FREE STUDY NOTES · SC-900

Azure DDoS Protection: infrastructure protection, Network Protection and IP Protection

The kinds of DDoS attack, what every public IP gets free, and what the paid tiers add.

From Ultra Transcenders SC-900 by Tony Rough (publishing soon)

A denial-of-service attack tries to make an application unavailable by exhausting its resources. When many machines attack at once, it is a distributed denial-of-service (DDoS) attack. Any endpoint reachable from the internet can be a target, so Azure includes a basic level of DDoS protection for everyone and sells enhanced tiers.

Types of attack

Learn sorts DDoS attacks into three groups:

Attack type What it does Examples Mitigated by
Volumetric Floods the network layer with huge amounts of seemingly legitimate traffic UDP floods, ICMP floods, reflection amplification Azure DDoS Protection (absorbs and scrubs the traffic)
Protocol Exploits weaknesses in the layer 3 and layer 4 protocol stack SYN floods, fragmented packet attacks, ping of death Azure DDoS Protection
Resource (application) layer Targets web application traffic at layer 7 HTTP floods, Slowloris, SQL injection, cross-site scripting A web application firewall (WAF), used alongside DDoS Protection

Layers 3 and 4 are the network and transport layers (IP addresses, TCP and UDP); layer 7 is the application layer (for example HTTP requests).

Tiers

Azure DDoS Protection comes in three levels:

Tier Cost What it covers Extras
DDoS infrastructure protection Free, always on, no configuration Every Azure service that uses a public IPv4 or IPv6 address, including PaaS (platform as a service) services None
DDoS Network Protection Paid plan, priced per 100 protected public IP addresses; one plan can cover virtual networks across subscriptions in a tenant Resources in the virtual networks linked to the plan, including Basic tier public IPs DDoS Rapid Response support, cost protection, WAF discount
DDoS IP Protection Paid per protected public IP; no plan needed Individual public IP resources (not Basic tier public IPs) None of the extras

Both paid tiers share the same core engine: always-on traffic monitoring, automatic layer 3/4 mitigation, policies tuned to the application’s own traffic, metrics, alerts, mitigation reports and flow logs, and a Microsoft Sentinel data connector. The differences are the value-added services:

Common trap: Expecting Azure DDoS Protection to stop HTTP floods, SQL injection or cross-site scripting - every tier mitigates layer 3 and 4 attacks only; layer 7 protection needs a web application firewall alongside it.

Common trap: Choosing DDoS IP Protection to get help from Microsoft during an attack - Rapid Response, cost protection and the WAF discount come only with DDoS Network Protection.

Get the whole book

This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Publishing soon on Amazon in Kindle and paperback editions.

About the book · SC-900 terms in the glossary · All SC-900 study notes

More SC-900 study notes