gpt4 book ai didi

azure - Azure 支持是否可以访问所有资源和敏感数据(例如 KeyVault)?

转载 作者:行者123 更新时间:2023-12-02 08:32:58 24 4
gpt4 key购买 nike

我找不到任何有关 Azure 支持人员或任何其他 Azure 人员(管理员、安全专家,无论他们拥有什么)如何访问客户端资源的文档。我想说的是,如果您有敏感数据(例如 KeyVault 中的数据),Microsoft 可以以任何方式查看这些数据吗?例如,他们将自己添加为全局管理员,甚至在后台拥有一些更高的角色?或者他们可以解密 KeyVault 中的所有数据,因为他们拥有所有 key ?

附注我纯粹是在理论上谈论。

最佳答案

来自the docs :

Access to customer data by Microsoft operations and support personnel is denied by default. When access to customer data is granted, leadership approval is required and then access is carefully managed and logged. The access-control requirements are established by the following Azure Security Policy:

  • No access to customer data, by default.
  • No user or administrator accounts on customer virtual machines (VMs).
  • Grant the least privilege that's required to complete task; audit and log access requests.

Azure support personnel are assigned unique corporate Active Directory accounts by Microsoft. Azure relies on Microsoft corporate Active Directory, managed by Microsoft Information Technology (MSIT), to control access to key information systems. Multi-factor authentication is required, and access is granted only from secure consoles.

All access attempts are monitored and can be displayed via a basic set of reports.

请看一下Trust Center也是如此。

关于azure - Azure 支持是否可以访问所有资源和敏感数据(例如 KeyVault)?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/59255338/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com