One leg of the CIA triad: information remains correct and is only changed through approved means. Hashes, digital signatures and audit trails help guard it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Integrity in context, with comparison tables and the common traps.
Terms in this definition
- CIA triad
Three core aims of security: confidentiality, so only permitted people can see data; integrity, so data is not altered without permission; and availability, so data and services can be reached when they are needed.
- Audit
Policy effect that lets a request proceed but flags the resource as non-compliant and logs a warning to the activity log. Microsoft suggests beginning there and later moving to something enforcing, like Deny.
Related terms
- AH
Short for Authentication Header, an IPsec protocol that verifies the sender and integrity of an entire IP packet but leaves it unencrypted. Network security group rules can filter on it, as they can on TCP, UDP, ICMP and ESP.
- Device Health Attestation
Reports, measured only while Windows starts up, on things like code integrity, Secure Boot and BitLocker, so that compliance policies can check a device's health.
- Guest Attestation extension
Lets Azure monitor a VM's boot integrity by passing its vTPM boot measurements to Azure Attestation. The VM also needs Secure Boot and vTPM switched on and must be able to reach the
AzureAttestationservice tag outbound. - New-AzIpsecPolicy
Cmdlet in Az.Network for defining a custom IPsec/IKE policy on a connection, covering IKE encryption and integrity, DH group, IPsec encryption and integrity, PFS group, and SA lifetime and size.
- Normalisation
Breaking data out into one table per entity, joined by keys, so that each fact is stored once and integrity is easier to keep. Analytical systems often reverse it (denormalise) for performance.
- Play Integrity verdict
Google Play's judgement on how trustworthy an Android device is, from basic up to device integrity, optionally with strong hardware-backed evaluation. Having replaced SafetyNet attestation, it informs Intune compliance and app protection decisions.
- ReFS
Resilient File System, aimed at large scale and data integrity: checksums, block cloning, mirror-accelerated parity and online repair with Storage Spaces. Windows cannot boot from it, and disk quotas and ODX, both found in NTFS, are missing.
- Restrict app execution
Locks a device down so that nothing but Microsoft-signed code can run, by applying a code integrity policy. Microsoft Defender Antivirus must be present; Remove app restrictions lifts it again.