I'm looking for some Azure security best practice advice. I've seen some articles around on how to do it, but not if its necessarily required.
I have a customer who would like to move to Azure and they have specifically requested we stick to a PAAS solution as much as possible. The apps we'll be deploying are fairly straight forward so a few web app services will meet the requirements.
The problem is they have always been fairly risk averse and security conscious, so I'm wondering if best practice would say we need each site in a virtual network behind an application gateway with a WAF, or can we just have the app services running and Azure will do enough by default?
On their current hosting solution we have a WAF and DDOS protection but this was only a recent addition, and it's almost a ticking the box exercise.