Security overview - Azure Arc
Security gaps often emerge when managing infrastructure across public cloud, private cloud, and on-prem environments. Azure Arc helps bridge those gaps by extending Azure security tools to Arc-enabled servers running anywhere. Read this Microsoft Learn article to see how it works and how your organization can benefit. Contact Bembry Business Solutions for a complimentary security assessment of your hybrid environment.
What is the shared responsibility model for Azure Arc-enabled servers?
The security of Azure Arc-enabled servers is a shared responsibility. Microsoft is responsible for securing the cloud service that stores system metadata, protecting privacy, documenting optional security features, publishing regular agent updates, managing RBAC access, and securing the server infrastructure. Users are responsible for securing the server itself, managing credentials, determining the application of security features, and ensuring compliance with legal and internal policies.
How does the Azure Connected Machine agent function?
The Azure Connected Machine agent acts as an enablement platform that connects your machine to Azure. It establishes a relationship with your Azure subscription, provides a managed identity for authentication, enables additional capabilities through extensions, and enforces settings on your server. The agent is essential for relaying data and actions between your managed server and Azure.
What security measures should be taken for Tier 0 assets?
For Tier 0 assets, it is recommended to use a dedicated Azure subscription to minimize access and closely monitor permissions. You should also disable unnecessary management features, such as remote access capabilities and the extension manager, unless they are needed. Implementing an extension allowlist can help restrict the use of extensions to only those that meet your security requirements.

Security overview - Azure Arc
published by Bembry Business Solutions
Welcome to Bembry Business's Cloud Solution offerings in partnership with Microsoft and SherWeb. We’re now your one-stop shop for a full range of IT cloud solutions.
Ready to step into the cloud but uncertainty is holding you back?
We know that it can be a very scary undertaking! We know you have questions. First and foremost, "is my data going to be safe?" We're here to see that all of your questions and concerns are addressed and answered. We serve the Small Business Community from the perspective of our owner, David J Bembry who's been working online since 1998, has been a Microsoft Partner for over 15 years and understands first hand the challenges of both going it alone and the information overload inherent in trying to keep up with and understand emerging technologies and techniques.
"We know the challenges you face with trying to run a business and keep up with the pace of technology and new proven business processes. As always, Bembry Business is here to help."
Patient, Professional and Private Counsel tailored to your individual needs is where we start the journey!
Microsoft Partner Network ID 1804446