Signing every Azure App Configuration REST API request with a secret access key. Once local authentication is turned off, every access key is removed, so only Microsoft Entra ID remains for authentication.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains HMAC in context, with comparison tables and the common traps.
Terms in this definition
- App Configuration
Central store in Azure for feature flags and application settings. Its key-values can be made read-only, but those locks differ from Resource Manager locks.
- REST
Short for representational state transfer, the style of HTTP API that Azure services expose.
- API
Short for application programming interface: a contract that client code calls programmatically, for example a web API secured with tokens or the Files, Images or Responses APIs.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - LSDOU
The sequence in which Group Policy is processed: the local policy first, followed by site, domain and organisational unit policies. The nearest, last-processed setting takes effect unless Enforced or Block Inheritance alters that.
- Authentication
Checking an identity claim made by a person, device or app, for instance by asking for a password plus an extra factor. Authorisation only happens once this step has succeeded.
- Microsoft Entra ID
Cloud identity service from Microsoft, previously named Azure AD, which provides the tenant behind Microsoft 365 and Azure.