Concept and mechanism
Compute security combines administrative access, integrity, segmentation, and detection. Bastion supports administration without a public IP on the VM, subject to the selected configuration requirements. JIT limits time windows and source access to supported ports; window expiry does not automatically terminate established sessions. Trusted Launch adds Secure Boot and vTPM subject to support and compatibility. An unsigned driver can prevent boot when the chain is validated. Prepare recovery to a supported version before changing low-level components. Agentless scanning analyzes disk snapshots; its result does not replace all runtime telemetry or investigation of memory activity.
Guided application
Machine Configuration assesses in-guest state through its prerequisites and assignments, complementing policies that only observe resource properties. In fictional AKS, a private API protects a management boundary but does not establish segmentation between all pods. Review network policies, identities, and workload privileges. For applications, separate backend protection and token validation: an API should check audience, issuer, and required rights rather than merely accept a presented token. If WAF blocks a legitimate field after a release, confirm the rule ID and request before creating a minimal exclusion. Retain inspection of other attributes and applications; check legitimate and malicious cases. In the change plan, include an exception owner, later review, regression signals, and a rollback alternative. Fast recovery should retain decision traceability.
WAF exception: one attribute in a known rule, validated within the window, with an owner and review.
Common pitfalls
JIT as session termination; private API as pod isolation; snapshot as full runtime coverage; disabled WAF as a permanent solution.
Related topics: Identity, access, and governance · Storage, SQL, and keys · Private networks and diagnosis
Reduce exposure while distinguishing management, network, and execution boundaries.
Reference: AKS layered security · SC-500 guide updated 2026-05-13; Microsoft security documentation accessed 2026-09-30