Pluralsight Hands-On Lab — Azure Security
Pluralsight Hands-On Lab — Security
| Platform | Pluralsight |
|---|---|
| Category | Azure Security |
| Lab Type | Guided + Challenge Mode |
| Environment | Azure Portal, Windows VM via Remote Desktop, PowerShell |
| Completed | 2026 |
Hard-coding secrets in plain text inside scripts is a common and critical security risk. In this lab, I was given a scenario as a security engineer tasked with securing an automation VM whose PowerShell scripts contained hard-coded secrets. I replaced that approach by configuring Azure Key Vault with a private endpoint to keep traffic off the public internet, attaching a user-assigned managed identity to the VM for native Entra ID authentication, and using PowerShell inside the VM to create and retrieve secrets from Key Vault — all without storing credentials in the script itself.
Connect-AzAccount -IdentitySet-AzKeyVaultSecret, and retrieved it in plain text using Get-AzKeyVaultSecret -AsPlainText to confirm end-to-end functionality