GitHub Copilot Customization Explained for Beginners: Instructions, Prompt Files, Skills, Agents, and Hooks Introduction If you've recently started using GitHub Copilot, you've probably come across terms like Instructions , Prompt Files , Skills , Agents , and Hooks . At first glance, they all seem to do the same thing—they tell Copilot what to do. So why does GitHub have five different customization features? The answer is simple: each feature solves a different problem. Think of GitHub Copilot as a new developer joining your team. On their first day, you don't just hand them code. You explain your coding standards, give them reusable templates, teach them specialized knowledge, assign them a role, and automate repetitive tasks. That's exactly how GitHub Copilot customization works. In this article, you'll learn what each feature does, when to use it, and how they all work together. By the end, you'll know which feature to start with and which ones can wait un...
AZURE SQL - Advanced Threat Protection
- Get link
- X
- Other Apps
In my last blog post, we looked at the Data Discovery & Classification, Vulnerability Assessment features within the Advanced Data Security (ADS) offering for Azure SQL. In this blog post, we will have a look into Advanced threat protection.
Azure SQL Overview
Azure SQL Database is a fully managed Platform as a Service (PaaS) Database Engine that handles most of the database management functions such as upgrading, patching, backups, and monitoring without user involvement. As with any database platform, security remains a top concern to address this issue or concerns Microsoft have offering called Advanced Data Security with Azure SQL service.Pre-requisites
- Enable Advanced Data Security (ADS) at the database level by navigating to Settings > Advanced Data Security for your SQL database and click Enable.
- Alternatively, ADS can also be configured and managed at the server level by navigating to Settings > Advanced Data Security for your server and switching the ‘Advanced Data Security’ setting from ‘Off’ to ‘On’.
Advanced Threat Protection
Advanced Threat Protection enables administrators to detect and respond to potential threats as they occur by providing security alerts on anomalous activities like SQL Injection,anomalous database access,potential vulnerabilities,suspicious database activities and query pattern.Administrator will be able to configure alerts using Azure portal on detection of such activities.This feature is available in all Azure SQL Database deployment options, including Managed Instance, Single and pooled instance.
Enable Advanced Threat Protection
In order to enable Advanced Threat Protection, ADS must be enabled as mentioned in pre-requisites.Once enabled, provide additional information to configure the specific Advanced Threat Protection Settings which are configured at Database server level under ADS as shown below.
Advance Threat Protection Types
Advanced Threat Protection types which includes the ability to choose
- All
- SQL Injection
- SQL Injection Vulnerability
- Data exfiltration
- Unsafe Action
- Anomalous Client Login
Alerts triggered based on the following features
- Vulnerability to SQL injection -This alert is triggered when an application generates a faulty SQL statement in the database.
- Potential SQL injection
- Access from unusual location
- Access from unusual Azure data center
- Access from unfamiliar principal
- Access from a potentially harmful application
- Brute force SQL credentials
You can also configure Advanced Threat Protection by leveraging Azure PowerShell cmdlets.
Alerts are visible through the Azure portal as a notification in the overview section of your database, as well as at the Advanced Data Security section.
References
https://docs.microsoft.com/en-us/azure/sql-database/sql-database-threat-detection
https://docs.microsoft.com/en-us/azure/sql-database/sql-database-managed-instance-threat-detection
Popular posts from this blog
Automate Certificate Issue and Renewal process - k8s cluster
In this blog post, we will see if you have an existing or new Kubernetes cluster with Ingress resources how do we auto-renew the certificates. If it's not auto-renewed things need to be manually done e.g. every three months you have to renew certificates, delete the expired certificate and secret, update with new certificate secrets accordingly. Manual is always tedious and not an ideal solution especially for your Test & Production environment. Pre-requisites Install and setup kubectl Install and setup Helm Kubernetes cluster already provisioned with Ingress resources. Note: The scope of the blog post is to show how the certificate renewal process can be automated, the same logic can be moved to your Deployment pipelines. Install Cert Manager Installing Cert-Manager CRDs using the below command. #For Kubernetes 1.15+ kubectl apply --validate = false \ -f https://github.com/jetstack/cert-manager/releases/downloa...
Tidy up - Unused Project and Nuget package reference using Visual Studio 2019
If you are a Developer/Architect using Visual Studio as IDE for your development activities, this blog post will be of your interest. During the Ignite 2021 conference, Microsoft released Visual Studio 2019 v16.9 and v16.10 Preview 1. As part of version 16.10 Preview 1, one of the cool features they introduced is to "Remove Unused References..." for any Projects and Nuget packages that are not in use. At the time of writing this blog post, we have Visual Studio Version 16.10.0 (official release) which includes this new feature. As part of development, we generally get carried away and introduce new Nuget package references to your project and add new references to your Projects. By the end of development, you will not be 100% sure which are not being referenced and unused which means you will leave those unused project references in your application. Now you might be wondering what's the big deal in it since it doesn't harm. The advantage of removing unused project r...
Azure App Configuration - How it's different from Azure Key Vault?
Azure App Configuration is a cloud-based managed service that helps developers and infrastructure team members to centralize and manage application configurations and feature flags. Using Azure App Configuration helps to separate application configuration from code. One of the Twelve-Factor App principles states strict separation of config from code with Azure App configuration this can be easily achieved. Azure App Configuration is now generally available as a free or paid service based on the pricing tier you choose as part of provisioning the service. In the modern world, applications often can run in different geographical locations, can be hosted on services like App Services, virtual machines, Serverless functions, Azure Container Instance, AKS, etc. Managing application configuration for all this type of service can be done in a centralized location using App configuration which means your operations and support team members need not...


Comments
Post a Comment