One-Pager · 12 Services

Azure
Security

Every Azure security service on one page — identity, network security, threat protection, and information protection. A quick reference for architects building secure environments.

Identity & Access

Microsoft Entra ID
Cloud identity platform. SSO, MFA, Conditional Access, PIM. Foundation for zero trust. Formerly Azure Active Directory.
Identity platformZero trustSSO / MFAConditional Access
Key Vault
Centralized secrets, keys, and certificate management. HSM-backed. RBAC and access policies. Integrates with App Service, AKS, VMs, DevOps pipelines.
Secrets mgmtCertificatesHSM-backedRBAC
Managed Identities
Automatic credential management for Azure resources. No secrets in code. System-assigned or user-assigned. Works with any Entra ID-compatible service.
No credentialsAuto-managedSystem/user assignedBest practice

Network Security

Azure Firewall
Managed stateful firewall. FQDN filtering, threat intelligence feed, TLS inspection (Premium). Integrates with Firewall Manager for multi-hub policies.
Network FWFQDN filteringThreat intelTLS inspection
Web Application Firewall
Protects web apps from OWASP top 10, bot attacks, and custom rules. Deployed on Application Gateway, Front Door, or CDN.
Web protectionOWASP top 10Bot protectionCustom rules
DDoS Protection
Always-on volumetric attack mitigation. Adaptive tuning, rapid response team, cost guarantee. Standard tier includes metrics and alerting.
DDoS defenseAlways-onCost protectAdaptive tuning
Private Link
Access PaaS services over private endpoints inside your VNet. No public internet exposure. Traffic stays on Microsoft backbone.
Private PaaSNo exposureVNet nativeBackbone only

Threat Protection

Microsoft Defender for Cloud
CSPM and CWPP in one. Secure Score, regulatory compliance dashboards, workload protection for VMs, containers, SQL, storage, and more.
CSPM / CWPPSecure ScoreComplianceWorkload protect
Microsoft Sentinel
Cloud-native SIEM and SOAR. Collects data at cloud scale, AI-driven detection, automated playbooks. Data connectors for 100+ sources.
SIEM / SOARAI detectionPlaybooks100+ connectors
Defender for Endpoint
Endpoint detection and response (EDR). Threat and vulnerability management, attack surface reduction, automated investigation. Cross-platform.
EDRVuln mgmtAuto investigationCross-platform

Information Protection

Microsoft Purview
Data governance across on-premises, multi-cloud, and SaaS. Data catalog, classification, lineage, and sensitivity labels. Unified data map.
Data governanceClassificationLineageSensitivity labels
Azure Information Protection
Classify and protect documents and emails with labels. Encryption, visual markings, and access controls that travel with the data.
Doc protectionLabelsEncryptionRights mgmt

Quick Comparison — Threat Protection

ServiceScopeDetectionResponseBest For
Defender for CloudAzure workloadsSecure Score, alertsRecommendationsPosture management, compliance
SentinelEnterprise-wideAI analytics, KQLSOAR playbooksSIEM, incident response
Defender for EndpointEndpointsBehavioral, MLAuto investigationEDR, vulnerability mgmt