* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Tuesday, August 19, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    ‘The Lucky Ones’: Mae Ngai Sells Film & TV Rights To Neurosphere Entertainment – Deadline

    The Lucky Ones’: Mae Ngai Lands Thrilling Deal for Film and TV Adaptations

    Our picks for the best things to do in Cincinnati this week, Aug. 18-24 – Cincinnati Enquirer

    Unmissable Things to Do in Cincinnati This Week, Aug. 18-24

    Terence Stamp: from arthouse icon to blockbuster villain – yahoo.com

    Terence Stamp: From Arthouse Legend to Hollywood’s Ultimate Villain

    Community & Entertainment redefined: The summer fun continues with Villagio Hospitality! – WJLA

    Summer Fun Redefined: Create Unforgettable Moments with Villagio Hospitality!

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    ‘The Rainmaker’ Premiere: Milo Callaghan Breaks Down Rudy Baylor’s ‘Misguided Valor’ – The Laconia Daily Sun

    Inside ‘The Rainmaker’ Premiere: Milo Callaghan Uncovers the Real Story Behind Rudy Baylor’s Misguided Valor

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Thaddeus Stevens College of Technology kicks off return to school for Lancaster County colleges [photos] – LancasterOnline

    Thaddeus Stevens College of Technology Kicks Off an Exciting New School Year for Lancaster County Colleges [Photos]

    Empyrean Technology’s revenue climbs, but profit plunges 92% in EDA spending squeeze – digitimes

    Empyrean Technology’s Revenue Skyrockets as Profits Plunge 92% Amid EDA Spending Crunch

    5G-A technology provides strong support for China’s football sensation Suchao – Global Times

    How 5G-A Technology is Revolutionizing China’s Football Star Suchao

    AI’s backyard: A map of the 21st-century gold rush – EL PAÍS English

    The AI Frontier: Exploring the Thrilling Gold Rush of the 21st Century

    Youxin Technology Ltd Faces Nasdaq Deficiency Notices Over Listing Compliance Issues

    Vermont famers say new technology is changing the state’s agriculture industry – News Channel 3-12

    Vermont Farmers Embrace New Technology Transforming the State’s Agriculture Industry

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    ‘The Lucky Ones’: Mae Ngai Sells Film & TV Rights To Neurosphere Entertainment – Deadline

    The Lucky Ones’: Mae Ngai Lands Thrilling Deal for Film and TV Adaptations

    Our picks for the best things to do in Cincinnati this week, Aug. 18-24 – Cincinnati Enquirer

    Unmissable Things to Do in Cincinnati This Week, Aug. 18-24

    Terence Stamp: from arthouse icon to blockbuster villain – yahoo.com

    Terence Stamp: From Arthouse Legend to Hollywood’s Ultimate Villain

    Community & Entertainment redefined: The summer fun continues with Villagio Hospitality! – WJLA

    Summer Fun Redefined: Create Unforgettable Moments with Villagio Hospitality!

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    ‘The Rainmaker’ Premiere: Milo Callaghan Breaks Down Rudy Baylor’s ‘Misguided Valor’ – The Laconia Daily Sun

    Inside ‘The Rainmaker’ Premiere: Milo Callaghan Uncovers the Real Story Behind Rudy Baylor’s Misguided Valor

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Thaddeus Stevens College of Technology kicks off return to school for Lancaster County colleges [photos] – LancasterOnline

    Thaddeus Stevens College of Technology Kicks Off an Exciting New School Year for Lancaster County Colleges [Photos]

    Empyrean Technology’s revenue climbs, but profit plunges 92% in EDA spending squeeze – digitimes

    Empyrean Technology’s Revenue Skyrockets as Profits Plunge 92% Amid EDA Spending Crunch

    5G-A technology provides strong support for China’s football sensation Suchao – Global Times

    How 5G-A Technology is Revolutionizing China’s Football Star Suchao

    AI’s backyard: A map of the 21st-century gold rush – EL PAÍS English

    The AI Frontier: Exploring the Thrilling Gold Rush of the 21st Century

    Youxin Technology Ltd Faces Nasdaq Deficiency Notices Over Listing Compliance Issues

    Vermont famers say new technology is changing the state’s agriculture industry – News Channel 3-12

    Vermont Farmers Embrace New Technology Transforming the State’s Agriculture Industry

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Microsoft’s security roadmap: Protect secrets in Azure DevOps

July 16, 2023
in Technology
Microsoft’s security roadmap: Protect secrets in Azure DevOps
Share on FacebookShare on Twitter

Microsoft has vowed to bulk up security around its Azure DevOps cloud services developers use to build their applications and manage their software projects.

The security enhancements are part of the larger roadmap for Azure DevOps that the cloud giant laid out this week that also includes additions to Azure Boards – for tracking ideas throughout the development lifecycle – and Azure Pipelines to automatically build and test code.

The changes also come as Microsoft bolsters its Entra suite of cloud-based identity and access services, not only by ditching the Azure AD name in favor of Entra ID – a move not fully embraced by all users – but also through its first offerings in the fast-growing security services edge (SSE) space.

One focus for Redmond is the GitHub code repository, which like other code bases – such as NPM and the Python Package Index (PyPI) – has become a target for criminals in supply chain attacks aimed at getting developers to inadvertently dropping malicious code into their applications.

GitHub Advanced Security (GHAS) for Azure DevOps is a suite of tools developers can use to protect their Azure Repos repositories and Pipelines. These include secret scanning to detect such secrets as credentials already in Azure Repos and ways to keep developers from accidentally pushing new secrets and dependency scanning, so they can find known vulnerable open-source packages and fix any problems.

Also in GHAS – which is in public preview and integrated into Azure DevOps – is code scanning, which uses GitHub’s CodeQL semantic analysis engine to identity app security flaws in the source code.

Authentication on the menu

Identity and authentication also will factor heavily in what Microsoft does through at least the rest of the year. The vendor for several years has banged the drum for improved authentication tools – such as ModernAuth and passkeys – as identity becomes a key focus for cyber-attackers.

In Azure DevOps, a key risk is credential theft.

“Azure DevOps supports many different authentication mechanisms, including basic authentication, personal access tokens (PATs), SSH, and Azure Active Directory access tokens,” the company wrote. “These mechanisms are not created equal from a security perspective, especially when it comes to the potential for credential theft.”

Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws

Microsoft keeps quiet amid talk of possible DDoS attack against Azure

Microsoft’s Azure mishap betrays an industry blind to a big problem

This typo sparked a Microsoft Azure outage

Criminals can use leaked credentials like PATs to get into organizations using Azure DevOps and access source code, launch supply chain attacks, or compromise the infrastructure.

Microsoft will also release Workload Identity federation for Azure Deployments, first in public preview in the third quarter and then generally by the end of the year. Developers are wary of storing secrets like passwords or certificate in Azure DevOps because they become vulnerable to theft when service connections in Azure DevOps are updated.

Protection through federation

Azure will use the Open ID Connect protocol to support workload identity federation and create service connections in Azure Pipelines that don’t access secrets and which are backed by managed identities with federated credentials in Azure AD.

“As part of its execution, a pipeline can exchange its own internal token with an AAD token, thereby gaining access to Azure resources,” Microsoft wrote. “Once implemented, this mechanism will be recommended in the product over other types of Azure service connections that exist today.”

Microsoft also will support granular scopes to limit the operations of Azure AD OAuth applications, such as viewing source code or configuring pipelines, when connecting to Azure DevOps.

Also by the end of 2023, Microsoft will let applications use managed identities and service principals when integrating with Azure DevOps through REST APIs and client libraries. Most applications now integrate through PATs.

“This highly requested feature offers Azure DevOps customers a more secure alternative to PATs,” Redmond wrote. “And Managed Identities offer the ability for applications running on Azure resources to obtain Azure AD tokens without needing to manage any credentials at all.”

Microsoft takes to SSE

All this comes the same week Microsoft made changes in its Entra suite. The first, as we’ve documented, was the name change from Azure AD to Entra. Another key one was the rollout into public preview of Entra Internet Access and Entra Private Access, Redmond’s first SSE offerings.

Secure Access Service Edge (SASE) hit the scene several years ago when enterprises, faced with having to manage security and identity wirelessly, wanted vendors to converge software-defined WAN and network security functions, such as zero trust, firewall-as-a-service (FWaaS), and cloud access security broker (CASB), into a cloud service.

SSE emerged during the pandemic, essentially ditching the SD-WAN functions and unifying CASB, zero trust, and secure web gateway (SWG) into a service. Microsoft is coming into this space late, with vendors like Cisco, Zscaler, and Palo Alto Networks, among others, already a year or two ahead.

However, Microsoft’s sheer gravitational pull will help it gain market share, as shown by the drop in share prices of Cloudflare, Palo Alto, and Zscaler right after Microsoft announced its SSE move. ®

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : The Register – https://go.theregister.com/feed/www.theregister.com/2023/07/16/microsoft_azure_devops_security/

Tags: Microsoft’ssecuritytechnology
Previous Post

This AI is better than you at figuring out where a street pic was taken just by looking at it

Next Post

Get Protocol Takes on Ticketmaster with $4.5 Million Funding for NFT Ticketing Revolution

The best ways to search the Tulsa World Archive of millions of stories – Tulsa World

Unlock Hidden Stories: Top Tips for Exploring the Tulsa World Archive

August 19, 2025
Global Economic Outlook: August 2025 – Seeking Alpha

August 2025 Global Economic Outlook: Unveiling Key Trends and Insights

August 19, 2025
‘The Lucky Ones’: Mae Ngai Sells Film & TV Rights To Neurosphere Entertainment – Deadline

The Lucky Ones’: Mae Ngai Lands Thrilling Deal for Film and TV Adaptations

August 19, 2025
Kearney Public Schools launches new mental health resource for parents – KSNB

Kearney Public Schools Unveils Innovative Mental Health Resource to Support Parents

August 19, 2025
Newsom announces California redistricting push, setting up a standoff with GOP-led opponents – CNN

Newsom announces California redistricting push, setting up a standoff with GOP-led opponents – CNN

August 19, 2025
Critically endangered plains-wanderer found in unfamiliar territory – EurekAlert!

Critically endangered plains-wanderer found in unfamiliar territory – EurekAlert!

August 19, 2025
Little Rock Central High opens new science building – Little Rock Public Radio

Little Rock Central High Unveils Cutting-Edge Science Building

August 19, 2025
Science | Santa Maria hosting “Astronaut for a Day” initiative – Azores – Portuguese American Journal

Experience Space Like Never Before with Santa Maria’s Exciting “Astronaut for a Day” Adventure!

August 19, 2025
Having 47 unread texts but nobody to call when you’re falling apart is the loneliest feeling nobody talks about – VegOut

Having 47 unread texts but nobody to call when you’re falling apart is the loneliest feeling nobody talks about – VegOut

August 19, 2025
Thaddeus Stevens College of Technology kicks off return to school for Lancaster County colleges [photos] – LancasterOnline

Thaddeus Stevens College of Technology Kicks Off an Exciting New School Year for Lancaster County Colleges [Photos]

August 19, 2025

Categories

Archives

August 2025
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Jul    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (778)
  • Economy (800)
  • Entertainment (21,678)
  • General (16,550)
  • Health (9,839)
  • Lifestyle (811)
  • News (22,149)
  • People (801)
  • Politics (808)
  • Science (16,012)
  • Sports (21,298)
  • Technology (15,780)
  • World (782)

Recent News

The best ways to search the Tulsa World Archive of millions of stories – Tulsa World

Unlock Hidden Stories: Top Tips for Exploring the Tulsa World Archive

August 19, 2025
Global Economic Outlook: August 2025 – Seeking Alpha

August 2025 Global Economic Outlook: Unveiling Key Trends and Insights

August 19, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version