Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
The Ins and Outs of Azure VMware Solution

You're reading from   The Ins and Outs of Azure VMware Solution Deploy, configure, and manage an Azure VMware Solution environment

Arrow left icon
Product type Paperback
Published in Jan 2023
Publisher Packt
ISBN-13 9781801814317
Length 328 pages
Edition 1st Edition
Tools
Arrow right icon
Author (1):
Arrow left icon
Kevin Jellow Kevin Jellow
Author Profile Icon Kevin Jellow
Kevin Jellow
Arrow right icon
View More author details
Toc

Table of Contents (20) Chapters Close

Preface 1. Part 1: Getting Started with Azure VMware Solution (AVS)
2. Chapter 1: Introduction to Azure VMware Solution FREE CHAPTER 3. Chapter 2: Enterprise-Scale for AVS 4. Part 2: Planning and Deploying AVS
5. Chapter 3: Planning for an Azure VMware Solution Deployment 6. Chapter 4: Deploying an Azure VMware Solution Cluster 7. Chapter 5: Deploying and Configuring HCX in Azure VMware Solution 8. Chapter 6: Networking in AVS using NSX-T 9. Part 3: Configuring Your AVS
10. Chapter 7: Creating and Configuring a Secure vWAN Hub for Internet Connectivity 11. Chapter 8: Inspecting Traffic for AVS 12. Chapter 9: Storage Concepts in AVS 13. Chapter 10: Working with VMware Site Recovery Manager 14. Part 4: Governance and Management for AVS
15. Chapter 11: Managing an Azure VMware Solution Environment 16. Chapter 12: Leveraging Governance for Azure VMware Solution 17. Chapter 13: Summary of Azure VMware Solution, Roadmap, and Best Practices 18. Index 19. Other Books You May Enjoy

Identity and access management

There are different identity requirements for AVS based on how it’s set up in Azure. AVS comes with a built-in user called cloudadmin in the new environment’s vCenter. This user has been given the CloudAdmin role, which gives them a lot of power in vCenter. It’s also possible to set up new roles in your AVS environment using the principle of least privilege:

  • Active Directory Domain Services (AD DS): It is highly recommended to deploy an AD DS domain controller in your identity subscription in Azure. This will help with users’ authentication in Azure instead of this request being made back in the customer’s on-premises environment.
  • Least-privilege roles: Allow only a small number of people to have the CloudAdmin role. When assigning users to AVS, use custom roles and as few permissions as possible.
  • Resource-based access control: People who need to manage AVS should only have Role-Based Access Control (RBAC) permissions for the resource group where AVS is installed, and for delegated users who need to manage it.
  • vSphere permissions: Only set up vSphere permissions with custom roles at the top level if you need to. It’s better to give permissions to the right VM folder or resource pool. In general, do not apply any kind of vSphere permissions at or above the level of the data center.
  • Active Directory sites and services: Ensure that Active Directory sites and services are configured with the appropriate and respective client IP subnets to provide a better authentication experience when attempting to locate the nearest domain controller.
  • Active Directory groups: When you set up groups in Active Directory, you can use RBAC to manage vCenter and NSX-T. You can make your own roles and assign them to Active Directory groups.
You have been reading a chapter from
The Ins and Outs of Azure VMware Solution
Published in: Jan 2023
Publisher: Packt
ISBN-13: 9781801814317
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Banner background image