The following section describes about some of the Azure-specific terminologies that are used to deploy the Virtual IPS solution. For more information about the Azure concepts, refer to Azure documentation.
Subscription — Subscriptions are logical units in Azure services that are assigned a role and linked to an account.
Azure Active Directory tenant — The Azure Active Directory (Azure AD) tenants are dedicated Azure instances to an enterprise or organization when they sign up for Microsoft Azure services. It contains information about the users in a company. A user in one Azure AD cannot access information in another AD.
Resource group — Resource groups are a group of resources which have the same lifecycle. All the resources in a resource group are deployed, updated, and deleted together. A single resource can be a part of one resource group only.
Regions — Azure regions are specific datacenters where your applications run or the data is stored. The regions correspond to specific geographic locations.
Resources — Resources are the manageable items that are created in Azure. The items can be virtual machines, storage, web app, database, and so on.
Virtual Machines — Virtual machines are the virtual equivalent to the physical computers running an operating system that can run simultaneously on the same hardware.
Virtual Network — This is the network that provides connectivity between Azure resources that are isolated from the other Azure tenants. It is the logical isolation of Azure cloud dedicated to your subscription.
Network Security Group — Network Security Groups are security rules for subnets, virtual machines, or resource groups that allow or deny network traffic to resources.
Availability set — The availability set provides redundancy to virtual machines by providing high availability during downtime or maintenance.
Azure Storage Blob — It is a storage space for large amounts of unstructured data that can be accessed through HTTP or HTTPS.
Managed Identity — It is feature in Azure that allows you to authenticate users to Azure services without any credentials. The Managed Identity is of two types:
- System-assigned managed identity — It is enabled directly on an Azure instance. The life cycle of this identity is completely dependent on the life time of the Azure instance it is enabled on. If the instance is deleted, Azure automatically deletes its system-assigned managed identity.
- User-assigned managed identity — It is created as an individual resource in Azure and can be assigned to multiple Azure instances. The life cycle of this identity is not dependent on the life cycle of the Azure instances using it.