changes in the utilization of resources and can greatly help during periods of peak utilization. The Azure Point-to-Site (P2S) VPN Gateway solution is cloud-based and can be provisioned quickly to cater for the increased demand of users to work from home. It can scale up easily and be turned off just as easily.

Microsoft Tutorial and Materials, Microsoft Certification, Microsoft Exam Prep, Microsoft VPN, Azure Exam Prep

Tips to help you get started with Azure VPN Gateway


Based on the customers we’ve been working with and best practices we’ve established over our years of work with enterprises, here are tips to help your own company get started with Azure VPN Gateway:

◉ For scenarios where you need to access resources on-premises or in Azure, you can build a VPN Gateway in Azure and connect your existing VPN solution to Azure. This eliminates single point of failure to on-premises and provides nearly limitless scale.

◉ Use Azure Active Directory (Azure AD), certificate-based authentication, or RADIUS authentication to authenticate users and to validate the status of their device before allowing them on VPN.

◉ We recommend split tunneling VPN traffic. This allows network traffic to go directly to public resources—such as Office 365 and Windows Virtual Desktops—and prevents internet traffic from having to go back to the corporate office, reducing overall load and bandwidth on your corporate internet links and on-premises VPN infrastructure.

◉ To improve on-premises to Azure connectivity to support scale, you can work with your local telecommunications provider to temporarily increase connectivity to the internet. This can help scale your connectivity from your office or data center to Microsoft up to 10 Gbps.

◉ Apply all available security updates to your VPN and firewall devices. The patching and updates for the Azure VPN gateway are managed by Microsoft. For your on-premises devices, please follow the guidance from the device vendor.

Tuesday, 5 May 2020

Manage and find data with Blob Index for Azure Storage—now in preview

Blob Index—a managed secondary index, allowing you to store multi-dimensional object attributes to describe your data objects for Azure Blob storage—is now available in preview. Built on top of blob storage, Blob Index offers consistent reliability, availability, and performance for all your workloads. Blob Index provides native object management and filtering capabilities, which allows you to categorize and find data based on attribute tags set on the data.

Manage and find data with Blob Index


As datasets get larger, finding specific related objects in a sea of data can be difficult and frustrating. Previously, clients used the ListBlobs API to retrieve 5000 lexicographical records at a time, parse through the list, and repeat until you found the blobs you wanted. Some users also resorted to managing a separate lookup table to find specific objects. These separate tables can get out-of-sync—increasing cost, complexity, and frustration. Customers should not have to worry about data organization or index table management, and instead focus on building powerful applications to grow their business.

Blob Index alleviates the data management and querying problem with support for all blob types (Block Blob, Append Blob, and Page Blob). Blob Index is exposed through a familiar blob storage endpoint and APIs, allowing you to easily store and access both your data and classification indices on the same service to reduce application complexity.

To populate the blob index, you define key-value tag attributes on your data, either on new data during upload or on existing data already in your storage account. These blob index tags are stored alongside your underlying blob data. The blob indexing engine then automatically reads the new tags, indexes them, and exposes them to a user-queryable blob index. Using the Azure portal, REST APIs, or SDKs, you can then issue a FindBlobsByTags API call specify a set of criteria. Blob storage will return a filtered result set consisting only of the blobs that met the match criteria.

The below scenario is an example of how Blob Index works:

1. In a storage account container with a million blobs, a user uploads a new blob “B2” with the following blob index tags: < Status = Unprocessed, Quality = 8K, Source = RAW >.

2. The blob and its blob index tags are persisted to the storage account and the account indexing engine exposes the new blob index shortly after.

3. Later on, an encoding application wants to find all unprocessed media files that are at least 4K resolution quality. It issues a FindBlobs API call to find all blobs that match the following criteria: < Status = Unprocessed AND Quality >= 4K AND Status == RAW>.

4. The blob index quickly returns just blob “B2,” the sole blob out of one million blobs that matches the specified criteria. The encoding application can quickly start its processing job, saving idle compute time and money.

Azure Tutorial and Material, Azure Learning, Azure Certification, Azure Exam Prep

Platform feature integrations with Blob Index

Blob Index not only helps you categorize, manage, and find your blob data but also provides integrations with other Blob service features, such as Lifecycle management.

Using the new blobIndexMatch as a filter, you can move data to cooler tiers or delete data based on the tags applied to your blobs. This allows you to be more granular in your rules and only move or delete data if they match your specified criteria.

The following sample lifecycle management policy applies to block blobs in the “videofiles” container and tiers objects to archive storage after one day only if the blobs match the blob index tag of Status = ‘Processed’ and Source = ‘RAW’.

Azure Tutorial and Material, Azure Learning, Azure Certification, Azure Exam Prep

Lifecycle management integration with Blob Index is just the beginning. We will be adding more integrations with other blob platform features soon!

Conditional blob operations with Blob Index tags


In REST versions 2019-10-10 and higher, most blob service APIs now support a new conditional header, x-ms-if-tags, so that the operation will only succeed if the specified blob index tags condition is met. If the condition is not met, the operation will fail, thus not modifying the blob. This functionality by Blob Index can help ensure data operations only occur on explicitly tagged blobs and can protect against inadvertent deletion or modification by multi-threaded applications.

How to get started


To enroll in the Blog Index preview, submit a request to register this feature to your subscription by running the following PowerShell or CLI commands:

Register by using PowerShell

Register-AzProviderFeature -FeatureName BlobIndex -ProviderNamespace Microsoft.Storage

Register-AzResourceProvider -ProviderNamespace Microsoft.Storage

Register by using Azure CLI

az feature register --namespace Microsoft.Storage --name BlobIndex

​az provider register --namespace 'Microsoft.Storage'

After your request is approved, any existing or new General-purpose v2 (GPv2) storage accounts in France Central and France South can leverage Blob Index’s capabilities. As with most previews, we recommend that this feature should not be used for production workloads until it reaches general availability.

Sunday, 3 May 2020

Azure Container Registry: Mitigating data exfiltration with dedicated data endpoints

Azure Container Registry announces dedicated data endpoints, enabling tightly scoped client firewall rules to specific registries, minimizing data exfiltration concerns.

Pulling content from a registry involves two endpoints:

◉ Registry endpoint, often referred to as the login URL, used for authentication and content discovery.
A command like docker pull contoso.azurecr.io/hello-world makes a REST request which authenticates and negotiates the layers which represent the requested artifact.

◉ Data endpoints serve blobs representing content layers.

Azure Tutorial and Material, Azure Certification, Azure Exam Prep, Azure Learning

Registry managed storage accounts


Azure Container Registry is a multi-tenant service, where the data endpoint storage accounts are managed by the registry service. There are many benefits for managed storage, such as load balancing, contentious content splitting, multiple copies for higher concurrent content delivery, and multi-region support with geo-replication.

Azure Private Link virtual network support


Azure Container Registry recently announced Private Link support, enabling private endpoints from Azure Virtual Networks to be placed on the managed registry service. In this case, both the registry and data endpoints are accessible from within the virtual network, using private IPs.

The public endpoint can then be removed, securing the managed registry and storage accounts to access from within the virtual network.

Azure Tutorial and Material, Azure Certification, Azure Exam Prep, Azure Learning

Unfortunately, virtual network connectivity isn’t always an option.

Client firewall rules and data exfiltration risks


When connecting to a registry from on-prem hosts, IoT devices, custom build agents, or when Private Link may not be an option, client firewall rules may be applied, limiting access to specific resources.

Azure Tutorial and Material, Azure Certification, Azure Exam Prep, Azure Learning

As customers locked down their client firewall configurations, they realized they must create a rule with a wildcard for all storage accounts, raising concerns for data-exfiltration. A bad actor could deploy code that would be capable of writing to their storage account.

To mitigate data-exfiltration concerns, Azure Container Registry is making dedicated data endpoints available.

Azure Tutorial and Material, Azure Certification, Azure Exam Prep, Azure Learning

Dedicated data endpoints


When dedicated data endpoints are enabled, layers are retrieved from the Azure Container Registry service, with fully qualified domain names representing the registry domain. As any registry may become geo-replicated, a regional pattern is used:

[registry].[region].data.azurecr.io.

For the Contoso example, multiple regional data endpoints are added supporting the local region with a nearby replica.

With dedicated data endpoints, the bad actor is blocked from writing to other storage accounts.

Azure Tutorial and Material, Azure Certification, Azure Exam Prep, Azure Learning

Enabling dedicated data endpoints


Note: Switching to dedicated data-endpoints will impact clients that have configured firewall access to the existing *.blob.core.windows.net endpoints, causing pull failures. To assure clients have consistent access, add the new data-endpoints to the client firewall rules. Once completed, existing registries can enable dedicated data-endpoints through the az cli.

Using az cli version 2.4.0 or greater, run the az acr update command:

az acr update --name contoso --data-endpoint-enabled

To view the data endpoints, including regional endpoints for geo-replicated registries, use the az acr show-endpoints cli:

az acr show-endpoints --name contoso

outputs:

{
  "loginServer": "contoso.azurecr.io",
  "dataEndpoints": [
    {
      "region": "eastus",
      "endpoint": "contoso.eastus.data.azurecr.io",
    },
    {
      "region": "westus",
      "endpoint": "contoso.westus.data.azurecr.io",
    }
  ]
}

Security with Azure Private Link


Azure Private Link is the most secure way to control network access between clients and the registry as network traffic is limited to the Azure Virtual Network, using private IPs. When Private Link isn’t an option, dedicated data endpoints can provide secure knowledge in what resources are accessible from each client.

Source: azure.microsoft.com