Home
%3CLINGO-SUB%20id%3D%22lingo-sub-843872%22%20slang%3D%22en-US%22%3EEnhanced%20security%20and%20resiliency%20with%20your%20Azure%20Data%20Explorer%20cluster%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-843872%22%20slang%3D%22en-US%22%3E%3CH2%20id%3D%22toc-hId-1820147486%22%20id%3D%22toc-hId-1820147486%22%3EAzure%20availability%20zones%3C%2FH2%3E%0A%3CP%3EAvailability%20zones%20are%20unique%20physical%20locations%20within%20the%20same%20Azure%20region.%3C%2FP%3E%0A%3CP%3EAzure%20availability%20zones%20can%20protect%20an%20Azure%20Data%20Explorer%20cluster%20and%20data%20from%20partial%20region%20failure.%3C%2FP%3E%0A%3CP%3EDeploying%20a%20new%20cluster%20to%20different%20availability%20zones%20means%20the%20underlying%20compute%20and%20storage%20components%20are%20deployed%20to%20different%20zones%20in%20the%20region%20with%20independent%20power%2C%20cooling%20and%20networking.%20In%20a%20case%20of%20a%20zonal%20downtime%20the%20cluster%20will%20continue%20to%20work%2C%20but%20it%20might%20have%20performance%20degradation%20until%20the%20failure%20will%20be%20resolved.%3C%2FP%3E%0A%3CP%3EIn%20addition%2C%20you%20can%20use%20zonal%20services%20which%20means%20allowing%20to%20pin%20an%20Azure%20Data%20Explorer%20cluster%20to%20the%20same%20zone%20as%20other%20Azure%20resources%20that%20are%20used%20in%20conjunction%20with%20that%20cluster.%3C%2FP%3E%0A%3CP%3EDeployment%20to%20various%20or%20specific%20availability%20zones%20can%20be%20done%20only%20during%20cluster%20creation%20and%20it%20cannot%20be%20modified%20later.%3C%2FP%3E%0A%3CP%3EFor%20more%20details%20on%20enabling%20availability%20zones%20on%20Azure%20Data%20Explorer%20please%20read%20-%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fdata-explorer%2Fcreate-cluster-database-portal%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fdata-explorer%2Fcreate-cluster-database-portal%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F130716i9B89D79B5D8701E9%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_0.png%22%20title%3D%22clipboard_image_0.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--732009475%22%20id%3D%22toc-hId--732009475%22%3EAzure%20Disk%20Encryption%3C%2FH2%3E%0A%3CP%3EAzure%20Data%20Explorer%20now%20supports%20encryption%20at%20REST.%3C%2FP%3E%0A%3CP%3EEncryption%20at%20REST%20provides%20protection%20to%20the%20data%20and%20OS%20stored%20on%20the%20Disk%20and%20SSD.%3C%2FP%3E%0A%3CP%3EEnabling%20disk%20encryption%20can%20be%20performed%20on%20an%20existing%20cluster%20that%20either%20contains%20or%20does%20not%20contain%20data.%3C%2FP%3E%0A%3CP%3EAll%20data%20hosted%20will%20be%20encrypted%20and%20after%20that%20encryption%20will%20take%20place%20when%20new%20data%20is%20persisted.%3C%2FP%3E%0A%3CP%3EFor%20more%20details%20on%20Azure%20Disk%20Encryption%20please%20read%20%E2%80%93%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity%2Ffundamentals%2Fencryption-atrest%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity%2Ffundamentals%2Fencryption-atrest%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EFor%20more%20details%20on%20enabling%20disk%20encryption%20on%20Azure%20Data%20Explorer%20please%20read%20-%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fdata-explorer%2Fmanage-cluster-security%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fdata-explorer%2Fmanage-cluster-security%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F130717i06594238894E1C5E%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22clipboard_image_1.png%22%20title%3D%22clipboard_image_1.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-843872%22%20slang%3D%22en-US%22%3E%3CP%3EWant%20to%20further%20secure%20data%20and%20improve%20resiliency%20of%20your%20Azure%20Data%20Explorer%20cluster%3F%3C%2FP%3E%0A%3CP%3ERecently%20Azure%20Data%20Explorer%20released%202%20new%20capabilities%20to%20improve%20security%20and%20resiliency%20of%20your%20cluster.%3C%2FP%3E%3C%2FLINGO-TEASER%3E
Microsoft

Azure availability zones

Availability zones are unique physical locations within the same Azure region.

Azure availability zones can protect an Azure Data Explorer cluster and data from partial region failure.

Deploying a new cluster to different availability zones means the underlying compute and storage components are deployed to different zones in the region with independent power, cooling and networking. In a case of a zonal downtime the cluster will continue to work, but it might have performance degradation until the failure will be resolved.

In addition, you can use zonal services which means allowing to pin an Azure Data Explorer cluster to the same zone as other Azure resources that are used in conjunction with that cluster.

Deployment to various or specific availability zones can be done only during cluster creation and it cannot be modified later.

For more details on enabling availability zones on Azure Data Explorer please read - https://docs.microsoft.com/en-us/azure/data-explorer/create-cluster-database-portal

clipboard_image_0.png

Azure Disk Encryption

Azure Data Explorer now supports encryption at REST.

Encryption at REST provides protection to the data and OS stored on the Disk and SSD.

Enabling disk encryption can be performed on an existing cluster that either contains or does not contain data.

All data hosted will be encrypted and after that encryption will take place when new data is persisted.

For more details on Azure Disk Encryption please read – https://docs.microsoft.com/en-us/azure/security/fundamentals/encryption-atrest

For more details on enabling disk encryption on Azure Data Explorer please read - https://docs.microsoft.com/en-us/azure/data-explorer/manage-cluster-security

 

clipboard_image_1.png