The forerunner of TLS, whose name is still applied to TLS. Terminating TLS at a load balancer is called SSL offload, and VPN Gateway's SSTP (SSL) and OpenVPN (SSL) P2S tunnels run TLS over TCP 443.
Also called Secure Sockets Layer.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-700DP-900AZ-400MD-102
Each book explains SSL in context, with comparison tables and the common traps.
Terms in this definition
- TLS
Transport Layer Security, the encryption protocol for traffic like HTTPS and Bastion sessions over port 443. On a storage account, minimumTlsVersion fixes the oldest accepted version without opening any network access.
- ELT
Extract, load, transform: raw data lands in the target system first and is transformed there. See ETL for the opposite order.
- TLS termination
Ending TLS at a gateway, for example Application Gateway, so traffic reaches backends as plain HTTP, or is encrypted again when end-to-end TLS is required.
- VPN gateway
Terminates IPsec tunnels for site-to-site, point-to-site and VNet-to-VNet connections, as a VPN-type virtual network gateway in GatewaySubnet. It gets a Standard static public IP when created, and that IP can't be swapped.
- SSTP
A Microsoft P2S tunnel type based on TLS, for Windows clients alone, capped at 128 connections and authenticating by RADIUS or certificate but not Entra ID. It is being retired in favour of OpenVPN or IKEv2: no new enablement after 31 August 2026, and connections cease on 31 March 2027.
- OpenVPN
Only this point-to-site tunnel type can use Microsoft Entra ID authentication. It is TLS-based, runs on TCP 443 and has clients for Android, iOS, Linux, macOS and Windows.
- Point-to-site VPN
Connection type in which single client machines, rather than whole sites, tunnel into an Azure virtual network gateway. App Service gateway-required VNet integration relies on it too.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
Related terms
- APIM protocols and ciphers
Blade in API Management for switching TLS/SSL protocols (SSL 3.0, for example) and cipher suites on or off, on the client side and towards backends. By default the minimum is TLS 1.2.
- SASL
Kafka's pluggable authentication layer (Simple Authentication and Security Layer). For Event Hubs, clients use
SASL_SSL, pickingPLAINwith a connection string orOAUTHBEARERfor Microsoft Entra ID. - Security Posture dashboard
Dashboard in Defender EASM that reports on open ports, CVE exposure, SSL certificate setup, hosting and networking, and how domains are administered.
- SSL profile
Settings on an Application Gateway v2 listener that hold a listener-specific SSL policy and client authentication, meaning the trusted client CA chain used for mutual TLS.