#
--attach-acr
Az aks create/update parameter that grants the cluster's kubelet identity AcrPull on a registry.
@secure() decorator
Bicep decorator on a string or object parameter or output that stops Resource Manager logging it or keeping it in deployment history; @description only documents.
A
Access keys (storage account keys)
The two 512-bit storage account keys that sign every account and service SAS; regenerating both invalidates all such SASs and direct key access.
Access package
Entitlement management bundle of groups, apps and sites with request policies and expiry; when the assignment expires its resource access is removed.
Access restrictions (App Service access restrictions)
App Service inbound allow/deny rules by IP range, service tag or subnet; the way to limit an app to specific public IPs such as corporate NAT addresses.
Access reviews
Entra ID Governance feature for recurring attestation of guests, app users or group members, with self-review and auto-removal of non-responders; not PIM, which covers privileged roles only.
Account SAS
SAS signed with the account key that can span several services (ss), resource types (srt) and permissions (sp), including service-level operations; denied when Shared Key is disabled.
AcrPull
Built-in ACR data-plane role to pull images and read tags; it must be on the identity that actually pulls, which for ACI is a user-assigned managed identity.
AcrPush
Built-in ACR role to push and pull images; the least-privilege push role, but it can't sign images.
AcrQuarantineWriter
Built-in ACR role to push quarantined images and change their quarantine state; part of the quarantine feature, not image signing.
Active assignment
PIM assignment that is in effect without activation for its assignment duration.
Active Directory - Integrated (Microsoft Entra Integrated)
SSMS authentication option that reuses a hybrid user's Windows sign-in (federation or seamless SSO) without prompting.
Active Directory - Password (Microsoft Entra Password)
SSMS authentication option where the user types an Entra user name and password.
Activity log
Subscription log of management-plane operations (deployments, Policy events), kept 90 days; it records no data-plane access such as Key Vault reads.
AD DS (Active Directory Domain Services)
The on-premises Windows domain service with domain controllers; see also Microsoft Entra Domain Services for the managed version.
AD DS authentication (Azure Files)
Storage account setting that registers (domain-joins) the account in on-premises AD DS so synced hybrid users mount SMB shares with Kerberos; share-level permissions come from RBAC, file-level from Windows ACLs.
Additional context (Authenticator)
Authenticator setting that shows the requesting application name and the sign-in's geographic location in push and passwordless notifications; Temporary Access Pass has no such feature.
ADLS Gen2 (Azure Data Lake Storage Gen2)
Standard GPv2 storage with hierarchical namespace enabled, giving real directories and POSIX-style ACLs for analytics.
Admin consent
Tenant-wide consent to an app's permissions granted by an authorised admin; always required for application permissions and not conferred by app ownership.
Admin consent workflow
Setting that lets users request admin approval for apps they can't consent to; designated reviewers act on requests, but approving still needs a role that can grant admin consent.
Administrative units
Entra containers that scope directory administration; not Azure Policy scopes or cost groupings.
Advanced hunting
KQL query tool in the Defender portal over 30 days of raw Defender XDR data (and onboarded Sentinel data) for hunting and custom detections; it detects after the fact and doesn't block at runtime.
Advanced Threat Protection
Defender for SQL component alerting on potential SQL injection, vulnerability to injection, brute force and access from unusual locations or principals.
AES (Advanced Encryption Standard)
Symmetric cipher; AES-256 is the TDE data encryption key that the RSA TDE protector wraps.
Agent ID Administrator
Privileged Entra role that manages the lifecycle of agent identities and blueprints; it can't approve partner agent permissions or grant admin consent.
Agent identity
Special service principal for an AI agent with no credentials of its own; it acts autonomously with app-only permissions or on behalf of a user with delegated permissions, and Conditional Access can only block it (no grant controls).
Agent identity blueprint
Microsoft Entra Agent ID template for a kind of agent that holds the credentials and acquires tokens for its agent identities; its permissions are inherited only after admin consent, and it can't hold Azure RBAC roles.
Agent risk
Conditional Access condition using ID Protection's risk level for agent identities; a policy on All agent identities with Agent risk = High and Block (a Microsoft template) stops flagged agents getting tokens.
Agent's user account (agent user)
Optional Entra user account paired 1:1 with an agent identity for systems that need a user object (mailbox, Teams, OneDrive); it has no password or passkey and can't hold privileged admin roles.
Agentless discovery for Kubernetes
Defender for Containers and Defender CSPM capability giving API-based inventory and posture of Kubernetes clusters via the Kubernetes Agentless Operator role; it doesn't block or admit pods.
Agentless malware scanning
Defender for Servers Plan 2 feature that scans VM disk snapshots for malware with Defender Antivirus engines, without an agent; Defender CSPM alone doesn't include it.
Agentless scanning (agentless machine scanning)
Defender for Cloud scanning of VM disk snapshots for vulnerabilities, software and secrets without installing an agent.
AI Administrator
Entra role for Microsoft 365 Copilot and AI settings that can also grant tenant-wide admin consent, except for Microsoft Graph application permissions.
AI bill of materials (AI BOM)
Inventory of generative AI application components (models, SDKs, data sources) built by AI security posture management in Defender CSPM.
AI gateway in Azure API Management
Set of API Management gateway features (not a separate product) available in all tiers that fronts model APIs, MCP servers and A2A agent APIs to authenticate callers, meter tokens and screen content.
AI Red Teaming Agent
Microsoft Foundry tool (built on PyRIT) that simulates adversarial probing of models and agents and reports attack success rate; it finds risk but doesn't block anything.
AI security posture management (AI-SPM)
Defender CSPM capability that discovers generative AI workloads, builds an AI bill of materials and surfaces AI recommendations and attack paths; not in Foundational CSPM, Defender for App Service or Defender for APIs.
AKS (Azure Kubernetes Service)
Managed Kubernetes with full cluster and node-pool control; autoscales with HPA and the cluster autoscaler; has no built-in user sign-in.
All resources (Conditional Access) (All cloud apps)
Conditional Access target covering every resource, including the Azure portal and Microsoft 365; broader than Microsoft Azure Management.
Allow Azure services and resources to access this server
Azure SQL networking switch that admits connections from any Azure IP, including other customers', so clear it for least privilege.
Allow storage account key access (AllowSharedKeyAccess)
Storage account setting that, when Disabled, rejects every Shared Key-authorised request (account keys, account and service SAS) with 403; it grants nothing to Entra identities, and user delegation SAS still works.
AllowAzureLoadBalancerInBound
Default inbound NSG rule (priority 65001) allowing Azure Load Balancer health probes.
allowBlobPublicAccess (Allow Blob anonymous access)
Storage account property that, when false, disallows anonymous read access for every container and overrides container-level access settings.
Allowed resource types
Built-in Azure Policy (Deny) that blocks every resource type not on its list.
AllowVNetInBound
Default inbound NSG rule (priority 65000) allowing traffic from the VirtualNetwork tag, including peered VNets.
Always Encrypted
SQL column encryption performed on the client with keys the engine never sees, so DBAs and cloud admins see only ciphertext.
Amazon EC2 (EC2)
AWS virtual machine service; the native AWS connector with Defender for Servers auto-provisions Azure Arc and Defender components to new EC2 instances.
Amazon ECR (ECR)
AWS container registry whose images Defender for Containers scans through the AWS connector.
AMD SEV-SNP (Secure Encrypted Virtualization-Secure Nested Paging)
AMD hardware technology that isolates and encrypts VM memory, used by the DCasv5/DCadsv5 and ECasv5/ECadsv5 confidential VM series.
Analytics rule
Microsoft Sentinel rule that queries ingested data, raises alerts and groups them into incidents; rules detect but don't remediate, and their logic is written in KQL.
Analytics tier
Microsoft Sentinel hot tier for detections, hunting and all Sentinel features, with analytics retention extendable up to two years.
Annotate and block
Foundry guardrail action that flags and blocks detected risk; at the tool call intervention point it stops the tool call from executing.
Anonymous IP address
ID Protection sign-in risk detection for sign-ins from an anonymizing proxy such as Tor.
API Management llm-content-safety policy
AI gateway policy that sends prompts or completions to Azure AI Content Safety and blocks with 403 on harm-category thresholds (0 strictest, 7 most lenient), blocklists or shield-prompt attacks.
API Management llm-token-limit policy
AI gateway inbound policy that limits tokens per counter key, returning 429 when tokens-per-minute is exceeded and 403 when a token-quota is exhausted; estimate-prompt-tokens blocks before the backend call.
API Management validate-jwt policy
Inbound policy that checks a JWT's signature, issuer, audience and required claims (for example against the Entra OpenID configuration) and rejects missing or invalid tokens with 401 by default before they reach the backend.
API permissions
Entra app-registration blade where a client requests delegated or application permissions, which then appear as token claims after consent.
API server authorized IP address ranges
AKS feature limiting the public Kubernetes API server to listed IP ranges; the least-effort lock-down because it can be enabled on an existing public cluster.
APIM named values (named values)
Name/value pairs used in APIM policies, stored plain, secret (encrypted in APIM) or as Key Vault references read by the instance's managed identity with Get/List secret permission.
APIM protocols and ciphers (Protocols + ciphers)
APIM blade to enable or disable client-side and backend TLS/SSL protocols (e.g. SSL 3.0) and cipher suites; TLS 1.2 is the default minimum.
APIM subscription key (Ocp-Apim-Subscription-Key)
Caller key sent in a header or query string to call APIs through API Management; checked by APIM, not an Entra token.
App Configuration Data Owner
Azure data-plane role for App Configuration key-values; grants no Entra directory permissions such as admin consent.
App consent policy
Policy of include/exclude conditions that governs which permissions users (or custom roles) may consent to; built-in examples include microsoft-user-default-low.
App manifest (application manifest)
JSON definition of an Entra app registration's attributes (e.g. groupMembershipClaims, accessTokenAcceptedVersion, keyCredentials), editable in the portal.
App registration
Entra ID object defining an application's identity, permissions and supported account types; used for OpenID Connect sign-in and multi-tenant apps.
App roles
Roles an API defines on its app registration; for app-to-app calls they arrive as the roles claim in client-credentials tokens.
App Service
Managed PaaS web hosting (web apps, Web App for Containers) in a sandbox with no OS access; autoscale and slots from Standard.
App Service custom domain
Hostname added to an App Service app after App Service verifies the A/CNAME record and an asuid TXT record; HTTPS then needs a TLS certificate binding.
App settings
Name/value pairs passed to an App Service app as environment variables, overriding Web.config or appsettings.json values; they can be made slot-specific.
Append blob
Blob of blocks optimised for append-only writes such as logs; can't be tiered.
Append effect
Azure Policy effect that adds fields at create or update time only; it cannot fix existing resources.
Application Administrator
Entra role that manages all app registrations and enterprise applications, including application proxy, and can grant admin consent except for Microsoft Graph app roles.
Application Developer
Entra role that can register applications even when "Users can register applications" is No; it can't manage other apps.
Application Gateway
Regional layer-7 load balancer with SSL offload, URL routing, cookie affinity and optional WAF; plays no part in Entra SSO to on-premises apps.
Application Gateway Basic SKU
Application Gateway v2 SKU for low-traffic apps with header rewrite but no URL rewrite, mTLS or WAF.
Application Gateway Ingress Controller (AGIC)
AKS add-on that programs an Application Gateway WAF v2 from Kubernetes Ingress resources.
Application object
Global definition of an app in its home tenant (the app registration), from which a service principal is created in each tenant that uses it.
Application permissions
App-only Entra permissions acting with no signed-in user, so they cover every user's data; not least privilege for per-user access.
Application rule
Azure Firewall rule filtering outbound HTTP, HTTPS and MSSQL by destination FQDN (URL filtering needs Premium); processed after DNAT and network rules.
Application security group (ASG)
Group of VM network interfaces used as a source or destination in NSG rules instead of IP addresses; it can't trigger alert actions.
Application segment (app segment)
Microsoft Entra Private Access destination (FQDN, wildcard FQDN, IP or range) plus ports and protocol on an enterprise application; only users assigned to that application can reach traffic matching it.
Approved Inventory
Defender EASM asset state for assets you directly own; the only state shown in dashboard charts by default, and scanned daily.
ARM template
Declarative JSON IaC file for Azure deployments; fire-and-forget, with no live link like Blueprints (which is being retired in phases, fully on 31 January 2027).
Artifact Registry (Google Artifact Registry)
Google Cloud container registry whose images Defender for Containers scans through the GCP connector.
ASIM parsers (Advanced Security Information Model parsers)
KQL functions that normalise Sentinel data into common schemas at query time, after ingestion is billed, so they don't reduce ingestion cost.
ASN (autonomous system number)
Identifier of a network routing domain, one of the internet asset types Defender EASM discovers.
Asset chain-based management
Defender EASM bulk removal of assets by the seed, discovery chain entry or discovery group that brought them in, removing all downstream assets too.
AssignableScopes
Role-definition list of where a custom role can be assigned: a management group, subscription, named resource group or resource.
Attack paths (attack path analysis)
Defender CSPM feature that maps exploitable chains of weaknesses leading to critical assets.
Attack surface composition
Section of the Defender EASM Attack Surface Summary dashboard that only counts assets by category and lists no insights.
Attack surface priorities
Section of the Defender EASM Attack Surface Summary dashboard that groups insights by high, medium and low severity; low includes deprecated technology and soon-to-expire infrastructure.
Attack Surface Summary
Defender EASM dashboard with a high-level overview; its Attack Surface Priorities section ranks insights by severity, while Attack surface composition only counts assets.
Audit action group
Predefined set of audited database-engine events (for example BATCH_COMPLETED_GROUP) chosen in an audit policy; the Azure SQL portal default is BATCH_COMPLETED_GROUP plus successful and failed database authentication.
Audit effect
Azure Policy effect that logs a warning and marks matching resources non-compliant but never blocks or changes anything.
AUDIT_CHANGE_GROUP
Audit action group raised whenever an audit or audit specification is created, modified or deleted; it records audit configuration changes, not queries or logins.
AuditIfNotExists
Azure Policy effect that marks a resource non-compliant when a related resource (details.type matching existenceCondition) is missing; it reports only and deploys nothing.
Authentication methods policy
Tenant policy that enables each authentication method (Authenticator, FIDO2, TAP, CBA, SMS) for target users or groups.
Authentication strength
Conditional Access grant control (Require authentication strength) that limits which method combinations satisfy a policy, e.g. built-in Phishing-resistant MFA; it restricts methods but doesn't enable them, which is the Authentication methods policy's job.
Automation rule
Sentinel rule that runs on incident or alert creation or update, from any source, to assign owners, change status, add tags and run playbooks centrally.
AWS connector (Defender for Cloud) (native AWS connector)
Defender for Cloud security connector added under Environment settings > Add environment > Amazon Web Services and completed by deploying the generated CloudFormation template in AWS; with Defender for Servers it auto-provisions Azure Arc to EC2 instances.
azcmagent
Command-line tool of the Azure Connected Machine agent; azcmagent connect onboards a server to Azure Arc, unattended with a service principal ID and secret or certificate.
AzCopy
Command-line copy tool for storage data; cannot manage queues or copy running VMs.
AZFWNetworkRule
Resource-specific Log Analytics table of Azure Firewall network rule log entries.
Azure ABAC (attribute-based access control)
Role assignment conditions layered on RBAC, e.g. by blob index tag; supported for blobs (including ADLS Gen2) and queues, not Files or Tables.
Azure AD B2C
Customer identity service; APIM validate-jwt can validate its tokens through its OpenID configuration.
Azure Arc
Service that manages non-Azure servers in place through the Azure Connected Machine agent; not a migration tool.
Azure Arc-enabled servers
Windows and Linux machines outside Azure connected through the Azure Connected Machine agent so they appear as Azure resources and can run AMA with DCRs.
Azure Automation
Runbook service for imperative scripts, e.g. AVD scaling; not IaC and cannot revoke access in reviews.
Azure Backup
Backup service storing recovery points in a Recovery Services vault, including long-term retention; not DR failover like Site Recovery.
Azure Backup always-on soft delete (enhanced soft delete)
Irreversible soft delete state for Recovery Services and Backup vaults that keeps deleted backup data for 14-180 days (14 by default, first 14 free) and can't be disabled; it doesn't cover operational backups of blobs and Azure Files.
Azure Backup security PIN
Five-minute PIN generated under Recovery Services vault Properties that hybrid backups (MARS, MABS, DPM) require for Stop protection with delete data and Change passphrase; it doesn't protect Azure VM backups.
Azure Bastion
Brokers RDP and SSH over TLS on port 443 from the portal, so VMs need no public IPs; unlike JIT, which opens 3389/22.
Azure Blueprints
Deprecated packaging of policies, roles and templates with a live link to assignments; assignments target one subscription. No new definitions since 31 July 2026; retires fully on 31 January 2027, replaced by deployment stacks and Template Specs.
Azure Connected Machine agent
The Azure Arc agent that makes non-Azure servers Azure Arc-enabled so Defender for Cloud can deploy extensions; install it first when onboarding on-premises servers.
Azure Connected Machine Onboarding
Azure built-in role that lets a service principal onboard machines to Azure Arc at scale, without broader rights.
Azure Container Registry (ACR)
Private container image registry with geo-replication, retention and ACR Tasks; webhooks drive continuous deployment.
Azure Content Delivery Network (CDN)
Caches static web content at edge points of presence near users; Azure CDN Standard from Microsoft (classic) accepts no new profiles and retires on 30 September 2027, so new deployments use Azure Front Door Standard or Premium.
Azure custom roles
Azure RBAC roles you define with your own actions when built-in roles don't fit; up to 5,000 per tenant, and not the mechanism behind multi-user authorization.
Azure Database for MariaDB
Retired managed MariaDB service (resource provider Microsoft.DBforMariaDB); resetting its admin password needed Microsoft.DBforMariaDB/servers/write.
Azure Database for PostgreSQL
Managed PostgreSQL that scales up and adds read replicas (no multi-master); horizontal write scale-out comes from its elastic clusters (Citus) feature.
Azure DDoS Protection
Service that mitigates volumetric and protocol DDoS attacks on public IPs; tiers are the free infrastructure protection, DDoS IP Protection and DDoS Network Protection.
Azure DevOps Administrator
Entra role that manages enterprise Azure DevOps policies for organisations backed by the tenant; it grants no app registration or admin consent rights.
Azure Disk Encryption (ADE)
In-guest encryption of OS and data disks with BitLocker or DM-Crypt and keys in Key Vault; no ephemeral OS disks, Write Accelerator disks or dynamic volumes, and it retires on 15 September 2028.
Azure Disk Encryption for volume encryption
Key Vault access policy (enabled-for-disk-encryption) that ADE requires before it can write keys and secrets to the vault, which must be in the VM's region.
Azure Event Hubs
High-volume telemetry ingestion over HTTPS/AMQP; a destination for diagnostic settings.
Azure Files
Managed SMB/NFS file shares; no Archive tier and one account-wide encryption key.
Azure Files OAuth over REST
Lets Entra users, groups and managed identities call the FileREST data API with OAuth tokens; requires a role with readFileBackupSemantics/writeFileBackupSemantics, not the SMB share roles.
Azure Firewall
Managed stateful network firewall, deployable in Virtual WAN hubs and managed by Firewall Manager.
Azure Firewall Manager
Central management of Azure Firewall policies with parent-child inheritance across regions and subscriptions.
Azure Firewall rule collection
Group of same-type rules (DNAT, network or application) inside a rule collection group with one action and a priority; priority orders collections only within a rule type.
Azure Firewall Standard
Azure Firewall SKU with network and application rules, threat intelligence filtering and DNS proxy, but no TLS inspection or IDPS.
Azure Front Door
Global layer-7 entry point with anycast failover, TLS termination, URL routing and WAF with rate limiting.
Azure Functions
Serverless event-driven code (Consumption, Premium or Dedicated plan) run by triggers such as timer, HTTP, Blob or Event Grid.
Azure Functions Consumption plan
Legacy event-driven serverless Functions plan with 10-minute maximum runs, no VNet integration and no inbound private endpoints (Flex Consumption, Premium and Dedicated support them).
Azure Functions Dedicated plan (App Service plan)
Functions on an App Service plan with unlimited run time and VNet integration from Basic.
Azure geography
A set of regions (e.g. United States) within which a Key Vault backup can be restored.
Azure Information Protection (AIP)
Classification and protection service applying one label per document (the last matching label in the policy wins) in Office apps; the classic client is retired in favour of Microsoft Purview sensitivity labels.
Azure Instance Metadata Service (IMDS)
Non-routable VM endpoint 169.254.169.254 that issues managed-identity tokens; not the login.microsoftonline.com endpoint.
Azure Key Vault (Key Vault)
Store for secrets, keys and certificates; where a same-geography pair exists it replicates there, with best-effort Microsoft-initiated failover during which the vault is read-only.
Azure Key Vault provider for Secrets Store CSI Driver (azure-keyvault-secrets-provider)
AKS add-on that mounts Key Vault secrets, keys and certificates into pods as CSI volumes and can sync them to Kubernetes secrets.
Azure Kubernetes Service Cluster Admin Role
Built-in role that can only list the AKS cluster admin credential (kubeconfig); it grants nothing on a container registry.
Azure Load Balancer
Regional layer-4 load balancer (Standard is zone-redundant); no WAF, TLS termination or URL routing.
Azure Machine Configuration (guest configuration)
Azure Policy feature that audits or applies OS settings inside Azure and Arc-enabled machines; the successor to the DSC extension and State Configuration.
Azure Monitor
Azure's unified observability service that collects, analyses and alerts on metrics, logs and traces from Azure and hybrid resources.
Azure Monitor agent (AMA)
Current agent collecting guest-OS logs according to DCRs; replaced the Log Analytics agent (MMA).
Azure Monitor alerts
Rules that notify or act when metric, log or activity-log conditions are met; they don't enforce SAS expiry or storage access.
Azure Monitor Logs
The log half of the Azure Monitor data platform, storing log and performance data in Log Analytics workspaces and queried with KQL.
Azure Network Function Manager
Service that deploys partner network functions (such as mobile packet core) to Azure Stack Edge devices; not a VNet security tool.
Azure Pipelines
Azure DevOps CI/CD with environments, approvals and checks for IaC deployments.
Azure Policy
Enforces and audits resource configuration (location, SKU, tags) through definitions and assignments; not a deployment tool or access control.
Azure Policy for Kubernetes (Azure Policy add-on for AKS)
AKS add-on (Arc extension elsewhere) that extends Gatekeeper v3 as an admission controller webhook so Azure Policy definitions with the Deny effect reject non-compliant pods.
Azure Policy initiative
A group of Azure Policy definitions assigned together; Defender for Cloud security policies and custom standards must be initiatives.
Azure Private Link (Private Link)
Platform that exposes PaaS services such as Azure Storage on a private endpoint in your VNet over the Microsoft backbone; needs VNet and DNS setup and does not admit a public IP.
Azure RBAC permission model (Key Vault)
Key Vault access granted through role assignments such as Key Vault Secrets User; replaces access policies.
Azure security baseline (Machine Configuration)
Built-in Machine Configuration baselines (Azure Security Baseline for Windows/Linux, CIS Linux Benchmarks) customised with the Modify settings wizard under Policy > Machine Configuration for Azure and Arc-enabled machines; built-in definitions can't be edited directly.
Azure Service Health (Service Health)
Personalized view of Azure platform incidents, planned maintenance and advisories affecting your subscriptions; it records no user identity for resource operations.
Azure SQL auditing
Writes Azure SQL audit logs to a storage account (same region as the server in the portal; not premium FileStorage or legacy BlobStorage), a Log Analytics workspace (the only KQL-queryable target) or Event Hubs.
Azure SQL connection policy (Proxy / Redirect)
Azure SQL setting for whether clients connect through the gateway (Proxy) or directly to the node (Redirect); it changes routing, not access.
Azure SQL Database
PaaS single database or elastic pool; up to 4 TB (128 TB Hyperscale); no cross-database queries, SQL Agent or CLR.
Azure SQL Managed Instance (MI)
PaaS SQL Server instance with near-full compatibility (SQL Agent, CLR, cross-database queries); regional DR only via auto-failover groups.
Azure Stack Edge
Microsoft-managed edge appliance for on-premises compute, AI and network functions, managed from Azure.
Azure Storage Explorer (Storage Explorer)
Desktop app for working with data in existing storage accounts (blobs, tiers, file shares, tables, queues, SAS URLs); it can't create storage accounts.
Azure Storage firewall
Storage account network rules (Public network access set to selected networks) that admit only listed VNet subnets, IP ranges, resource instances and trusted services to the public endpoint and deny everything else.
Azure Virtual Network Manager
Central management of connectivity (hub-and-spoke or mesh) and security admin rules across VNets and subscriptions; not a packet capture or diagnostic tool.
Azure VPN Client
Microsoft VPN client app (Windows 11, macOS) required for Entra ID P2S connections; configured by importing azurevpnconfig.xml from the profile package.
AzureBastionSubnet
Required name of Azure Bastion's dedicated subnet, /26 or larger for every SKU since 2 November 2021 (/27 was accepted before).
AzureDiagnostics
Shared Log Analytics table holding Azure resource logs sent by diagnostic settings in legacy Azure diagnostics mode (for example Azure Firewall logs), not guest-OS logs.
AzureFirewallSubnet
Required name of the dedicated subnet (/26 or larger) that Azure Firewall is deployed into.
AzureRM
Retired Azure PowerShell module (deprecated 29 February 2024) replaced by Az; e.g. Get-AzureRmRoleDefinition became Get-AzRoleDefinition.
B
Backend pool
Load balancer targets by NIC IP configuration (or IP); limited to one VNet, and a Standard pool can't include a VM with a Basic public IP.
Backup Management Service
Azure Backup's service app that must be granted Key Vault key and secret access (access policy or Key Vault role) to back up ADE-encrypted VMs.
Backup Operator
Built-in role that can run backups and restores in a vault but can't remove backups or create vaults or policies.
Basic Load Balancer
Retired (30 September 2025) Load Balancer SKU with a backend pool limited to one availability set, scale set or standalone VM, no zones or HA Ports, Basic public IPs only and open by default.
BATCH_COMPLETED_GROUP
Audit action group capturing every completed query batch and stored procedure text; part of the recommended Azure SQL audit set.
BGP (Border Gateway Protocol)
Dynamic routing protocol used over ExpressRoute and VPN; over ExpressRoute private peering, the only way routes (including a forced-tunnelling 0.0.0.0/0) are exchanged.
BGP route propagation
Route table setting (Propagate gateway routes) that controls whether routes learned by a VNet gateway reach the subnet; disable it on spoke subnets so on-premises routes don't bypass the firewall.
BitLocker (BitLocker Drive Encryption)
Windows full-volume encryption; Import/Export drives are AES-256 BitLocker-encrypted.
Blast radius (Exposure Management) (View blast radius)
Exposure Management graph view that shows, from a selected node such as a choke point or identity, how its compromise could propagate to critical assets, with no manual analysis.
Blob index tags
Key-value attributes on blobs that are indexed for search and can drive lifecycle filters (blobIndexMatch) and ABAC conditions; a SAS cannot filter by them.
Blob storage
Object storage for unstructured data such as video and images; block blobs up to about 190.7 TiB.
BlobStorage (legacy account)
Legacy blob-only standard account kind with access tiers; retiring on 13 October 2026, so upgrade to GPv2.
Block access (Conditional Access)
Conditional Access grant option that denies access when the policy applies; it overrides every other control, so satisfying MFA or device compliance in another policy never gets past it.
BlockBlobStorage
Premium SSD account for block and append blobs with lowest latency; LRS or ZRS only, no access tiers.
Boot integrity monitoring
Trusted launch capability (portal Integrity monitoring, CLI --enable-integrity-monitoring) that uses the Guest Attestation extension to remotely attest a healthy boot, with Defender for Cloud alerting on attestation failure.
Built-in authentication for App Service and Container Apps (Easy Auth)
Platform sign-in layer (a sidecar in Container Apps) for Microsoft Entra ID, GitHub, Google, Facebook, X or any OpenID Connect provider; Require authentication rejects unauthenticated requests, and it should be used with HTTPS only.
BYOK (bring your own key)
Using your own key in Key Vault as a customer-managed TDE protector or storage encryption key.
C
Calendars.ReadWrite
Microsoft Graph permission to create, read, update and delete events; the application version covers all calendars in the organisation (admin consent), the delegated version only the signed-in user's calendars.
Candidate (Defender EASM asset state)
Defender EASM state for an asset with some but not enough connection to your seeds; you must review ownership manually, and it's scanned only during discovery.
CanNotDelete (Delete lock)
Resource lock level that allows reads and changes but blocks deletion; it doesn't block moves.
CEF (Common Event Format)
Syslog-based text log format used by firewalls and other appliances; Sentinel ingests it through a Linux log forwarder into the CommonSecurityLog table.
CEF via AMA
Microsoft Sentinel connector that receives CEF messages on a Linux log forwarder running AMA and a DCR; it replaces the legacy CEF connector that used the Log Analytics agent.
Certificate authentication (P2S) (Azure certificate)
P2S authentication type in which the gateway trusts an uploaded root certificate and each client presents a client certificate issued from it.
Certificate lifetime actions
Key Vault certificate-policy triggers (days before expiry or percentage of lifetime) that either auto-renew the certificate or email contacts; certificates renew this way, not through a key rotation policy.
Certificate-based authentication (CBA)
Entra sign-in with X.509 user certificates issued by your PKI; enabling it for a group adds an option and can satisfy MFA passwordlessly, without blocking others.
Checkov
Open-source IaC scanner run by Microsoft Security DevOps that checks ARM, Terraform, CloudFormation, Kubernetes, Helm and Dockerfiles, covering more formats than Template Analyzer.
CIDR (Classless Inter-Domain Routing)
IP address range notation, e.g. an AKS overlay pod range.
Classic subscription administrators (Service Administrator and Co-Administrators)
Legacy subscription-wide admin roles (Account Administrator, Service Administrator, Co-Administrator), retired August 2024; use Azure RBAC instead.
Client secret (application password)
App registration credential created under Certificates & secrets; its value is shown only once. Public clients don't use one.
Cloud App Security Administrator
Entra role that manages Microsoft Defender for Cloud Apps; no app registration or consent rights.
Cloud Application Administrator
Entra role like Application Administrator but without application proxy management.
Cloud security explorer
Defender CSPM tool for building graph queries on the cloud security graph, with built-in templates; it queries existing findings and doesn't scan.
Cloud security graph
Defender for Cloud graph-based context engine (inventory, exposure, permissions, vulnerabilities, lateral movement) that attack path analysis and cloud security explorer run on; needs Defender CSPM.
CloudAppEvents
Advanced hunting table of enriched Office 365 and connected SaaS app activity that is populated only by Defender for Cloud Apps with its Microsoft 365 connector, not by Purview Audit on its own.
Codeless Connector Framework (CCF)
Framework for building SaaS Microsoft Sentinel connectors without code: define the output (custom) table, the DCR, the connector UI and the connection rules, in that order.
Column encryption key (CEK)
Always Encrypted key that encrypts column data; stored encrypted in database metadata and fetched by the driver, never handed to clients.
Column master key (CMK (Always Encrypted))
Always Encrypted key kept outside the database (Azure Key Vault or Windows certificate store) that protects column encryption keys; clients need access to it.
CommonSecurityLog
Log Analytics table holding CEF messages received through a Sentinel log forwarder.
Communication Compliance (Microsoft Purview Communication Compliance)
Purview insider-risk solution that detects potentially inappropriate or regulatory-violating messages (email, Teams, Copilot interactions) for reviewers to act on; it doesn't own DLP policies.
Conditional Access
Entra ID P1 policy engine that grants access with controls such as MFA or compliant device, based on conditions like named locations or risk.
Conditional Access App Control
Reverse-proxy integration of Entra Conditional Access with Defender for Cloud Apps that applies access and session policies to browser sessions in real time.
Confidential disk encryption
OS-disk encryption for confidential VMs only that binds keys to the VM's TPM so only that VM can read the disk.
Confidential VM
VM on AMD SEV-SNP or Intel TDX hardware whose memory is encrypted from the host; needs a confidential size (e.g. DCasv5, ECasv5) and a supported image (not Debian).
Connectivity configuration
Azure Virtual Network Manager configuration that builds hub-and-spoke or mesh topologies (peerings or connected groups) across a network group; it doesn't make gateways exchange routes.
Contained user (contained database user)
Database user authenticated at the database without a master login, e.g. created with CREATE USER ... FROM EXTERNAL PROVIDER for an Entra user, group or managed identity.
Container Apps environment
Security and networking boundary for Azure Container Apps whose networking choices (workload profiles or Consumption only, own VNet, internal or external) are fixed at creation.
Container Apps peer-to-peer encryption
Container Apps environment setting, off by default, that TLS-encrypts traffic between apps with platform-managed certificates; it authenticates apps to each other but doesn't authorise calls between them.
Container Apps workload profiles
Default Container Apps environment type with Consumption and Dedicated profiles and a /27 minimum subnet that supports UDRs, NAT Gateway egress and private endpoints, which the legacy Consumption-only type (/23) doesn't.
Container image vulnerability assessment
Defender for Containers agentless scanning of registry and running container images for CVEs, triggered on push, import or recent pull.
Copilot Studio (Microsoft Copilot Studio)
Low-code platform for building AI agents and workflows; generative agents can send each tool invocation to an external threat detection provider such as Microsoft Defender.
Copilot Studio external threat detection
Power Platform admin center setting (preview) that sends every proposed tool invocation of a generative Copilot Studio agent to a provider endpoint authorised through a Microsoft Entra app ID, which allows or blocks it (default allow if no answer in one second).
Cosmos DB (Azure Cosmos DB)
Globally distributed NoSQL database with multi-region writes, automatic indexing and under 10 ms latency.
CREATE USER FROM EXTERNAL PROVIDER
T-SQL that creates a Microsoft Entra contained database user (user, group, service principal or managed identity); it adds Entra access but doesn't block SQL logins.
Cross-tenant CMK (cross-tenant customer-managed keys)
Storage CMK configuration using a key vault in another Entra tenant through a multitenant app and federated credential.
Custom IPsec/IKE policy (IPsec/IKE connection policy)
Per-connection set of IKE (Phase 1) and IPsec (Phase 2) algorithms, DH and PFS groups and SA lifetimes; every parameter must be specified and one policy applies per connection, not per gateway.
Custom log table (_CL table)
Log Analytics table with a user-defined schema and a _CL name suffix, fed by a DCR, for data that doesn't fit a standard table.
Custom roles (Azure custom roles)
Azure RBAC roles you define with your own actions when built-in roles don't fit; up to 5,000 per tenant, and not the mechanism behind multi-user authorization.
Custom string masking function (partial())
Dynamic data masking function that exposes a set number of leading and trailing characters with custom padding between them.
Customer-managed keys (CMK)
Your own RSA or RSA-HSM key (2048, 3072 or 4096 bits) in Key Vault or Managed HSM that wraps the storage account encryption key; can be enabled after creation, but CMK support for tables and queues is creation-only.
CVE (Common Vulnerabilities and Exposures)
Public catalogue of numbered software vulnerabilities, used in Defender EASM's Security Posture dashboard and in vulnerability assessment results.
D
Daemon app
Background app or service with no signed-in user that authenticates as itself (client credentials) and so needs application permissions granted with admin consent.
Data access governance reports (DAG reports)
SharePoint Advanced Management reports in the SharePoint admin center: activity reports (sharing links and EEEU sharing in the last 28 days) and snapshot reports (site permissions, content shared via Everyone or EEEU) that identify oversharing.
Data collection endpoint (DCE)
Endpoint receiving Logs Ingestion API data; can be added to AMPLS for private ingestion.
Data collection rule (DCR)
Defines what AMA or the Logs Ingestion API collects (e.g. XPath event filters) and where it goes.
Data connector (Microsoft Sentinel data connector)
Microsoft Sentinel component that ingests data from a Microsoft service, Azure resource or third-party source into the Sentinel workspace; it ingests only and doesn't detect or respond.
Data Discovery & Classification
Labels sensitive SQL columns; does not encrypt or mask them.
Data Lake Storage Gen1 (ADLS Gen1)
Retired first-generation Azure Data Lake store (retired February 2024), replaced by ADLS Gen2.
Data lake tier (Microsoft Sentinel data lake)
Low-cost Microsoft Sentinel storage tier for rarely used logs, queryable with KQL queries, KQL jobs and search jobs, with total retention up to 12 years.
Data plane
Operations on the contents of a vault (keys, secrets, certificates), authorised by access policies or Key Vault data roles and subject to the Key Vault firewall.
Data Security Posture Management (DSPM)
Microsoft Purview solution that discovers sensitive-data risks and consolidates DLP, Insider Risk Management and sensitivity-label insights, with data risk assessments and remediation for oversharing.
DataActions
Role-definition list of data-plane operations such as blob reads or VM login/action; data actions put in Actions don't work.
Database scoped credential
Database credential created with CREATE DATABASE SCOPED CREDENTIAL, requiring CONTROL on the database.
Database-level auditing
Azure SQL auditing policy set on one database that runs side by side with server-level auditing, adding its own destinations; disabling it never stops the server audit for that database.
db_datareader
Fixed database role that can read all user tables; combine with db_datawriter for least-privilege read/write.
db_datawriter
Fixed database role that can insert, update and delete data in all user tables but can't read them.
db_owner
Fixed database role with full control of the database; over-privileged for data access, and membership only via an Entra group can't create database scoped credentials (error 2760).
DCasv5 (DCadsv5)
AMD SEV-SNP confidential general-purpose VM sizes; D2ads_v5 and Ddsv5 look similar but are not confidential.
Dedicated cluster (Log Analytics)
Log Analytics cluster tier required for Azure Monitor Logs customer-managed keys; a storage account CMK doesn't cover Log Analytics.
Default security rules (NSG)
Six rules every NSG gets at priority 65000-65500 (AllowVnetInBound, AllowAzureLoadBalancerInBound, DenyAllInBound and the outbound AllowVnetOutBound, AllowInternetOutBound, DenyAllOutBound); you can't delete them, only override them with custom rules numbered 100-4096.
Default to Microsoft Entra authorization in the Azure portal
Storage account setting that makes the portal use the user's Entra credentials for data access by default; it is not the prerequisite for identity-based SMB access.
Default user permissions
Entra User settings such as Users can register applications and Restrict access to the Microsoft Entra administration portal; the portal restriction is UI-only, not a security boundary.
default() masking function
Dynamic data masking function that fully masks a column: XXXX for strings, 1900-01-01 for date, 1900-01-01 00:00:00.0000 for datetime, zero for numbers.
Defender Antivirus passive mode
Microsoft Defender Antivirus state where a third-party antivirus is primary and Defender doesn't remediate but EDR keeps working; on Windows Server it must be forced with ForceDefenderPassiveMode.
Defender CSPM
Paid Defender for Cloud posture plan adding attack path analysis, cloud security explorer, agentless scanning and AI security posture management.
Defender EASM inventory filters
Filters on the Defender EASM inventory, which shows only Approved assets by default; remove the State = Approved filter to see other states.
Defender EASM labels
Free-text tags applied to Defender EASM assets to add business context; they don't change state, scanning or ownership.
Defender for Cloud Apps session policy
Conditional Access App Control policy that monitors or controls actions (download, upload, copy) inside browser sessions; it doesn't evaluate AI agent tool calls.
Defender for Cloud Data and AI security dashboard
Subscription-level Defender for Cloud dashboard of data and AI resources, coverage, top issues and internet exposure; the full view needs Defender CSPM with sensitive data discovery, Defender for Storage, Defender for Databases and AI threat protection.
Defender for Cloud DevOps security (Defender for DevOps)
Defender for Cloud capability that connects Azure DevOps, GitHub and GitLab and shows code, secret, dependency and IaC findings in one console; it catches issues early but only an Azure Policy Deny stops deployments that bypass the pipeline.
Defender for Cloud email notifications
Defender for Cloud alert emails, by default for High severity only and throttled per recipient to about 4 high, 2 medium and 1 low a day.
Defender for Cloud pull request annotations (PR annotations)
DevOps security feature that comments on IaC findings in only the pull request diff in Azure DevOps or GitHub; it needs Defender CSPM, and in Azure DevOps a Build Validation policy on main plus Contributor or Owner to enable.
Defender for Cloud workload protection plans (Azure Defender)
Paid Defender for Cloud plans (Servers, Storage, Databases, Containers, App Service, Key Vault, Resource Manager, APIs) that add threat protection; there is no plan for virtual networks.
Defender for container registries
Retired Defender plan that scanned ACR images on push, import or recent pull (Linux only at exam time); now part of Microsoft Defender for Containers.
Defender for Containers runtime threat protection
Defender sensor-based detection of suspicious activity in Kubernetes clusters, nodes and workloads that raises alerts after pods run; it doesn't prevent admission.
Defender for Identity (Microsoft Defender for Identity)
Monitors on-premises AD for threats; not an access-review or governance tool.
Defender for Servers Plan 1
Entry Defender for Servers tier giving Defender for Endpoint integration (EDR, malware protection) and agent-based vulnerability scanning; FIM, JIT and agentless scanning need Plan 2.
Defender for Servers Plan 2
Higher Defender for Servers tier adding file integrity monitoring, agentless scanning, JIT VM access and (since August 2023) Defender for DNS alerts; enabled at subscription or Log Analytics workspace.
Defender for Storage malware scanning (on-upload malware scanning)
Defender for Storage feature scanning uploaded blobs with Microsoft Defender Antivirus, billed per GB with a per-account monthly cap (default 10,000 GB); results go to blob index tags, alerts, Event Grid or Log Analytics.
Defender security for AI agents
Defender portal setup that connects the Microsoft 365 app connector and Copilot Studio (same Entra App ID) so Defender evaluates agent tool invocations at runtime and blocks risky ones, surfacing alerts and incidents.
Defender sensor
Defender for Containers DaemonSet on cluster nodes that collects runtime telemetry via eBPF for runtime threat detection; deployed as an AKS security profile or an Arc extension on EKS/GKE.
Delegated permissions
Entra permissions letting an app act as the signed-in user on only that user's data.
Deny assignments
Azure RBAC denials that override role assignments; historically only Azure services (such as deployment stacks) created them, today you can also create user-assigned ones with New-AzDenyAssignment or az role deny-assignment create (write, delete and action operations only, not groups).
Deny effect
Azure Policy effect that blocks non-compliant create and update requests, so nothing is deployed for Audit to report.
DenyAllInBound
Default inbound NSG rule (priority 65500) denying everything not allowed earlier, including internet traffic.
Dependency (Defender EASM asset state)
Defender EASM state for third-party infrastructure that directly supports your owned assets, kept in inventory separately from Approved Inventory.
DeployIfNotExists
Azure Policy effect that deploys an ARM template when a related resource is missing; it fixes existing resources only through a remediation task under the assignment's managed identity.
Deterministic encryption
Always Encrypted type producing the same ciphertext for a value, allowing equality lookups, joins, grouping and indexing but revealing patterns.
Diagnostic setting
Routes a resource's logs and metrics to storage, Log Analytics, Event Hubs or a partner; up to five per resource.
Directory Reader (Directory Readers)
Microsoft Entra role (not an Azure role) for reading basic directory information; members have it by default, but a guest who assigns Sentinel incidents needs it.
Directory.Read.All
Microsoft Graph permission to read directory data (users, groups, apps); as an application permission it's the minimum for a daemon reading the directory and always needs admin consent.
Discovery group
Defender EASM cluster of seeds and exclusions run as one discovery on its own recurrence schedule (weekly by default); deleting it or one of its seeds can remove every asset it discovered.
Discovery seeds
Known assets (domains, hosts, IP blocks, ASNs, email contacts, WHOIS organisations) that Defender EASM recursively scans to find connected external assets; private IP addresses can't be seeds.
DNAT rule (destination network address translation)
Azure Firewall rule that translates the firewall's public IP and port to a private IP and port and implicitly allows that traffic; always processed first.
DNS proxy
Azure Firewall policy setting that makes the firewall resolve and proxy DNS for clients, required for FQDNs in network rules.
docker push
Docker CLI command that uploads a tagged local image to a registry, after az acr login and docker tag with the login server.
DSC (Desired State Configuration)
PowerShell configuration management applied to VMs; does not create VMs.
DSPM for AI (Microsoft Purview Data Security Posture Management for AI)
Purview solution for Copilot, agent and AI-app data security whose one-click recommendations create policies (such as DLP policies scoped to Microsoft 365 Copilot and Copilot Chat) that are then edited in the owning solution, not in DSPM.
Dynamic data masking
Masks query output (e.g. last four digits) for non-privileged users without changing stored data; UNMASK bypasses it.
Dynamic groups
Entra groups with rule-based membership from user attributes; not an access review.
E
E5 (Microsoft 365 E5)
Licence bundle including Entra ID P2 and ID Governance features.
EC (elliptic curve)
Key Vault key type (P-256, P-384, P-521); not supported for storage customer-managed keys.
EDR (endpoint detection and response)
Defender for Endpoint behavioural detection and response for post-breach activity; it keeps working when Defender Antivirus is in passive mode.
EDR in block mode
Defender for Endpoint Plan 2 feature that lets Defender Antivirus in passive mode block and remediate post-breach EDR detections; an extra layer, not a fix for antivirus conflicts.
EEEU (Everyone except external users)
Built-in SharePoint group containing every internal user but no guests; content shared with it (a public site or public item) is visible org-wide and can surface in Microsoft 365 Copilot results.
Elevate access (Access management for Azure resources)
Entra Properties toggle that gives the signed-in Global Administrator User Access Administrator at root scope (/); it applies only to that admin.
Eligible assignment
PIM assignment that the user must activate (with any required MFA, justification or approval) before the role takes effect.
Enable access to Azure Virtual Machines for deployment
Key Vault advanced access policy letting VMs retrieve certificates stored as secrets; not what ADE needs.
enabledForTemplateDeployment
Key Vault setting (Azure Resource Manager for template deployment) that lets Resource Manager read secrets during deployments; the deployer also needs Microsoft.KeyVault/vaults/deploy/action.
Encryption at host
VM option that encrypts temp disks, ephemeral OS disks and caches on the host so data flows encrypted to storage; it can't be combined with ADE and is the ADE replacement.
Encryption scopes
Per-container or per-blob encryption keys on top of account encryption; blob only.
EnforceOPAConstraint
Deprecated Azure Policy effect for Kubernetes clusters (with EnforceRegoPolicy) that applied Open Policy Agent Gatekeeper constraints; not used for Azure resources and now replaced by Audit/Deny with Azure Policy for Kubernetes.
Enterprise application
Entra service-principal object where users are assigned and SSO and Conditional Access are applied.
Enterprise exposure graph (exposure graph)
Graph of assets, identities, findings and relationships from Defender for Cloud, Defender for Endpoint, Defender for Identity, Entra ID and connectors that Exposure Management uses to build attack paths; queryable in advanced hunting.
Entra ID P1
Entra licence needed for Conditional Access and Password Protection for on-premises AD.
Entra ID Protection (Identity Protection)
Entra ID P2 service evaluating user and sign-in risk and running the MFA registration policy.
Event Grid
Event router that pushes events (such as Key Vault SecretNearExpiry) to handlers like Azure Functions; not a store.
Event Grid custom topic
User-created Event Grid endpoint that receives events (e.g. Defender for Storage scan results) and pushes them to subscribers such as Azure Functions or Logic Apps.
existenceCondition
Condition under a policy rule's details (for AuditIfNotExists and DeployIfNotExists) that the related resource must match; if it evaluates true, the effect doesn't trigger.
Expose an API
App registration blade that defines an Application ID URI and the delegated scopes the app offers to clients; it doesn't configure platforms, token claims or app role assignment.
F
FAILED_DATABASE_AUTHENTICATION_GROUP
Database-level audit action group recording failed logins to the database; part of the recommended Azure SQL audit set.
FAILED_LOGIN_GROUP
Server-level SQL Server audit action group for failed instance logins; not one of the recommended Azure SQL Database groups.
Federated identity credential (workload identity federation)
Trust that lets an external workload (e.g. GitHub Actions, Kubernetes) exchange its token for an Entra token without a secret.
FIDO2 security key (passkey (FIDO2))
Phishing-resistant, passwordless hardware authenticator; shows no number or location.
File integrity monitoring (FIM)
Defender for Servers Plan 2 feature that tracks changes to OS files, registry keys and config files on Windows and Linux machines.
Firewall policy (Azure Firewall policy)
Resource holding Azure Firewall rules and settings that can be applied to many firewalls across regions and hubs; Standard or Premium tier.
Forced tunnelling
Sending all internet-bound Azure traffic on-premises: over ExpressRoute by advertising 0.0.0.0/0 via BGP; over site-to-site VPN via BGP or a default site.
ForceDefenderPassiveMode
REG_DWORD under HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection set to 1 before onboarding to put Defender Antivirus on Windows Server into passive mode.
Foundational CSPM
Free Defender for Cloud posture tier giving recommendations, Secure Score and the Microsoft cloud security benchmark; it does not include AI-SPM, attack paths or threat protection.
Foundry evaluations
Microsoft Foundry scoring of model and agent quality and safety with built-in or custom evaluators; measures risk without blocking at runtime.
Foundry guardrail
Named collection of controls (risk, intervention point, action) in Microsoft Foundry; a guardrail assigned to an agent fully overrides the guardrail of its underlying model deployment.
FQDN (fully qualified domain name)
Complete DNS name including the zone, such as www.example.com.
Frontend IP configuration
Load balancer IP address clients connect to, public or private; rules and inbound NAT rules reference it.
G
Gatekeeper (OPA Gatekeeper)
Open Policy Agent admission controller webhook for Kubernetes that Azure Policy for Kubernetes extends; standalone installs aren't supported alongside the add-on.
GatewaySubnet
Dedicated subnet for VPN or ExpressRoute gateways; /27 recommended minimum.
GDPR (General Data Protection Regulation)
EU personal-data regulation; Defender EASM has a GDPR Compliance dashboard for related risks.
GDPR Compliance dashboard
Defender EASM dashboard surfacing personal-data compliance risks such as exposed PII, login protocols, cookies and certificate issues.
General-purpose v1 (GPv1, Storage)
Legacy storage account kind (kind Storage) with no access tiers, Archive or premium file shares, retiring by October 2026; upgrade to GPv2 (irreversible) before converting to ZRS.
Get-AzPolicyAssignment
Az PowerShell cmdlet that reads existing policy assignments by name and scope or ID; it creates nothing.
Get-AzPolicyDefinition
Az.Resources cmdlet that retrieves a policy definition (e.g. by -Name) to pass to New-AzPolicyAssignment.
Get-AzPolicyRemediation
Az.PolicyInsights cmdlet that reads existing remediation tasks; it remediates nothing.
Global Administrator
Microsoft Entra role with full directory administration; it grants no Azure data-plane access unless the holder elevates access to manage subscriptions.
Global Secure Access
Microsoft's Security Service Edge umbrella for Microsoft Entra Internet Access and Microsoft Entra Private Access, managed in the Entra admin center.
Global VNet peering (global virtual network peering)
VNet peering between different Azure regions; works within one cloud but not between Azure public, Azure Government and Azure operated by 21Vianet.
Grant controls
Conditional Access controls that block or require MFA, a compliant device, an approved client app and others, combined as require all or require one.
Guardrail intervention point
Point where a Foundry guardrail control scans content: user input, tool call (preview, agents only), tool response (preview, agents only) or output.
Guest Attestation extension
VM extension that sends vTPM boot measurements to Azure Attestation for boot integrity monitoring; installing it alone isn't enough, as it needs Secure Boot and vTPM on and outbound access to the AzureAttestation service tag.
Guest user
Entra user with UserType Guest, created by a B2B invitation with a UPN in the #EXT# format; the UPN isn't the sign-in identity.
H
HSM (hardware security module)
Tamper-resistant key hardware, e.g. RSA-HSM keys in Key Vault Premium or Managed HSM; generating a key there authorises no identity.
Hub-spoke topology (hub-spoke)
Network design where a central hub VNet holds shared services such as the firewall and gateway, and peered spoke VNets hold workloads.
Hunting queries
Saved KQL query in Microsoft Sentinel Hunting used to proactively search the workspace for threats.
Hybrid Identity Administrator
Entra role that manages Entra Connect, cloud sync, PTA, PHS and federation settings; the least-privileged cloud role for Entra Connect.
I
IAM (identity and access management)
Portal Access control (IAM) blade for RBAC role assignments.
ICMP (Internet Control Message Protocol)
Protocol used by ping; an NSG rule for TCP 3389 doesn't block it.
IdentityLogonEvents
Advanced hunting table of authentication events from on-premises AD (Defender for Identity) and Microsoft online services (Defender for Cloud Apps); it records past sign-ins only.
IDPS (intrusion detection and prevention system)
Azure Firewall Premium signature-based detection that alerts on or blocks malicious traffic; works only when a Premium policy is attached.
image data type
Deprecated SQL Server large binary type (replaced by varbinary(max)); Always Encrypted cannot encrypt image columns.
Image pull secret
Kubernetes secret holding registry credentials (e.g. a service principal) used to pull images; unnecessary when the kubelet identity has AcrPull.
Immutable Blob storage
WORM protection for blobs via time-based retention or legal hold.
Immutable vaults
Recovery Services vault setting that stops recovery points being deleted early.
Impossible travel (atypical travel)
ID Protection sign-in risk detection for sign-ins from distant locations in less time than travel allows.
Ingestion-time transformation (DCR transformation)
KQL query in a data collection rule that filters or reshapes each record at ingestion before it's stored; it doesn't choose which Windows events the agent collects (XPath does).
Insider Risk Management (Microsoft Purview Insider Risk Management)
Purview solution that uses activity indicators to score and alert on risky user behaviour such as data theft or leaks; not where DLP policies are edited.
Integrated vulnerability assessment (Qualys scanner)
Retired Defender for Servers extension (powered by Qualys) that scanned Windows and Linux Azure VMs and Arc machines but not scale set instances; replaced by Defender Vulnerability Management.
Internet (service tag)
Service tag for public IP space outside the VNet; a deny from Internet doesn't block intra-VNet traffic.
Intune (Microsoft Endpoint Manager)
Microsoft Intune (formerly Microsoft Endpoint Manager): device management whose compliance policies back the Conditional Access compliant-device grant.
IP network rule
Storage firewall rule (IpRules) admitting public IPv4 addresses or CIDR ranges; it can't match private addresses, and it no longer applies to requests from the same Azure region.
IPAM (Virtual Network Manager) (IP address management)
Azure Virtual Network Manager feature that creates IP address pools and assigns non-overlapping CIDRs to VNets; it plans addresses, it does not filter or route.
IPsec/IKE (Internet Protocol Security / Internet Key Exchange)
Protocol suite that encrypts and negotiates S2S and VNet-to-VNet VPN tunnels.
ITSM (IT service management)
Practice and tools (such as ServiceNow or SCSM) for incidents and work items; Azure Monitor reaches them through an ITSM action or Secure Webhook in an action group.
J
JIT (just-in-time)
Time-limited access, e.g. JIT VM access opening ports 3389/22, or PIM role activation.
Just-in-time VM access (JIT VM access)
Defender for Servers feature that blocks management ports with NSG or Azure Firewall deny rules and adds a temporary allow rule for the requesting IP (default maximum request time 3 hours); a VM with no NSG or firewall shows as Unsupported.
JWT (JSON Web Token)
Signed token format of Microsoft identity platform access tokens presented to REST APIs; SMB to Azure Files uses Kerberos tickets instead.
K
Kerberos
Ticket-based Windows authentication used by Entra Domain Services, Application Proxy KCD and Azure Files.
Key rotation policy (rotation policy)
Key Vault key setting that rotates a key automatically at a fixed interval after creation or before expiry and sets notification time; available for keys only, not secrets.
Key Vault access policies
The legacy Key Vault permission model; the Azure RBAC permission model is the current one.
Key Vault access policy
Legacy Key Vault permission entry granting one principal (user, group, app or managed identity) key, secret or certificate operations; an Always Encrypted CMK identity needs get, unwrapKey, wrapKey, verify and sign.
Key Vault Administrator
Key Vault RBAC role for all data-plane operations on keys, secrets and certificates at its scope; assigned on a single key it grants nothing on the rest of the vault.
Key Vault backup and restore
Key Vault backup of a key, secret or certificate as an encrypted blob restorable only into a vault in the same subscription and Azure geography.
Key Vault Contributor
Azure built-in role that manages vaults, including firewall and access policies, but can't read keys, secrets or certificates or assign roles.
Key Vault Crypto Officer
Key Vault RBAC role that performs any action on keys (keys/*) except managing permissions; broader than needed for get/list/wrap/unwrap.
Key Vault Crypto Service Encryption User
Built-in role that reads key metadata and performs wrap and unwrap, the least privilege for a storage account or SQL server identity using a customer-managed key.
Key Vault Crypto User
Key Vault RBAC role that reads key metadata and performs cryptographic operations (encrypt, decrypt, sign, verify, wrap, unwrap).
Key Vault network settings (Key Vault firewall)
Key Vault network setting that limits data-plane access to allowed VNet subnets (service endpoints) and public IP ranges, with an optional trusted-services bypass; private IPs can't be added as IP rules.
Key Vault Reader
Key Vault RBAC role that reads vault and object metadata only; no secret values and no cryptographic operations such as wrap/unwrap.
Key Vault references
@Microsoft.KeyVault(...) app settings that App Service resolves with no code change.
Key Vault Secrets Officer
Key Vault RBAC role that performs any action on secrets except managing permissions.
Key Vault Secrets User
Role granting secret Get for the Key Vault RBAC permission model.
Key Vault soft delete
Keeps a deleted Key Vault and its keys, secrets and certificates recoverable for the retention period (7 to 90 days, default 90), during which the name stays reserved; now always on.
Key Vault Standard
Key Vault pricing tier with software-protected RSA and EC keys (FIPS 140 Level 1); HSM-protected keys need Premium, and both tiers support key rotation policies.
Key Vault VM extension
VM extension that polls Key Vault and installs new versions of observed certificates into the Windows certificate store or a Linux path; it doesn't sync keys or secrets.
KQL (Kusto Query Language)
Query language of Log Analytics and Azure Data Explorer, used for log alerts.
KQL job
Scheduled or one-time KQL query over the Microsoft Sentinel data lake (up to 12 years back) that can promote results to the analytics tier.
Kubelet identity (agent pool managed identity)
User-assigned managed identity used by AKS nodes to pull images; this identity, not the control plane identity, needs AcrPull on the registry.
Kubernetes Agentless Operator
Built-in role Defender for Cloud uses for agentless Kubernetes discovery; it grants no registry data-plane access.
Kubernetes cluster should not allow privileged containers
Built-in Azure Policy definition for Kubernetes that, assigned with the Deny effect, makes the API server reject privileged containers.
Kubernetes RBAC (Kubernetes role-based access control)
Kubernetes-native authorization with Roles, ClusterRoles and their bindings; Entra authentication to AKS grants nothing until a binding gives users or groups permissions.
L
Leaked credentials
ID Protection user risk detection for valid credentials found publicly or on the dark web; always High risk.
Ledger
Azure SQL feature that makes table history tamper-evident with cryptographic digests; it doesn't mask or encrypt data.
Legal hold
Immutability policy that keeps blobs in a WORM state until explicitly cleared; a container can hold one legal hold and one time-based retention policy together.
Linux log forwarder
Dedicated Linux machine running rsyslog or syslog-ng and AMA that receives syslog and CEF from devices on port 514 and sends them to the Sentinel workspace.
listKeys action (Microsoft.Storage/storageAccounts/listKeys/action)
Control-plane action that returns the storage account keys, so a holder gets full Shared Key data access even without any DataActions.
Log alert
Azure Monitor alert on a KQL query in Log Analytics; cannot run on logs in storage or Event Hubs.
Log Analytics agent (MMA)
Legacy agent retired August 2024; replaced by AMA with DCRs.
Log Analytics data export
Continuous export of workspace table data to a storage account or Event Hubs; exported data isn't queryable from Sentinel without extra tooling.
Log Analytics workspace
Store for logs queried with KQL; used by Sentinel, VM insights and workspace-based Application Insights.
Logic Apps
Low-code workflows with triggers and connectors, e.g. approval emails; cannot run custom C#.
Logic Apps authorization policy (Microsoft Entra ID OAuth for Logic Apps)
Logic app setting that validates OAuth tokens on request-based triggers against issuer and claims; enabling it doesn't disable SAS, so turn on Disable SAS authentication (Consumption only) to make OAuth the only method.
Logic Apps Consumption (Consumption logic app)
Multitenant, pay-per-execution logic app type with one workflow per resource; supports Entra OAuth authorization policies on the Request trigger and the Disable SAS option.
Logical server (Azure SQL server)
Azure SQL Database server resource holding logins, the Entra admin, firewall rules, auditing and TDE settings for its databases; not a SQL Server instance.
M
Machine Configuration assignment types
Machine Configuration modes: Audit reports only, ApplyAndMonitor applies once then only reports drift, and ApplyAndAutoCorrect applies and fixes drift at the next evaluation.
Machine secrets scanning
Agentless Defender for Cloud scan of VM disk snapshots for plaintext secrets such as connection strings, tokens and SSH private keys; needs Defender CSPM or Defender for Servers Plan 2.
Mail.Read
Microsoft Graph permission to read mail; not classed as low impact, so under a low-impact consent policy users need admin approval for it.
Managed Application Contributor
Azure role that creates managed application resources; an Azure RBAC role with no directory permissions.
Managed Application Operator
Azure role that can read and perform actions on managed application resources; it can't manage role assignments.
Managed identity
Entra identity for Azure resources with no stored secret; system-assigned or user-assigned.
Managed Identity Contributor
Azure role that creates, reads, updates and deletes user-assigned managed identities; scope it to a resource group for least privilege.
Managed Identity Operator
Azure role that reads and assigns existing user-assigned managed identities but can't create or delete them.
Management groups
Containers above subscriptions for policy and RBAC inheritance; they never span tenants.
Management plane (control plane)
Operations on the Key Vault resource itself (properties, firewall, access policies) authorised by Azure RBAC; it grants no access to key, secret or certificate values.
Mesh topology (Virtual Network Manager)
Connectivity configuration in which every VNet in the network group connects bidirectionally to every other through a connected group; regional by default, global mesh optional.
MFA (multifactor authentication)
A second sign-in factor, required through Conditional Access grants.
Microsoft 365 app connector
Defender for Cloud Apps API connector that ingests Microsoft 365 activity; for Copilot Studio agents, blocking works without it but no alerts or incidents appear in the Defender portal.
Microsoft 365 Copilot
AI assistant in Microsoft 365 apps grounded in organizational data through Microsoft Graph; it honours existing permissions, so overshared SharePoint content surfaces in its answers.
Microsoft 365 groups
Microsoft 365 collaboration groups with a shared mailbox, calendar and files; they aren't alert constructs, so alerts email people through action group receivers.
Microsoft Agent 365
Per-user licence and control plane (included in Microsoft 365 E7, add-on to E5, A5 or Business Premium) needed to extend Entra security such as Conditional Access to agents; its registry in the Microsoft 365 admin center holds the full agent inventory.
Microsoft Authenticator
Mobile app providing push notifications (with number matching), one-time codes and passwordless phone sign-in.
Microsoft Configuration Manager (Configuration Manager)
On-premises Microsoft endpoint management product; its client does not onboard servers to Defender for Cloud.
Microsoft Defender Antivirus
Built-in Windows antimalware that works with Defender for Endpoint; it can run in active or passive mode.
Microsoft Defender External Attack Surface Management (Defender EASM)
Service that discovers an organisation's internet-facing assets (domains, hosts, IPs, ASNs, certificates) and flags their vulnerabilities, unlike Defender for Cloud, which assesses resources you connect.
Microsoft Defender for AI Services (threat protection for AI workloads)
Defender for Cloud workload plan that raises real-time alerts on attacks against generative AI apps using Prompt Shields and threat intelligence; turning off prompt evidence only masks prompts in alerts, and detection continues.
Microsoft Defender for APIs (Defender for APIs)
Defender plan that protects APIs published through Azure API Management only.
Microsoft Defender for App Service (Defender for App Service)
Defender plan that detects attacks on App Service apps, such as connections from anomalous IP addresses.
Microsoft Defender for Cloud (formerly Azure Security Center)
Cloud security posture and workload protection service (free foundational CSPM plus paid Defender plans) with Secure Score, recommendations and a regulatory compliance dashboard that reports but blocks nothing.
Microsoft Defender for Cloud Apps (Microsoft Cloud App Security)
Microsoft CASB for SaaS app discovery, session control and data protection; integrating it with Defender for Cloud unlocks no Defender for Cloud features.
Microsoft Defender for Cloud Servers Scanner Resource Provider
First-party app (ID 0c7668b5-3260-4ad0-9f53-34ed54fa19b2) that agentless scanning uses; for CMK-encrypted disks grant it Get, Wrap Key and Unwrap Key or Key Vault Crypto Service Encryption User.
Microsoft Defender for Containers (Defender for Containers)
Defender plan protecting Kubernetes clusters and container images across AKS/ACR, EKS/ECR and GKE/Artifact Registry, including registry image vulnerability scanning.
Microsoft Defender for Databases (Defender for Databases)
Defender for Cloud plan grouping threat protection for Azure SQL, SQL Server on machines, open-source relational databases and Cosmos DB; it doesn't give VM OS malware protection.
Microsoft Defender for DNS (Defender for DNS)
Detection of DNS tunnelling, exfiltration, C2 or phishing domains and malicious resolvers, now delivered as part of Defender for Servers Plan 2.
Microsoft Defender for Endpoint (MDE, Defender ATP)
Microsoft endpoint detection and response and antivirus platform, integrated with Defender for Servers; on its own it doesn't onboard servers to Defender for Cloud.
Microsoft Defender for Key Vault (Defender for Key Vault)
Defender plan that alerts on unusual or suspicious access to key vaults.
Microsoft Defender for open-source relational databases (Defender for open-source relational databases)
Defender plan detecting threats such as brute-force attacks on Azure Database for PostgreSQL and MySQL flexible servers (and on Amazon RDS engines, including MariaDB, in connected AWS accounts); historically it also covered Azure Database for MariaDB, which retired on 19 September 2025.
Microsoft Defender for Resource Manager (Defender for Resource Manager)
Defender plan that detects suspicious Azure Resource Manager (control-plane) operations.
Microsoft Defender for Servers (Defender for Servers)
Defender plan for Azure VMs and Arc-enabled servers; Plan 1 (subscription or per-resource) gives Defender for Endpoint integration, Plan 2 (subscription or workspace) adds FIM, agentless scanning and Defender for DNS alerts.
Microsoft Defender for SQL
Defender for Cloud plan bundling Advanced Threat Protection (SQL injection, brute force, anomalous access alerts) and SQL vulnerability assessment; it detects, but doesn't encrypt or mask.
Microsoft Defender for Storage (Defender for Storage)
Defender for Cloud plan that detects threats and scans for malware in Blob (including ADLS Gen2) and Azure Files, not Table or Queue storage; enabled per subscription or per account, not per resource group.
Microsoft Defender portal
Unified security portal (security.microsoft.com) for Defender XDR, Defender for Cloud Apps, Microsoft Sentinel and other Microsoft security products.
Microsoft Defender Vulnerability Management (MDVM)
Microsoft vulnerability scanning engine now used by Defender for Servers and Defender for Containers, covering VMs (including scale sets) and Windows images.
Microsoft Defender Vulnerability Management add-on (MDVM add-on)
Licence that adds premium MDVM capabilities (security baselines, blocking vulnerable apps, certificate and firmware assessments) to client devices; servers on Defender for Servers Plan 2 already include them, so don't buy it for those.
Microsoft Defender XDR (Microsoft 365 Defender)
Unified pre- and post-breach suite correlating signals from Defender for Endpoint, Office 365, Identity, Cloud Apps and more into incidents, with advanced hunting and automatic attack disruption.
Microsoft Entra admin
Single Entra user, security group, service principal or managed identity set on a logical server or managed instance that can sign in to every database and create other Entra users.
Microsoft Entra Agent ID
Identity and security framework that gives AI agents their own Entra identities (agent identities created from blueprints) so Conditional Access, ID Protection and governance apply to them as to users.
Microsoft Entra application proxy (Azure AD Application Proxy)
Publishes on-premises web apps via an outbound-only connector, with no VPN or inbound ports.
Microsoft Entra authentication for Azure SQL
Sign-in to Azure SQL with Entra identities (users, groups, managed identities) instead of SQL logins, enabling MFA and Conditional Access.
Microsoft Entra B2B (Azure AD B2B)
Guest accounts that authenticate against their home tenant.
Microsoft Entra Connect (Azure AD Connect)
Syncs on-premises AD identities to Entra ID.
Microsoft Entra Connect provisioning agent
On-premises agent through which cloud provisioning apps write users to AD.
Microsoft Entra custom roles
Entra directory roles built from custom-enabled permissions, assignable at tenant or single-object (e.g. app registration) scope, never Azure resource scope; they can clone a custom role but not a built-in role.
Microsoft Entra Domain Services (Azure AD DS)
Managed Azure domain offering LDAP, Kerberos and NTLM, populated from Entra ID with no on-premises connectivity.
Microsoft Entra External ID
Microsoft's external identity platform covering B2B collaboration and customer (CIAM) tenants; the successor to Azure AD B2C for new customers.
Microsoft Entra ID (Azure AD)
Microsoft's cloud identity service and tenant for Azure and Microsoft 365.
Microsoft Entra ID authentication (P2S) (Azure AD authentication)
P2S authentication type that signs users in with Entra ID (enabling Conditional Access and MFA); requires the OpenVPN tunnel type and the Azure VPN Client.
Microsoft Entra Kerberos (Azure AD Kerberos)
Identity source for Azure Files in which Entra ID issues Kerberos tickets for SMB, for hybrid identities (and, in preview, cloud-only identities); only one identity source per storage account.
Microsoft Entra Private Access
Global Secure Access service giving users VPN-less, Conditional Access-controlled access to private apps; it doesn't route VNet-to-storage traffic.
Microsoft Entra roles (directory roles)
Tenant-level admin roles such as User Administrator that manage Entra objects and grant no Azure resource rights; Azure RBAC is separate.
Microsoft Entra tenant
Dedicated Entra ID directory instance with an initial .onmicrosoft.com domain chosen at creation; each Azure subscription trusts exactly one.
Microsoft Entra Workload ID (workload identity)
AKS feature that federates a Kubernetes service account with an Entra managed identity or app so pods get Entra tokens; it authenticates but doesn't itself bring Key Vault content into pods.
Microsoft Entra-only authentication
Server setting that disables SQL authentication so only Entra identities can connect.
Microsoft Foundry (Azure AI Foundry)
Azure platform for building, evaluating and running AI agents and models under one resource, with guardrails, evaluations and AI red teaming.
Microsoft Graph
API for Microsoft 365 and Entra data, authorised with delegated or application permissions, not Azure RBAC.
Microsoft Purview (Azure Purview)
Data governance with a metadata-only Data Map of schema, lineage and classification; not log collection.
Microsoft Purview Audit (Purview Audit)
Unified audit log search (Audit Standard, 180-day retention; Audit Premium, longer retention and intelligent insights) for user and admin activity across Microsoft services; correlation is manual.
Microsoft Purview Audit (Standard)
Default unified audit log tier that keeps records for 180 days (90 days for logs before 17 October 2023) with no retention policies or intelligent insights.
Microsoft Purview Data Loss Prevention (DLP)
Purview policies that detect sensitive information types or labels in content across locations (including the Microsoft 365 Copilot location) and audit, warn or block, with simulation mode before enforcement; they don't report sharing scope.
Microsoft Purview DSPM for AI (Data Security Posture Management for AI)
Purview solution giving AI observability, data risk assessments and one-click policies for data in Copilot, agent and other AI app interactions; it doesn't map lateral movement or attack paths.
Microsoft Purview Information Protection (Azure Information Protection (AIP))
Sensitivity labelling and encryption for documents and email; it grants no access to Azure Key Vault.
Microsoft Security Copilot (Security Copilot)
Generative AI security assistant with a standalone portal and embedded experiences in Defender, Entra, Intune and Purview, extended by plugins and agents.
Microsoft Security DevOps (MSDO)
Azure DevOps task (MicrosoftSecurityDevOps@1) or GitHub action that runs security scanners such as Template Analyzer, Checkov and Terrascan in the pipeline; set categories: 'IaC' to run only the IaC scanners.
Microsoft Security Exposure Management (MSEM)
Defender portal posture solution that unifies assets across endpoints, identities, cloud and external attack surface into the enterprise exposure graph, with critical assets, attack paths, choke points and blast radius.
Microsoft Sentinel content hub
Central Sentinel page to discover, install and update out-of-the-box solutions and standalone content; installing only makes templates available, so each item must still be activated.
Microsoft Sentinel Contributor
Azure built-in role with Responder rights plus creating and editing analytics rules, workbooks and content hub solutions; more than incident handling needs.
Microsoft Sentinel incident (incident)
Sentinel case record that groups related alerts, entities and evidence for investigation, with an owner, status and severity.
Microsoft Sentinel Reader
Azure built-in role to view Sentinel data, incidents and workbooks without changing incidents; least privilege for reading incidents, including through Security Copilot's Sentinel plugin.
Microsoft Sentinel Responder
Azure built-in role with Reader rights plus incident management (assign owner, change status and severity); a guest also needs Directory Reader to assign incidents.
Microsoft Sentinel solution
Azure Marketplace-powered package of Sentinel content (connectors, analytics rules, workbooks, playbooks) for a product or scenario; you must install the whole solution and update it yourself, unlike standalone content.
Microsoft-hosted agents
Azure Pipelines agents that Microsoft runs on a fresh VM per job outside your network, so pipelines deploying to an AKS private cluster need extra connectivity or self-hosted agents.
microsoft-user-default-low
Built-in app consent policy allowing user consent only for permissions classified as low impact, for apps from verified publishers or registered in the tenant.
Microsoft.Authorization
Resource provider namespace for role assignments, role definitions, resource locks and policy; roleAssignments/write is held only by Owner, User Access Administrator and similar roles.
Microsoft.AzureActiveDirectory service endpoint
Legacy service endpoint tag used only for Data Lake Storage Gen1 virtual network integration; Microsoft Entra ID doesn't support service endpoints natively.
Microsoft.Compute
Resource provider namespace for VMs, managed disks (Microsoft.Compute/disks) and VM sign-in data actions (virtualMachines/login/action).
Microsoft.ContainerInstance
Resource provider namespace for Azure Container Instances; Microsoft.Compute rights don't cover it.
Microsoft.KeyVault
Resource provider namespace for Key Vault (e.g. Microsoft.KeyVault/vaults/write for vault settings) and the service endpoint name for Key Vault.
Microsoft.Network
Azure resource provider namespace for networking resources such as VNets, NSGs and Network Watcher; its actions are what Network Contributor grants.
Microsoft.Resources
Resource provider namespace for subscriptions, resource groups, deployments and tags (Microsoft.Resources/tags/*).
Microsoft.Security
Resource provider namespace for Microsoft Defender for Cloud settings, pricing and assessments; it holds no role assignments or policies.
Microsoft.Sql service endpoint
Service endpoint routing subnet traffic to Azure SQL over the backbone, bypassing forced tunnelling.
Microsoft.Storage
Resource provider namespace for Azure Storage (storage accounts, which hold unmanaged disks) and the service endpoint name for Azure Storage.
Microsoft.Storage.Global (cross-region service endpoint)
Azure Storage service endpoint reaching storage accounts in any region, unlike the regional Microsoft.Storage; a subnet can hold only one of the two.
Microsoft.Web
Resource provider namespace for App Service and Azure Functions apps; Microsoft.Compute rights don't cover it.
minimumTlsVersion (Minimum TLS version)
Storage account property (TLS1_0, TLS1_1, TLS1_2) that rejects requests using an older TLS version with 400; it doesn't filter networks or block HTTP.
Modify effect
Azure Policy effect that adds, replaces or removes tags and properties, fixing existing resources through a remediation task under the assignment's managed identity.
Monitor Only (Defender EASM asset state)
Defender EASM state for assets relevant to your attack surface but neither directly controlled nor a technical dependency, such as franchisees or related companies.
MS-PIM
Service principal through which PIM manages Azure resource roles; it needs User Access Administrator on the subscription or management group.
Multi-user authorization (MUA)
Protects critical backup operations by requiring a role on a Resource Guard, ideally in a separate tenant.
My Apps
Entra user portal whose browser extension fills credentials for password-based SSO.
MySQL Flexible Server
Managed MySQL with zone-redundant HA on General Purpose and Business Critical, not Burstable.
N
Network Contributor
Azure built-in role for managing networking resources (Microsoft.Network/*); it lacks the storage, Log Analytics workspace and DCR actions that flow logs and Traffic Analytics need.
Network group
Azure Virtual Network Manager group of VNets or subnets from within the manager's scope, populated statically or dynamically through Azure Policy; out-of-scope VNets never join.
Network manager scope
Management groups and subscriptions an Azure Virtual Network Manager instance can manage; out-of-scope VNets get no configuration, and when overlapping managers conflict the higher scope wins.
Network rule
Azure Firewall rule filtering by IP address, port, protocol, service tag, or FQDN when DNS proxy is enabled; processed after DNAT and before application rules.
Network Watcher effective security rules
Network Watcher view of the merged inbound and outbound rules on one NIC (NIC NSG, subnet NSG and Virtual Network Manager admin rules) on a running VM; it lists rules but doesn't test a flow.
Network Watcher IP flow verify
Network Watcher tool that tests a 5-tuple against a VM NIC's security and admin rules and returns allowed or denied plus the deciding rule; it covers only TCP and UDP and not scale sets, so use NSG diagnostics for ICMP.
Network Watcher next hop
Network Watcher tool that returns the next hop type, IP and route table (a UDR's table or System Route) for a destination; it diagnoses routing, not NSG filtering.
Network Watcher NSG diagnostics
Network Watcher tool that simulates a flow (including ICMP) against VMs, NICs, scale set NICs and Application Gateway v2 and returns allow or deny with rule details; use it where IP flow verify can't reach.
New-AzPolicyAssignment
Az.Resources cmdlet that assigns a policy definition (-PolicyDefinition) at a scope (-Scope, e.g. a resource group's ResourceId); Set-AzPolicyAssignment changes an existing one.
New-AzPolicyDefinition
Az.Resources cmdlet that creates a policy definition (Set-AzPolicyDefinition changes one); it assigns nothing.
New-AzRoleAssignment
Az cmdlet that assigns a role definition to a user, group or service principal at a scope; replaces New-AzureRmRoleAssignment.
New-AzRoleDefinition
Az cmdlet that creates a custom role from a JSON file (-InputFile) or a role object.
NIST SP 800-53
US National Institute of Standards and Technology security-control catalogue (Rev. 5) available as a built-in Defender for Cloud regulatory standard.
Non-applicable observations
Defender EASM table that CVEs or other observations move to when marked non-applicable, removing them from dashboard counts (reversible).
nonComplianceMessages (non-compliance messages)
Policy assignment property holding custom deny/non-compliance text: a default message plus policy-specific messages targeted by policyDefinitionReferenceId in an initiative.
Not allowed resource types
Built-in Azure Policy (Deny) that blocks the listed resource types however they're deployed, ARM templates included.
NotActions
Role-definition list subtracted from Actions (e.g. Microsoft.Authorization/* for the Contributor pattern); not a deny, so another role can still grant it.
NTLM (NT LAN Manager)
Legacy Windows challenge-response authentication; Azure Files key-based SMB mounts use NTLMv2, so allowing only Kerberos blocks them.
Number matching
Authenticator push feature that makes the user type the number shown at sign-in; now enforced for all push notifications.
O
OATH token (OATH TOTP)
Time-based one-time passcode from a hardware token or an authenticator app (software token); a second factor used with a password, not a passwordless method.
OAuth 2.0
Industry-standard authorization protocol the Microsoft identity platform uses to issue access tokens to apps; a client ID and client secret obtain a token in the client credentials flow.
On-behalf-of authentication (OBO)
OAuth flow Security Copilot uses so plugins access data only with the signed-in user's own permissions, so users also need data roles such as Microsoft Sentinel Reader.
On-premises data gateway
Bridge for Power BI, Logic Apps and Power Apps to on-premises data; not for Data Factory.
OpenVPN (OpenVPN (SSL))
TLS-based P2S tunnel type over TCP 443 for Windows, macOS, Linux, iOS and Android; the only tunnel type that supports Microsoft Entra ID authentication.
Optional claims
Extra token claims (e.g. ipaddr) added on the app registration's Token configuration blade or optionalClaims in the manifest.
OWASP (Open Web Application Security Project)
Body behind the OWASP Top 10 critical web application risks, used by WAF rules and a Defender EASM dashboard.
OWASP Top 10 dashboard
Defender EASM dashboard listing assets exposed to OWASP's most critical web application risks such as broken access control and injection.
P
Paired region
Region matched with another in the same geography for sequenced updates and prioritised recovery; the usual DR target, but pairing gives no automatic failover.
Parent firewall policy (base policy)
Azure Firewall policy that child policies inherit; its network and application rule collections always take precedence over the child policy, it can be associated with firewalls in any region, and its NAT rules are not inherited.
Partner-built agent
Security Copilot agent from a partner via the Security Store; if it needs Microsoft product data permissions, a Global Administrator must approve them before an owner or contributor can finish setup.
Passwordless phone sign-in
Authenticator mode, enabled in the Authentication methods policy for a target group, that signs users in without a password.
Per-user MFA (legacy per-user multifactor authentication)
Legacy per-user MFA states (Disabled, Enabled, Enforced) managed outside Conditional Access; Conditional Access requires MFA independently of it.
pgAudit
PostgreSQL extension that writes audit logs for Azure Database for PostgreSQL; it would need custom alerting, unlike Defender plan alerts.
Phishing Triage Agent
Security Copilot agent in the Defender portal that classifies user-reported phishing alerts; managing its settings (set up, pause, remove) needs Security Administrator.
PIM activation
User request to turn an eligible PIM assignment into an active role for a limited duration; a requester can't approve their own request.
PIM alerts
PIM security alerts such as potential stale accounts in a privileged role (default 90 days without password change) or roles assigned outside PIM.
PIM role settings
Per-role PIM settings for activation maximum duration, MFA, justification, ticket, approval, assignment duration and notifications.
PKI (public key infrastructure)
Certificate authorities and processes that issue certificates; required for certificate-based authentication.
Playbook
Azure Logic Apps workflow run from Microsoft Sentinel by an automation rule or manually to perform response actions such as assigning, ticketing or blocking IPs; running playbooks directly from analytics rules is retired.
Point-to-site VPN (P2S)
VPN from individual clients to an Azure virtual network gateway; used by gateway-required VNet integration.
Policy assignment
Applies a policy definition or initiative to a scope (management group, subscription, resource group) with parameters, exclusions, enforcement mode and non-compliance messages; triggers evaluation.
Policy definition
JSON rule (if/then with an effect, parameters and metadata) describing a compliance condition; it does nothing until assigned, and its category is metadata only.
Policy exclusions (Policy)
Excluded scopes (notScopes) that remove part of a policy assignment's scope from evaluation; they never add scope.
Private cluster (AKS private cluster)
AKS cluster whose API server has only a private IP; it needs cluster rebuild plus private DNS and connectivity, and Microsoft-hosted DevOps agents can't reach it.
Private DNS zone
Azure DNS zone linked to a VNet holding private A records; queryable only via 168.63.129.16, so on-premises needs a forwarder or DNS Private Resolver.
Private endpoint
Private IP for a service in your VNet, reachable from peered VNets and from on-premises over ExpressRoute or VPN; public access can then be disabled.
Private endpoint connection
Approval record on the target resource for a private endpoint (Pending, Approved, Rejected or Disconnected); consumers without permission on the resource, such as another tenant, stay Pending until the owner approves.
Private endpoint DNS zone (privatelink zone)
Service-specific private DNS zone a private endpoint registers in, such as privatelink.blob.core.windows.net, privatelink.database.windows.net, privatelink.documents.azure.com or privatelink.azurewebsites.net.
Private endpoint network policies (PrivateEndpointNetworkPolicies)
Subnet setting (Disabled by default, NetworkSecurityGroupEnabled, RouteTableEnabled or Enabled) that must be turned on before NSGs or UDRs apply to private endpoint traffic; subnet delegation doesn't do this.
Private Link service
Your own service published behind a Standard Load Balancer frontend IP so consumers reach it through private endpoints; not used to expose PaaS services such as Azure SQL Database.
privatelink.vaultcore.azure.net
Private DNS zone that must exist and be linked to the VNet so a vault name resolves to its private endpoint IP; without the link the public IP is returned.
Privileged Authentication Administrator
Entra role that manages authentication methods (e.g. a TAP) for any user, including Global Administrators.
Privileged Identity Management (PIM)
Entra ID P2 just-in-time, time-bound privileged role activation with approval; not for reviewing guest access.
Privileged Role Administrator
Entra role that manages Entra role assignments, PIM, administrative units and role-assignable groups, and can grant admin consent to any permission, including Graph application permissions.
Protocol settings (Azure Files) (SMB security settings)
Azure Files setting that restricts allowed SMB versions (e.g. SMB 3.1.1 only), authentication mechanisms (NTLMv2, Kerberos), channel encryption and Kerberos ticket encryption.
Public access level (anonymous read access)
Container setting allowing unauthenticated reads of blobs; it controls anonymous reads only and doesn't stop authorised writers.
Public network access
Storage account setting (Enabled from all networks, from selected networks, or Disabled) that governs only the public endpoint; private endpoints still work when it is disabled.
Purge protection
Key Vault setting that blocks permanent deletion of the vault and its objects until the soft-delete retention period ends; requires soft delete and can't be disabled once on.
Q
Queue Storage
Simple storage queues with messages up to 64 KB and no ordering guarantee; AzCopy cannot manage them.
R
Randomized encryption
Always Encrypted type producing different ciphertext each time; more secure but prevents searching, grouping or indexing on the column.
rate-limit-by-key
APIM policy that throttles calls per key (e.g. IP or subscription), returning 429; it doesn't authenticate callers.
RBAC (role-based access control)
Azure role assignments governing who can manage resources, inherited down scopes; not where or what size resources are.
RC4-HMAC
Legacy Kerberos ticket encryption type that Azure Files SMB security settings can allow or disallow alongside AES-256.
RDP (Remote Desktop Protocol)
Windows remote-session protocol on port 3389; Bastion carries it over TLS on 443.
Reader
Built-in management-plane role that views resources, letting a user see a storage account in the portal, but grants no data access or keys.
readFileBackupSemantics (Microsoft.Storage/storageAccounts/fileServices/readFileBackupSemantics/action)
Azure Files data action that OAuth-over-REST callers need (with writeFileBackupSemantics for writes); only the Storage File Data Privileged roles (and SMB Admin roles) include it.
ReadOnly (ReadOnly lock)
Resource lock level that blocks changes and deletion, and blocks moves when on the source or target resource group or subscription.
Recovery point (restore point)
Copy of backed-up data at a point in time; it exists only for backups that have actually run and counts once even when it matches several retention tiers.
Recovery Services vault
Store for Azure Backup and Site Recovery data, supporting soft delete, immutability and MUA; not a cheap archive for existing files.
Redirect URI (reply URL)
Location where Entra ID sends tokens after sign-in; supplied by the developer on the app registration's Authentication blade.
reference()
ARM template function that returns a resource's runtime state and creates an implicit dependency; it doesn't return an ID for dependsOn.
Regional service tag
Service tag narrowed to one region by a suffix, e.g. Sql.EastUS or Storage.WestUS; the unsuffixed tag covers every region in the cloud.
Regional VNet integration
Outbound App Service access into a VNet (Basic tier up) via a subnet delegated to Microsoft.Web/serverFarms; inbound access needs a private endpoint.
Regulatory compliance standard
Built-in compliance framework (e.g. CIS, NIST SP 800-53, ISO 27001, AWS Foundational Security Best Practices) added in Defender for Cloud as a policy initiative assignment, which needs Owner or Resource Policy Contributor.
Remediation task
Applies a DeployIfNotExists or Modify assignment to existing non-compliant resources, running as the assignment's managed identity.
Report-only (report-only mode)
Conditional Access policy state that evaluates and logs results without enforcing them.
Request (HTTP) trigger
Logic Apps trigger started by an incoming HTTP call or webhook.
Require app protection policy
Conditional Access grant control requiring an Intune app protection policy on the client app; with Require one of the selected controls it can satisfy a policy without MFA.
Require approved client app
Conditional Access grant control allowing access only from approved (modern-auth, Intune-aware) client apps; often combined with MFA using Require one of the selected controls.
Require device to be marked as compliant
Conditional Access grant control needing an Intune-compliant device; it's a grant control, not a condition (device platform is the condition).
Requires Investigation (Defender EASM asset state)
Defender EASM state set from Microsoft's confidence scores to flag an asset for manual review of how to categorise it; start reviews here.
Resource Graph
KQL query service for exploring and inventorying resources across subscriptions; it can't group, assign or deploy policy.
Resource group (RG)
Container for resources whose location stores only metadata; its location can't change and it can't nest.
Resource Guard
Separate resource holding the permissions MUA requires for critical Recovery Services vault operations; best placed in a separate tenant.
Resource locks
CanNotDelete or ReadOnly locks on management-plane operations; they do not restrict regions or sizes or protect blob data.
Resource Policy Contributor
Azure role that creates and assigns policy and initiative definitions, the least-privilege role for adding a Defender for Cloud standard; Contributor lacks policyDefinitions/write.
Resource provider
Service that supplies Azure resource types under a namespace such as Microsoft.Compute or Microsoft.Network; role actions are written as namespace/resourceType/operation.
Resource-specific consent (RSC)
Teams and Microsoft Graph authorization model that grants an app permissions on one team, chat or user (e.g. post to that team's channels) instead of tenant-wide.
Resource-specific tables
Diagnostic-setting destination mode that writes each log category to its own table (for example AZFWNetworkRule for Azure Firewall) instead of the shared AzureDiagnostics table.
Restrict access to Microsoft Entra administration portal
User setting that only hides common admin center pages from non-admins; it's not a security control and doesn't block PowerShell, Graph or other tools.
Risk prioritization (Defender for Cloud) (risk level)
Defender CSPM engine that gives each recommendation a Critical/High/Medium/Low risk level from internet exposure, data sensitivity, lateral movement and attack paths; without Defender CSPM the risk shows as Not evaluated.
Robocopy
Windows SMB file-copy tool used to migrate data to a mounted Azure file share; it can't use a SAS and can't reach blob containers.
Role Based Access Control Administrator
Azure role that can create and delete role assignments (roleAssignments/write) without managing resources; like Owner and User Access Administrator, it can assign roles.
Role definition Actions
Role-definition list of allowed control-plane operations (e.g. Microsoft.Storage/storageAccounts/read); wildcards such as * are allowed.
Role-assignable group
Entra group created with isAssignableToRole = true (Entra ID P1) that can hold directory roles; assigned membership only, no nesting, and the flag can't be added later.
roleDefinitionIds
Array in a DeployIfNotExists or Modify definition's details listing the full role IDs that the assignment's managed identity needs for remediation; the portal grants them automatically, other methods don't.
Route table
Resource holding UDRs, associated with subnets; it affects traffic leaving those subnets (associate it with GatewaySubnet to steer inbound VPN traffic).
Routing configuration (Virtual Network Manager)
Azure Virtual Network Manager configuration whose rule collections create UDRs (next hops) for a network group; it steers traffic but filters no ports.
RSA (Rivest–Shamir–Adleman)
Asymmetric algorithm; storage customer-managed keys can be RSA or RSA-HSM at 2048, 3072 or 4096 bits, but TDE protectors only 2048 or 3072.
Rule collection group
Container in a firewall policy that groups rule collections; priority orders groups and same-type collections, but DNAT, then network, then application rules always run in that order.
Runbook
Azure Automation script (PowerShell, Python or graphical) run as a job in an Azure sandbox or on a Hybrid Runbook Worker, for example on a schedule to resize a VM.
S
S2S VPN (site-to-site VPN)
IPsec/IKE tunnel over the internet between an on-premises VPN device and a VNet's VPN gateway, needing a local network gateway and a connection; cheaper than ExpressRoute.
SAML (Security Assertion Markup Language)
Federation protocol for SSO to apps added as non-gallery enterprise applications.
SAML token encryption
Encrypts SAML assertions with the app's public certificate; configured on the enterprise application, not the app registration.
SCU (Security Compute Unit)
Unit of Security Copilot compute capacity, provisioned (billed hourly) or overage, attached per workspace and not shareable between workspaces.
Seamless SSO (Microsoft Entra seamless single sign-on)
Signs domain-joined devices on the corporate network in silently with PHS or PTA (not AD FS); needs autologon.microsoftazuread-sso.com in the Local intranet zone and no inbound ports.
Search job
Long-running single-table KQL search over analytics, data lake or archived data, returning up to 100 million records to a results table.
Secret attributes (nbf / exp / enabled)
Key Vault secret properties Enabled, NotBefore (nbf, activation) and Expires (exp); a disabled secret can't be read, while nbf/exp are advisory for secrets but treated as limits on the exam.
SecretNearExpiry (Microsoft.KeyVault.SecretNearExpiry)
Event Grid event Key Vault raises 30 days before a secret expires; handle it with a function or Logic App to rotate secrets, which have no rotation policy.
Secure Inputs and Secure Outputs
Logic Apps action settings that hide inputs or outputs in run history; they don't restrict who can call the trigger.
Secure transfer required (supportsHttpsTrafficOnly)
Storage account setting that rejects unencrypted HTTP (and unencrypted SMB) requests; it forces HTTPS only and does not restrict networks.
Secured virtual hub
Virtual WAN hub with Azure Firewall deployed in it and managed by Azure Firewall Manager.
Security Admin
Azure role for Microsoft Defender for Cloud policy, alerts and recommendations; it can't assign roles or create general policy definitions.
Security admin configuration
Azure Virtual Network Manager configuration holding one or more rule collections of security admin rules; only one can be deployed per region, so add rule collections instead of more configurations.
Security admin rule
Azure Virtual Network Manager rule evaluated before any NSG rule, with actions Allow (continue to NSGs), Always allow (skip NSGs) or Deny (block regardless of NSGs).
Security Administrator
Entra role for security settings and reports; it can't change SSPR policy or control guest invitations.
Security Copilot agent
AI agent that runs Security Copilot workflows under an assigned identity and trigger, set up by a Copilot owner or contributor.
Security Copilot Contributor (Copilot contributor)
Security Copilot role (not an Entra role) for creating sessions and setting up agents, with no access to security data by itself.
Security Copilot custom plugin settings
Owner settings for who can add and manage custom plugins for themselves (user scope) and for everyone in the workspace or organisation (tenant scope, including embedded experiences).
Security Copilot embedded experience
Security Copilot inside another product such as the Microsoft Defender portal; unlike the standalone portal it can't pick a workspace and uses the tenant's designated workspace.
Security Copilot Owner (Copilot owner)
Security Copilot role (not an Entra role) that manages Copilot settings, plugins, roles and capacity but grants no security-data access; inherited by Security Administrator and Global Administrator.
Security Copilot plugin (plugin)
Connector that gives Security Copilot access to a Microsoft, third-party or custom data source; it still needs the user's own access to that source.
Security Copilot standalone experience
The Security Copilot portal at securitycopilot.microsoft.com, where users work in the workspace they select.
Security Copilot workspace
Tenant-bound Security Copilot container that defines where data is stored, which SCU capacity is used and who has owner or contributor access.
Security defaults
Free, tenant-wide baseline that requires MFA registration and blocks legacy authentication; cannot be scoped to a group.
Security Events via Legacy Agent
Retired Microsoft Sentinel connector that collected Windows security events through the Log Analytics agent (MMA); replaced by Windows Security Events via AMA.
Security group
Entra group type for access to resources; members can be users, devices and service principals, with assigned or dynamic membership.
Security Operator
Entra role that manages security alerts and incidents; it can't grant admin consent.
Security policies (Defender for Cloud)
Environment settings page where standards (MCSB, regulatory standards, custom standards) are assigned to a subscription, AWS account or GCP project; only initiatives, not single policy definitions, can be added.
Security Posture dashboard
Defender EASM dashboard covering CVE exposure, domain administration, hosting and networking, open ports and SSL certificate configuration.
Security Reader
Read-only security role (Entra role and Azure built-in role) that grants no Microsoft Sentinel workspace access and no directory lookup for a guest.
Security recommendations (Defender for Cloud)
Defender for Cloud remediation guidance generated when a resource fails a control in an assigned standard (MCSB by default); each addresses a single issue in isolation.
Security rule priority (NSG)
Number from 100 to 4096 that orders NSG rules within one direction; the lowest number is evaluated first and processing stops at the first match, so an allow must have a lower number than the deny it carves out.
Security Store (Microsoft Security Store)
Microsoft marketplace for discovering, buying and deploying Microsoft and partner security agents and solutions for Security Copilot and Sentinel.
SecurityAlert
Log Analytics table holding alerts from Microsoft security products connected to Sentinel, such as Defender for Cloud and Entra ID Protection.
SecurityEvent
Log Analytics table of Windows Security events collected by Sentinel or Defender.
Self-service application access
Enterprise application setting letting users request access from My Apps, adding approved users to a chosen group.
Sensitive information type
Pattern-based classifier (e.g. credit card numbers) that labels and policies use to detect sensitive content; custom types can be created.
Sensitivity labels (Microsoft Purview sensitivity labels)
Microsoft Purview labels that classify and optionally encrypt content across Office apps and services, replacing AIP classic labels.
Server IP firewall rules
Logical server rules allowing public source IP ranges; they don't match private VNet addresses, which need a virtual network rule.
Server-level auditing
Azure SQL auditing policy on the logical server that covers all its databases; database-level auditing adds destinations rather than replacing it.
Server-side encryption (SSE)
Always-on encryption at rest of managed disks by Azure Storage with platform- or customer-managed keys; temp disks and caches aren't covered and a downloaded VHD isn't encrypted.
Service endpoint
Routes a subnet's traffic to a service's public endpoint over the Azure backbone; free, but not usable from on-premises.
Service principal
Local instance of an app registration or managed identity in a tenant, to which users and Azure or directory roles are assigned; app-registration ones use a secret or certificate that must be rotated.
Service SAS
SAS signed with the account key that delegates access to one storage service (for example a container); can reference a stored access policy and stops working when Shared Key is disabled.
Service tag
Microsoft-maintained group of IP prefixes for an Azure service (e.g. Storage, AzureKeyVault, optionally regional) usable as an NSG source or destination.
Session controls
Conditional Access sign-in frequency and app-enforced restrictions; they limit a session but do not require MFA.
Set-AzContext
Az.Accounts cmdlet that sets the subscription (and tenant) later Az cmdlets run against; run it before remediating in another subscription.
Set-AzPolicyAssignment
Az PowerShell cmdlet that modifies an existing policy assignment (display name, identity and so on); New-AzPolicyAssignment creates one.
Set-AzPolicyDefinition
Az PowerShell cmdlet that modifies an existing policy definition; it doesn't assign it.
Set-AzResourceGroup
Az PowerShell cmdlet that only changes a resource group's tags; it can't rename the group or run remediation.
Set-AzureRmStorageAccount
Retired AzureRM cmdlet that modifies storage account settings; it doesn't encrypt VM disks.
Set-AzVMDiskEncryptionExtension
Az PowerShell cmdlet that enables Azure Disk Encryption on a VM, using a key vault in the VM's region and subscription.
set-backend-service
APIM policy that redirects a request to a different back-end URL or backend entity; routing, not authentication.
Set-MpPreference
Defender PowerShell cmdlet that configures Microsoft Defender Antivirus scan, update and exclusion preferences; turning off real-time protection with it isn't a supported way to coexist with third-party antivirus.
Sign-in frequency
Conditional Access session control that forces reauthentication after a set period.
Sign-in risk policy
ID Protection (Entra ID P2) risk-based policy acting on the probability that a sign-in isn't from the account owner, e.g. requiring MFA; it enables no methods.
SMB (Server Message Block)
Windows file-share protocol for Azure Files, using identity-based authentication.
SMS and voice call verification
Phone-based methods that send a one-time code by text or place a call; usable as an MFA second factor (SMS also as frontline sign-in) but not passwordless or phishing-resistant, and not helpdesk-issued like a TAP.
SMTP (Simple Mail Transfer Protocol)
Email transfer protocol on TCP port 25.
SNAT (source network address translation)
Rewriting a flow's source address; Azure Firewall automatically SNATs outbound internet traffic to its public IP (no separate enable step), and a NAT gateway only adds SNAT ports.
Split transformation
Ingestion-time transformation that routes part of a table's data to a different table or tier; it's defined in a DCR (or Sentinel table management), so the DCR is still the component to choose.
SQL Health Check
Legacy on-premises SQL Server assessment offering, not an Azure SQL threat detection tool.
SQL injection
Attack that inserts SQL into application input; Microsoft Defender for SQL alerts on potential SQL injection, while the Application Gateway WAF blocks it at the web tier.
SQL Managed Instance auditing
SQL Server Audit on Azure SQL Managed Instance: one server audit covers every database on the instance, writing .xel files to Blob storage (TO URL) or to Event Hubs/Log Analytics (TO EXTERNAL_MONITOR).
SQL Security Manager
Built-in role managing SQL server and database security policies such as auditing and threat detection; it doesn't grant Key Vault key access.
SQL Server Audit
SQL Server feature that records server and database events to a file or to the Windows Security or Application log, from where an agent can collect them.
SQL Server Authentication (SQL authentication)
Sign-in with a SQL login name and password stored in the server; it can't enforce MFA.
SQL Server Contributor
Built-in role that manages logical servers and databases and can set the Microsoft Entra admin, but can't enable or disable Microsoft Entra-only authentication (SQL Security Manager or Contributor can).
SQL Server enabled by Azure Arc
SQL Server outside Azure connected through Azure Arc; its Microsoft Entra authentication (SQL Server 2022) needs an app registration and certificate in Key Vault, unlike Azure SQL Database.
SQL vulnerability assessment
Defender for SQL scan of databases for misconfigurations, with recurring scans and report recipients configured after the plan is enabled; separate from threat-detection alert types.
SSMS (SQL Server Management Studio)
SQL Server management tool, e.g. for creating a target schema.
Standard general-purpose v2 (StorageV2)
Standard account for all storage services with access tiers and every redundancy option.
Standard V2 (Standard_v2)
Application Gateway tiers: Basic (no URL rewrite, no WAF), Standard_v2 (rewrites, no WAF) and WAF_v2 (adds WAF); a WAF policy can attach only to WAF_v2.
Start-AzPolicyComplianceScan
Az.PolicyInsights cmdlet that triggers an on-demand policy compliance evaluation; it evaluates only and remediates nothing.
Start-AzPolicyRemediation
Az.PolicyInsights cmdlet that creates a remediation task for a DeployIfNotExists or Modify assignment; -ResourceDiscoveryMode ReEvaluateCompliance rescans first.
Storage (service tag)
Service tag for Azure Storage's IP ranges (outbound); it covers the service, not a specific account.
Storage account
Top-level Azure Storage resource providing a unique namespace for blob, file, queue and table data; its kind, performance and location are fixed at creation.
Storage Account Contributor
Built-in management-plane role for storage accounts that includes listKeys, so it reaches all data via Shared Key and exceeds least privilege for uploads.
Storage Blob Data Contributor
Built-in data-plane role that reads, writes and deletes containers and blobs; with Reader, the least privilege for portal uploads.
Storage Blob Data Owner
Built-in data-plane role with full access to blob containers and data, including setting POSIX ACLs and blob index tags.
Storage Blob Data Reader
Built-in data-plane role that reads and lists containers and blobs.
Storage Blob Delegator
Built-in role that only lets a principal get a user delegation key (generateUserDelegationKey) at account scope or above to sign a user delegation SAS; it grants no blob data access.
Storage File Data Privileged Contributor
Built-in role granting read, write, delete and modify-ACL on all Azure Files data over OAuth/REST (includes writeFileBackupSemantics), overriding NTFS ACLs.
Storage File Data Privileged Reader
Built-in role granting read of all Azure Files data over OAuth/REST (includes readFileBackupSemantics), overriding NTFS ACLs; the least-privilege read role for a managed identity using Azure Files over REST.
Storage network rule exceptions (networkAcls bypass)
Storage firewall exceptions (Bypass AzureServices, Logging, Metrics or None) that let trusted Azure services or logging and metrics traffic through when the default action is Deny.
Stored access policy
Container-level policy that constrains, and lets you revoke, any service SAS that references it; grants nothing on its own, maximum five per container, not usable with user delegation SAS.
SUCCESSFUL_DATABASE_AUTHENTICATION_GROUP
Database-level audit action group recording successful logins to the database; part of the recommended Azure SQL audit set.
SUCCESSFUL_LOGIN_GROUP
Server-level SQL Server audit action group for successful instance logins; not one of the recommended Azure SQL Database groups.
Syslog via AMA
Microsoft Sentinel connector that collects syslog from Linux machines through AMA and a DCR (facilities and minimum log levels) into the Syslog table; not for Windows.
System-assigned managed identity
Identity created and deleted with one resource; ten VMs get ten identities; Azure Policy remediation can use one.
T
T-SQL (Transact-SQL)
Microsoft's SQL dialect for SQL Server and Azure SQL; it isn't used to query Azure Monitor logs or filter event collection.
Table storage
Cheap key-value tables indexed on PartitionKey and RowKey only, with one write region and 1 MB entities.
Tag Contributor
Azure built-in role that manages tags only (Microsoft.Resources/tags/*); narrower than Contributor.
Target sub-resource
The storage service (blob, dfs, file, queue, table, web) a private endpoint connects to; one endpoint per type covers every container or share of that type, and ADLS Gen2 needs both dfs and blob.
TDE protector
Customer-managed asymmetric RSA key in Key Vault or Managed HSM that wraps the TDE data encryption key.
Template Analyzer
IaC scanner in Microsoft Security DevOps (includes PSRule) that checks ARM and Bicep templates; for Terraform, CloudFormation or Kubernetes files use Checkov or Terrascan instead.
Temporary Access Pass (TAP)
Time-limited passcode for onboarding or recovery; its value is shown only at creation.
Tenant Root Group
Root management group of a tenant; one policy or role assignment there covers every subscription.
Threat intelligence-based filtering
Azure Firewall feature (Standard and Premium) that alerts on or denies traffic to and from known malicious IPs and domains from Microsoft's threat intelligence feed.
Time-based retention (WORM) policy
Immutability policy: data can be read but not modified or deleted for the period.
TLS (Transport Layer Security)
Protocol that encrypts traffic such as HTTPS; storage minimumTlsVersion sets the lowest version accepted but grants no network access.
TLS inspection
Azure Firewall Premium feature that decrypts, inspects and re-encrypts outbound and east-west TLS traffic using an intermediate CA certificate from Key Vault.
Total retention
Microsoft Sentinel retention setting covering analytics plus data lake storage, up to 12 years; the only way to keep data longer than analytics retention's two years.
Transparent Data Encryption (TDE)
Encrypts database files at rest only; anyone who can query sees plaintext.
Trusted launch
Azure VM security type that adds Secure Boot, vTPM and boot integrity monitoring to Generation 2 VMs on supported sizes at no extra cost; unlike a confidential VM it doesn't encrypt memory in hardware.
Trusted launch Secure Boot
Trusted launch feature that lets only signed boot loaders, kernels and kernel drivers load, so an unsigned image fails to boot; it must be on (with vTPM) before guest attestation works.
Trusted Microsoft services (Allow trusted Microsoft services to bypass this firewall)
Key Vault firewall exception letting listed services such as Azure Disk Encryption, Azure Backup and Resource Manager template deployment reach the vault from any network.
U
UDR (user-defined route)
Static route-table entry, e.g. next hop virtual network gateway; not dynamic like BGP.
Unfamiliar sign-in location (unfamiliar sign-in properties)
ID Protection sign-in risk detection for sign-ins with properties (location, IP, device) not seen before for the user.
Universal with MFA (Microsoft Entra MFA)
SSMS interactive Entra authentication option that supports multifactor sign-in.
Unmanaged disks
Legacy VM disks stored as page blobs (VHDs) in your own storage account; retired in favour of managed disks.
URL filtering
Azure Firewall Premium feature that filters on the full URL path in application rules (Standard filters on FQDN only); not available in network rules.
User Access Administrator
Azure role that grants access but cannot manage resources, write tags or assign policy.
User Administrator
Entra role that creates and manages users and all groups, resets passwords for limited admins and assigns licences.
User consent
Setting (Enterprise applications > Consent and permissions) controlling whether users may consent to apps accessing data on their behalf.
User delegation SAS
SAS signed with Entra credentials; most secure SAS, works with shared key disabled, maximum 7 days; supported for Blob (including ADLS Gen2), Queue, Table and Azure Files (REST); cannot use a stored access policy.
User-assigned managed identity
Standalone identity attached to many resources, so roles are granted once.
User.Read
Low-impact delegated Microsoft Graph permission to read the signed-in user's profile; added by default to new app registrations and typically user-consentable under microsoft-user-default-low.
User.ReadWrite.All
Microsoft Graph permission to read and write all users' profiles; an app needs a registration (service principal) before it can be granted this.
user_impersonation
Delegated permission (e.g. on Azure Key Vault) letting an app call the API as the signed-in user; for Key Vault it doesn't need admin consent, so users can consent themselves.
Users can register applications
Tenant-wide switch under Entra ID > Users > User settings; set to No, only admins and roles such as Application Developer can register apps (and so create their service principals).
V
validate-azure-ad-token
APIM inbound policy that validates a Microsoft Entra-issued JWT (tenant, client application IDs, audiences, claims); the Entra-specific alternative to validate-jwt.
Virtual hub (hub)
Microsoft-managed VNet in a Virtual WAN (one per region) that hosts the VPN, ExpressRoute and User VPN gateways and the hub router.
Virtual Machine Administrator Login
Azure role that signs in to a VM as administrator via the loginAsAdmin data action; it can't manage the VM.
Virtual Machine Contributor
Azure role for managing VMs but not the network or storage they connect to.
Virtual Machine User Login
Azure role that signs in to a VM as a regular user via the login data action.
Virtual network peering (VNet peering)
Private, low-latency connection between VNets in the same or different regions over the Microsoft backbone; on its own it gives App Service no VNet access.
Virtual network rule (VNet rule)
Storage firewall rule that admits a specific subnet, which must have the Microsoft.Storage service endpoint enabled; the endpoint alone grants nothing.
Virtual WAN
Hub-based networking; Basic supports site-to-site VPN only, Standard adds ExpressRoute, point-to-site and transit.
VirtualNetwork (service tag)
Service tag covering the VNet address space, peered VNets and connected on-premises ranges.
VM extensions
Small post-deployment apps (resource type Microsoft.Compute/virtualMachines/extensions) run by the Azure VM Agent to install software or configure a VM; the VM must be running.
VMAccess extension (VMAccess)
VM extension that resets the built-in administrator password or Remote Desktop configuration on a Windows VM; needs VM/extension write, which the VM login roles lack.
VNet peering (virtual network peering)
Private, low-latency connection between VNets in the same or different regions over the Microsoft backbone; on its own it gives App Service no VNet access.
VPN gateway
Virtual network gateway of type VPN in GatewaySubnet for S2S, P2S and VNet-to-VNet IPsec tunnels; its Standard static public IP is fixed at creation and can't be swapped.
vTPM (virtual Trusted Platform Module)
Virtual TPM in a VM; in confidential VMs confidential disk encryption binds the OS disk keys to it.
W
Watchlist
Microsoft Sentinel reference list (such as VIP users or IP ranges) stored in the Watchlist table for lookups in queries and rules; it doesn't act on incidents.
Web categories (Azure Firewall)
Application-rule destinations such as gambling or social networking; Standard classifies by FQDN only, Premium by full URL.
What If tool (What If)
Conditional Access tool that shows which On or Report-only policies would apply to a simulated sign-in.
WHOIS
Domain-registration lookup protocol whose contacts and organisations Defender EASM uses as discovery seeds and asset data.
Windows Azure Service Management API (Microsoft Azure Management)
Conditional Access cloud app covering the portal and ARM, used to require MFA before Bastion.
Windows certificate store
Local Windows key store usable for Always Encrypted column master keys; App Service managed identities can't reach it, so use Key Vault.
Windows Event Forwarding (WEF)
Windows feature that forwards Windows event log entries from source computers to a collector server via subscriptions; it can't receive CEF or syslog.
Windows Firewall Events via AMA (Windows Firewall connector)
Microsoft Sentinel connector that collects Windows Defender Firewall events through AMA and a DCR (via Azure Arc for on-premises servers); it replaces the legacy MMA-based Windows Firewall connector.
Windows Forwarded Events
Microsoft Sentinel connector that collects events from a Windows Event Collector running AMA into the WindowsEvent table, not directly from each VM and not into SecurityEvent.
Windows Hello for Business (WHfB)
Passwordless, phishing-resistant sign-in on Windows devices with compatible hardware only.
Windows Security Events connector (Security Events connector)
Microsoft Sentinel data connector that collects Windows security events into the SecurityEvent table; it doesn't onboard servers to Defender for Cloud.
Windows Security Events via AMA
Microsoft Sentinel connector that collects Windows Security event log events into the SecurityEvent table through AMA and a DCR.
Windows Server 2022 Datacenter: Azure Edition (Azure Edition)
VM-only Windows Server edition optimized for Azure (Hotpatch, SMB over QUIC, Extended Network); the only edition the Extended network wizard lists for the Azure appliance.
WinRM (Windows Remote Management)
Windows protocol behind PowerShell remoting, listening on TCP 5985 for HTTP and 5986 for HTTPS.
Workbook (Azure Workbooks)
Azure Monitor interactive report combining logs, metrics and text; not a prerequisite for Traffic Analytics.
wrapKey / unwrapKey
Key Vault key operations that encrypt and decrypt another key; with get they are the access-policy permissions a CMK or TDE protector identity needs.
X
XPath (XML Path Language)
Query syntax used in a DCR's xPathQueries (for example Security!*[System[(EventID=4648)]]) to choose which Windows events AMA collects; the portal takes up to 20 expressions per box, and a DCR allows up to 100 XPath queries.