A global financial services firm operates a legacy banking application on physical Windows servers in their private data center, along with several containerized microservices hosted on Google Cloud Platform (GCP). The IT department wants to apply consistent corporate compliance rules and security monitoring to these non-Azure workloads using Azure Policy and Microsoft Defender, without migrating any resources to Azure. Which of the following Azure services should they use to achieve this goal?
- AAzure Stack Hub
- Azure ArcCevap
- CAzure Policy without any additional services
- DAzure Role-Based Access Control (RBAC)
Cevap
Azure Arc
Azure Arc is designed to extend Azure management and services to any infrastructure, including virtual machines, physical servers, and Kubernetes clusters running on-premises or in other clouds (such as GCP). By registering these resources with Azure Arc, they appear as resource objects inside Azure, allowing the IT department to apply Azure Policy and Microsoft Defender just as they would with native Azure resources.
Adım Adım Çözüm
Anahtar Kavram
Azure Arc extends the Azure Resource Manager control plane, enabling the management, governance, and security of resources running on-premises, at the edge, or in multi-cloud environments.