Understanding the benefits of a locked system
The benefits of a locked system start from the hardware used to deploy Azure Stack Hub. As we have learned in previous chapters, the Azure Stack Hub solution provided by OEM vendors such as Lenovo, Dell, HPE, and Cisco is an integrated system. This means that the hardware and software is known at deployment time. This gives us a few security advantages, which are detailed as follows:
- List of software components: Applications are whitelisted, and Device Guard ensures that only Microsoft-signed software is deployed.
- OS dependencies: Azure Stack Hub includes a customized OS configuration with unnecessary legacy applications removed.
- Known hardware characteristics: All OEM vendors have data at rest enabled by default.
These properties are the same regardless of which OEM vendor is chosen by the organization and all integrated systems are certified by Microsoft.
The next property that affords a security benefit in this...