Azure Atlas: Services, Endpoints and Maps
Azure Atlas: Services, Endpoints and Maps
The Azure companion to the AWS atlas. Where AWS has one API host per service and region, Azure has one control plane (Resource Manager) for everything and a per-resource data-plane hostname for the things you connect to. This sheet maps the hierarchy, the token audiences, the sovereign clouds, the regions, the resource providers and the DNS suffixes you will meet in firewall rules, Private Link zones and SIEM parsers.
Resource hierarchy
Every Azure object lives at a fixed depth in one tree. RBAC role assignments, Policy assignments and locks are inherited downward; the resource ID tells you exactly where you are.
fig 1 · the five scopes; a resource ID is the path through this tree
| Scope | ID prefix | What binds here |
|---|---|---|
| Tenant | / | Entra ID users, groups, apps, Conditional Access; tenant-level deployments (az deployment tenant) |
| Management group | /providers/Microsoft.Management/managementGroups/{id} | Policy initiatives, landing-zone RBAC, Defender plans at scale |
| Subscription | /subscriptions/{sub-id} | Quotas, billing, resource provider registration, Activity Log |
| Resource group | /subscriptions/{sub}/resourceGroups/{rg} | Deployments (ARM, Bicep), locks, tags, deletion as a unit; has a location but resources inside can be anywhere |
| Resource | …/providers/{namespace}/{type}/{name} | Diagnostic settings, data-plane RBAC, Private Endpoints, resource locks |
Sovereign clouds: endpoint suffixes
Three independent clouds with separate tenants, separate IP space and separate DNS suffixes. Nothing crosses between them. Azure Germany was retired in 2021.
| Endpoint | Azure (public) | Azure China (21Vianet) | Azure Government (US) |
|---|---|---|---|
| az cloud name | AzureCloud | AzureChinaCloud | AzureUSGovernment |
| Resource Manager | management.azure.com | management.chinacloudapi.cn | management.usgovcloudapi.net |
| Entra ID sign-in | login.microsoftonline.com | login.chinacloudapi.cn login.partner.microsoftonline.cn | login.microsoftonline.us |
| Microsoft Graph | graph.microsoft.com | microsoftgraph.chinacloudapi.cn | graph.microsoft.us dod-graph.microsoft.us |
| Portal | portal.azure.com | portal.azure.cn | portal.azure.us |
| Storage | *.core.windows.net | *.core.chinacloudapi.cn | *.core.usgovcloudapi.net |
| SQL Database | *.database.windows.net | *.database.chinacloudapi.cn | *.database.usgovcloudapi.net |
| Key Vault | *.vault.azure.net | *.vault.azure.cn | *.vault.usgovcloudapi.net |
| Cosmos DB | *.documents.azure.com | *.documents.azure.cn | *.documents.azure.us |
| Container Registry | *.azurecr.io | *.azurecr.cn | *.azurecr.us |
| AKS API server | *.azmk8s.io | *.cx.prod.service.azk8s.cn | *.azmk8s.us |
| App Service | *.azurewebsites.net | *.chinacloudsites.cn | *.azurewebsites.us |
| Service Bus / Event Hubs | *.servicebus.windows.net | *.servicebus.chinacloudapi.cn | *.servicebus.usgovcloudapi.net |
| Log Analytics ingestion | *.ods.opinsights.azure.com | *.ods.opinsights.azure.cn | *.ods.opinsights.azure.us |
| Azure DNS public IP label | *.{region}.cloudapp.azure.com | *.{region}.cloudapp.chinacloudapi.cn | *.{region}.cloudapp.usgovcloudapi.net |
Switching az cloud set -n AzureUSGovernment && az login. The SDKs take an AzureAuthorityHosts / cloud parameter; Terraform takes environment = “usgovernment”. Service tags, Private Link zone names and the portal all differ per cloud, so copy nothing between them without checking.
Control plane vs data plane
Create, configure and delete go through Azure Resource Manager at one global hostname. Reading a blob, running a query or sending a message goes straight to the resource with a token for that service’s audience.
fig 2 · one ARM endpoint for all services; the data plane has its own hostname, token audience and logging
| Target | Token scope (v2) or resource (v1) | Notes |
|---|---|---|
| Resource Manager | https://management.azure.com/.default | control plane for everything; also Resource Graph, Cost Management, Policy |
| Microsoft Graph | https://graph.microsoft.com/.default | Entra users, groups, apps, Intune, Defender XDR |
| Storage (blob, queue, dfs, file) | https://storage.azure.com/.default | needs a data-plane RBAC role (Storage Blob Data Reader etc.) |
| Key Vault | https://vault.azure.net/.default | Managed HSM: https://managedhsm.azure.net/.default |
| SQL Database / MI / Synapse SQL | https://database.windows.net/.default | Entra authentication in the connection string |
| PostgreSQL / MySQL flexible | https://ossrdbms-aad.database.windows.net/.default | token is the password |
| Cosmos DB (NoSQL) | https://cosmos.azure.com/.default | data-plane RBAC via Cosmos SQL role definitions, not ARM roles |
| Service Bus | https://servicebus.azure.net/.default | also Relay and Notification Hubs namespaces |
| Event Hubs | https://eventhubs.azure.net/.default | Kafka clients use OAUTHBEARER with the same audience |
| Log Analytics query | https://api.loganalytics.io/.default | query host api.loganalytics.azure.com |
| Monitor ingestion (DCR) | https://monitor.azure.com/.default | Logs Ingestion API via a data collection endpoint |
| Azure OpenAI / AI Services | https://cognitiveservices.azure.com/.default | or the api-key header |
| Azure DevOps | 499b84ac-1321-427f-aa17-267ca6975798/.default | fixed app ID; PATs are the alternative |
| Azure Databricks | 2ff814a6-3304-4ab8-85cb-cd0e6f879c1d/.default | fixed app ID |
| Data Explorer (Kusto) | https://{cluster}.{region}.kusto.windows.net/.default | per-cluster audience |
| Container Registry | (exchange an ARM token at /oauth2/exchange) | az acr login does this; result is a registry refresh token |
| Batch | https://batch.core.windows.net/.default | |
| App Configuration | https://azconfig.io/.default | |
| Azure Maps | https://atlas.microsoft.com/.default |
# Control plane by hand: list subscriptions through ARM TOKEN=$(az account get-access-token --resource https://management.azure.com --query accessToken -o tsv) curl -s -H "Authorization: Bearer $TOKEN" \ "https://management.azure.com/subscriptions?api-version=2022-12-01" # Same thing with az rest (token and host are implied) az rest --method get --url "/subscriptions?api-version=2022-12-01" # Data plane by hand: list blobs with a Storage-audience token TOKEN=$(az account get-access-token --resource https://storage.azure.com --query accessToken -o tsv) curl -s -H "Authorization: Bearer $TOKEN" -H "x-ms-version: 2024-11-04" \ "https://myacct.blob.core.windows.net/mycontainer?restype=container&comp=list" # Managed identity on a VM: IMDS hands out tokens, no secret on disk curl -s -H "Metadata: true" \ "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/" # Managed identity on App Service, Functions, Container Apps curl -s -H "X-IDENTITY-HEADER: $IDENTITY_HEADER" \ "$IDENTITY_ENDPOINT?api-version=2019-08-01&resource=https://vault.azure.net" # Instance metadata (VM facts, scheduled events, attested document) curl -s -H "Metadata: true" "http://169.254.169.254/metadata/instance?api-version=2021-02-01" | jq .compute curl -s -H "Metadata: true" "http://169.254.169.254/metadata/scheduledevents?api-version=2020-07-01"
Two RBAC layers ARM roles carry actions (control plane) and dataActions (data plane). Owner on a storage account does not grant blob reads; you need Storage Blob Data Reader or a key. Key Vault, Cosmos and SQL have the same split, and some keep their own legacy access policies alongside.
Regions map
Tile map by geography. Each tile is a country or area; the codes are what az account list-locations returns and what resource IDs carry. Dashed tiles are separate clouds.
fig 3 · geography tiles, not to scale; region count grows every year, verify with the CLI below
| Region | Paired with | Region | Paired with |
|---|---|---|---|
| westeurope | northeurope | eastus | westus |
| uksouth | ukwest | eastus2 | centralus |
| francecentral | francesouth | westus2 | westcentralus |
| germanywestcentral | germanynorth | westus3 | eastus |
| switzerlandnorth | switzerlandwest | northcentralus | southcentralus |
| norwayeast | norwaywest | canadacentral | canadaeast |
| swedencentral | swedensouth | brazilsouth | southcentralus |
| southeastasia | eastasia | australiaeast | australiasoutheast |
| japaneast | japanwest | centralindia | southindia |
| koreacentral | koreasouth | uaenorth | uaecentral |
| southafricanorth | southafricawest | polandcentral, italynorth, spaincentral, israelcentral, qatarcentral, mexicocentral | no pair: availability zones only |
Pairs vs zones Paired regions get sequential platform updates and are the GRS replication target for storage, Key Vault and SQL geo-backups. Newer regions ship with three availability zones and no pair, so cross-region DR there is on you (Site Recovery, geo-replication you configure). Zone numbers (1, 2, 3) are per subscription: zone 1 in your subscription may be zone 2 in another; use az rest on /locations?api-version=2022-12-01 to see the physical mapping.
Identity (Microsoft Entra)
| Service | Endpoint | Protocol | Provider / CLI | Notes |
|---|---|---|---|---|
| Entra ID token endpoint | login.microsoftonline.com/{tenant}/oauth2/v2.0/token | OAuth 2.0 / OIDC | az login | {tenant} = GUID, domain, common, organizations, consumers |
| OIDC discovery | login.microsoftonline.com/{tenant}/v2.0/.well-known/openid-configuration | JSON | JWKS at /discovery/v2.0/keys | |
| Device code sign-in | microsoft.com/devicelogin | HTML | az login –use-device-code | legitimate flow, also a phishing favourite: watch for it in sign-in logs |
| Microsoft Graph | graph.microsoft.com/v1.0 graph.microsoft.com/beta | REST JSON | az ad / az rest | users, groups, service principals, sign-in logs, Conditional Access, Intune |
| Azure AD Graph (legacy) | graph.windows.net | REST | retired 2025; migrate to Microsoft Graph | |
| Entra admin center | entra.microsoft.com | HTML | also aad.portal.azure.com (redirects) | |
| Entra External ID (CIAM) | {tenant}.ciamlogin.com | OIDC | successor to B2C for new tenants | |
| Azure AD B2C | {tenant}.b2clogin.com | OIDC | closed to new customers since May 2025 | |
| Entra Domain Services | (LDAP/Kerberos inside the VNet) | LDAP 389/636, Kerberos 88 | Microsoft.AAD/domainServices | managed AD, no domain admin |
| Managed identities | (IMDS or IDENTITY_ENDPOINT) | HTTP | Microsoft.ManagedIdentity/userAssignedIdentities | system-assigned lives and dies with the resource |
| Workload identity federation | login.microsoftonline.com (client_assertion) | OIDC | az ad app federated-credential | GitHub Actions, AKS, Terraform Cloud without secrets |
| RBAC | management.azure.com | ARM | Microsoft.Authorization/roleAssignments | role assignment is itself a resource with an ID |
| PIM | graph.microsoft.com/v1.0/roleManagement | REST | eligible vs active assignments | |
| Entra Connect / Cloud Sync | *.msappproxy.net, login.microsoftonline.com | HTTPS | hybrid sync agents |
Compute
| Service | Resource provider / type | Data-plane hostname | CLI | Notes |
|---|---|---|---|---|
| Virtual Machines | Microsoft.Compute/virtualMachines | {label}.{region}.cloudapp.azure.com | az vm | DNS label is on the public IP, not the VM |
| VM Scale Sets | Microsoft.Compute/virtualMachineScaleSets | az vmss | Flexible orchestration is the default | |
| Managed disks, snapshots, images | Microsoft.Compute/disks, snapshots, galleries | az disk / az sig | Compute Gallery for image versions | |
| App Service / Functions | Microsoft.Web/sites | {app}.azurewebsites.net {app}.scm.azurewebsites.net (Kudu) {app}-{hash}.{region}-01.azurewebsites.net | az webapp / az functionapp | the unique default hostname form is used for apps created since 2024 |
| Static Web Apps | Microsoft.Web/staticSites | {name}.{n}.azurestaticapps.net | az staticwebapp | |
| Container Apps | Microsoft.App/containerApps | {app}.{env-hash}.{region}.azurecontainerapps.io | az containerapp | KEDA, Dapr, built on AKS |
| Batch | Microsoft.Batch/batchAccounts | {acct}.{region}.batch.azure.com | az batch | |
| Azure Virtual Desktop | Microsoft.DesktopVirtualization/hostPools | rdweb.wvd.microsoft.com client.wvd.microsoft.com | az desktopvirtualization | session hosts reach *.wvd.microsoft.com on 443 |
| Spring Apps | Microsoft.AppPlatform/Spring | {svc}-{app}.azuremicroservices.io | az spring | retiring 2028 (Basic/Standard), move to Container Apps |
| Service Fabric | Microsoft.ServiceFabric/clusters | {cluster}.{region}.cloudapp.azure.com:19080 | az sf | managed clusters: Microsoft.ServiceFabric/managedClusters |
| Dedicated Hosts | Microsoft.Compute/hostGroups | az vm host | ||
| Azure Arc servers | Microsoft.HybridCompute/machines | *.his.arc.azure.com, gbl.his.arc.azure.com *.guestconfiguration.azure.com | az connectedmachine | agent needs these plus login and management hosts |
Containers
| Service | Resource provider / type | Data-plane hostname | CLI | Notes |
|---|---|---|---|---|
| AKS | Microsoft.ContainerService/managedClusters | {dnsprefix}-{hash}.hcp.{region}.azmk8s.io {hash}.privatelink.{region}.azmk8s.io (private) | az aks | node resource group MC_{rg}_{cluster}_{region} is auto-created |
| AKS egress (nodes) | mcr.microsoft.com, *.data.mcr.microsoft.com packages.microsoft.com, acs-mirror.azureedge.net *.hcp.{region}.azmk8s.io:443,9000 login.microsoftonline.com, management.azure.com | required outbound list; use AzureKubernetesService FQDN tag on Azure Firewall | ||
| Container Registry | Microsoft.ContainerRegistry/registries | {reg}.azurecr.io {reg}.{region}.data.azurecr.io (data endpoint) | az acr | dedicated data endpoints need a second FQDN in firewalls |
| Container Instances | Microsoft.ContainerInstance/containerGroups | {label}.{region}.azurecontainer.io | az container | |
| Container Apps | Microsoft.App/containerApps, managedEnvironments | see Compute | az containerapp | |
| Microsoft Container Registry (public) | mcr.microsoft.com | Microsoft base images; anonymous pull | ||
| Arc-enabled Kubernetes | Microsoft.Kubernetes/connectedClusters | *.{region}.arcdataservices.com, *.servicebus.windows.net | az connectedk8s | |
| Red Hat OpenShift (ARO) | Microsoft.RedHatOpenShift/openShiftClusters | api.{domain}.{region}.aroapp.io | az aro |
# Registry login (exchanges your Entra token for an ACR refresh token) az acr login --name myreg # Login without Docker, for example to feed a CI step az acr login --name myreg --expose-token --query accessToken -o tsv # kubeconfig; with Entra integration kubectl uses kubelogin az aks get-credentials -g rg-prod -n aks-prod kubelogin convert-kubeconfig -l azurecli # Required egress FQDNs for a given cluster az aks egress-endpoints list -g rg-prod -n aks-prod -o table
Storage
| Service | Hostname | Port / protocol | CLI | Notes |
|---|---|---|---|---|
| Blob | {acct}.blob.core.windows.net | 443 REST | az storage blob | containers, block/page/append blobs, versioning, immutability |
| Data Lake Storage Gen2 | {acct}.dfs.core.windows.net | 443 REST (ABFS) | az storage fs | hierarchical namespace on the same account; both endpoints serve the same data |
| Files | {acct}.file.core.windows.net | 445 SMB 3.x, 2049 NFS 4.1, 443 REST | az storage file / share | many ISPs block 445: use VPN or Private Endpoint |
| Queue | {acct}.queue.core.windows.net | 443 REST | az storage queue | simple queue; Service Bus for anything richer |
| Table | {acct}.table.core.windows.net | 443 REST (OData) | az storage table | Cosmos Table API shares the SDK |
| Static website | {acct}.z{nn}.web.core.windows.net | 443 | az storage blob service-properties update –static-website | serves the $web container; put Front Door or CDN in front for custom TLS |
| Secondary (RA-GRS) | {acct}-secondary.blob.core.windows.net | 443 | read-only copy in the paired region | |
| Managed disks | (ARM only) | az disk | Microsoft.Compute, not Microsoft.Storage; disk access via Private Link for export | |
| NetApp Files | (mount target IP in your VNet) | NFS 3/4.1, SMB | az netappfiles | Microsoft.NetApp/netAppAccounts |
| Elastic SAN | (iSCSI target in VNet) | iSCSI 3260 | az elastic-san | |
| Backup / Recovery Services | Microsoft.RecoveryServices/vaults Microsoft.DataProtection/backupVaults | ARM | az backup / az dataprotection | agents reach *.backup.windowsazure.com, *.blob.core.windows.net |
| Storage Mover / Data Box | Microsoft.StorageMover, Microsoft.DataBox | ARM | az storage-mover / az databox | migration |
Account firewall vs Private Endpoint The storage firewall (networkAcls) allows selected VNets and public IPs. A Private Endpoint is per sub-service (one for blob, another for dfs, another for file), each with its own privatelink.* zone. Trusted Microsoft services bypass is a flag, not a default. SAS tokens work through either path.
Database
| Service | Hostname | Port | Provider | Notes |
|---|---|---|---|---|
| SQL Database | {server}.database.windows.net | 1433; redirect mode 11000-11999 | Microsoft.Sql/servers/databases | logical server is a name, not a VM; Entra auth, TDE, ledger |
| SQL Managed Instance | {mi}.{dns-zone}.database.windows.net {mi}.public.{dns-zone}.database.windows.net | 1433 private, 3342 public endpoint | Microsoft.Sql/managedInstances | sits in your VNet; redirect uses 11000-11999 |
| Cosmos DB (NoSQL) | {acct}.documents.azure.com | 443; SDK direct mode 10000-20000 | Microsoft.DocumentDB/databaseAccounts | regional endpoints {acct}-{region}.documents.azure.com |
| Cosmos DB for MongoDB | {acct}.mongo.cosmos.azure.com {cluster}.mongocluster.cosmos.azure.com (vCore) | 10255 / 10260 | Microsoft.DocumentDB | RU and vCore are different products |
| Cosmos DB for Cassandra / Gremlin / Table | {acct}.cassandra.cosmos.azure.com {acct}.gremlin.cosmos.azure.com {acct}.table.cosmos.azure.com | 10350 / 443 / 443 | Microsoft.DocumentDB | |
| Cosmos DB for PostgreSQL (Citus) | c-{cluster}.{hash}.postgres.cosmos.azure.com | 5432 | Microsoft.DBforPostgreSQL/serverGroupsv2 | |
| PostgreSQL flexible server | {server}.postgres.database.azure.com | 5432 | Microsoft.DBforPostgreSQL/flexibleServers | Single Server retired March 2025 |
| MySQL flexible server | {server}.mysql.database.azure.com | 3306 | Microsoft.DBforMySQL/flexibleServers | Single Server retired September 2024 |
| MariaDB | {server}.mariadb.database.azure.com | 3306 | Microsoft.DBforMariaDB | retired September 2025 |
| Cache for Redis | {name}.redis.cache.windows.net | 6380 TLS (6379 off by default) | Microsoft.Cache/redis | Enterprise tier: {name}.{region}.redisenterprise.cache.azure.net:10000 |
| Managed Redis | {name}.{region}.redis.azure.net | 10000 | Microsoft.Cache/redisEnterprise | successor to Enterprise tier, 2025 |
| Data Explorer (Kusto) | {cluster}.{region}.kusto.windows.net ingest-{cluster}.{region}.kusto.windows.net | 443 | Microsoft.Kusto/clusters | KQL engine behind Log Analytics, Sentinel and Fabric Real-Time |
| SQL on VMs | (your VM) | 1433 | Microsoft.SqlVirtualMachine | IaaS agent extension for backup and patching |
Networking and delivery
| Service | Resource type | Hostname / address | Notes |
|---|---|---|---|
| Virtual Network, subnets, peering | Microsoft.Network/virtualNetworks | first 4 + last IP of each subnet reserved | DNS at 168.63.129.16; .1 is the gateway |
| Platform IP (DNS, DHCP, health probes) | 168.63.129.16 | never block it; appears as the Load Balancer probe source and the Wire Server | |
| Instance metadata | 169.254.169.254 | needs header Metadata: true; no proxy | |
| NSG / ASG | Microsoft.Network/networkSecurityGroups | service tags, not IPs | default rules allow VNet and LB inbound, Internet outbound |
| Load Balancer (L4) | Microsoft.Network/loadBalancers | public IP or internal frontend | Standard SKU is zone-redundant and secure by default |
| Application Gateway (L7, WAF) | Microsoft.Network/applicationGateways | {label}.{region}.cloudapp.azure.com | regional; v2 needs a dedicated /24 subnet |
| Front Door (global L7, CDN, WAF) | Microsoft.Cdn/profiles (Standard/Premium) | {endpoint}-{hash}.z01.azurefd.net | Private Link to origins on Premium; anycast edge |
| CDN (classic) | Microsoft.Cdn/profiles | {endpoint}.azureedge.net | Edgio profiles retired January 2025; Microsoft classic retires 2027, move to Front Door |
| Traffic Manager (DNS) | Microsoft.Network/trafficmanagerprofiles | {profile}.trafficmanager.net | DNS-level routing; no proxying |
| Azure DNS (public zones) | Microsoft.Network/dnszones | ns1-0x.azure-dns.com / .net / .org / .info | four name servers per zone, alias records to public IPs |
| Private DNS zones | Microsoft.Network/privateDnsZones | linked to VNets | auto-registration for VM names; home of privatelink.* |
| DNS Private Resolver | Microsoft.Network/dnsResolvers | inbound / outbound endpoints in subnets | conditional forwarding to on-premises |
| Azure Firewall | Microsoft.Network/azureFirewalls | subnet AzureFirewallSubnet /26 | FQDN tags, IDPS on Premium, forced tunnelling |
| Bastion | Microsoft.Network/bastionHosts | bst-{id}.bastion.azure.com | subnet AzureBastionSubnet /26; native client needs Standard SKU |
| VPN Gateway | Microsoft.Network/virtualNetworkGateways | subnet GatewaySubnet | IKEv2, OpenVPN P2S; Entra auth for P2S |
| ExpressRoute | Microsoft.Network/expressRouteCircuits | Microsoft peering uses public prefixes | private peering reaches VNets; Microsoft peering reaches PaaS |
| Virtual WAN | Microsoft.Network/virtualWans, virtualHubs | managed hub-and-spoke | |
| NAT Gateway | Microsoft.Network/natGateways | static outbound IPs | default outbound access is being removed for new VNets (2025) |
| Public IP | Microsoft.Network/publicIPAddresses | {label}.{region}.cloudapp.azure.com | Standard SKU only for new work; Basic retires September 2025 |
| DDoS Protection | Microsoft.Network/ddosProtectionPlans | Network Protection (plan) or IP Protection (per IP) | |
| Network Watcher | Microsoft.Network/networkWatchers | NetworkWatcherRG | flow logs, packet capture, connection monitor |
| Service tag | Covers | Service tag | Covers |
|---|---|---|---|
| VirtualNetwork | VNet, peered VNets, on-premises via gateway | AzureResourceManager | management.azure.com |
| Internet | everything outside the VNet, including Azure public IPs | AzureActiveDirectory | login.microsoftonline.com and Graph |
| AzureLoadBalancer | 168.63.129.16 health probes | AzureMonitor | Log Analytics, App Insights ingestion |
| AzureCloud, AzureCloud.{region} | all Azure public IPs | AzureKeyVault, Sql, AzureCosmosDB | PaaS data planes, regional variants exist |
| Storage, Storage.{region} | storage account IPs | AzureContainerRegistry | registry endpoints; MCR is MicrosoftContainerRegistry |
| AzureFrontDoor.Backend | Front Door egress to your origin | AzureBastion, GatewayManager | needed in Bastion and gateway subnet NSGs |
| ServiceBus, EventHub | messaging namespaces | AzureUpdateDelivery, AzureKubernetesService | FQDN tags for Azure Firewall only |
Private Link and DNS
A Private Endpoint puts a NIC with a private IP into your subnet for one PaaS resource. The public FQDN keeps working; a CNAME layer decides whether the client gets the public or the private address.
fig 4 · the same FQDN resolves publicly or privately depending on who asks; the privatelink zone is the switch
| Resource | Sub-resource (groupId) | Private DNS zone |
|---|---|---|
| Storage | blob, dfs, file, queue, table, web | privatelink.blob.core.windows.net (one zone per sub-resource) |
| SQL Database / MI | sqlServer / managedInstance | privatelink.database.windows.net privatelink.{dns-zone}.database.windows.net |
| Cosmos DB | Sql, MongoDB, Cassandra, Gremlin, Table | privatelink.documents.azure.com (and per API) |
| PostgreSQL / MySQL flexible | postgresqlServer / mysqlServer | privatelink.postgres.database.azure.com privatelink.mysql.database.azure.com |
| Key Vault / Managed HSM | vault / managedhsm | privatelink.vaultcore.azure.net privatelink.managedhsm.azure.net |
| Container Registry | registry | privatelink.azurecr.io (plus {region}.data records) |
| AKS (private cluster) | management | privatelink.{region}.azmk8s.io |
| App Service / Functions | sites | privatelink.azurewebsites.net (also scm.privatelink…) |
| Service Bus / Event Hubs / Relay | namespace | privatelink.servicebus.windows.net |
| Event Grid | topic, domain | privatelink.eventgrid.azure.net |
| Cache for Redis | redisCache | privatelink.redis.cache.windows.net |
| Azure OpenAI / AI Services | account | privatelink.openai.azure.com privatelink.cognitiveservices.azure.com privatelink.services.ai.azure.com |
| AI Search | searchService | privatelink.search.windows.net |
| Monitor (AMPLS) | azuremonitor | privatelink.monitor.azure.com, privatelink.oms.opinsights.azure.com, privatelink.ods.opinsights.azure.com, privatelink.agentsvc.azure-automation.net, privatelink.blob.core.windows.net |
| Data Factory / Synapse | dataFactory / Sql, Dev | privatelink.datafactory.azure.net privatelink.sql.azuresynapse.net, privatelink.dev.azuresynapse.net |
| Backup (Recovery Services) | AzureBackup | privatelink.{region}.backup.windowsazure.com |
| App Configuration | configurationStores | privatelink.azconfig.io |
| IoT Hub | iotHub | privatelink.azure-devices.net |
Service Endpoints are not Private Link A VNet service endpoint (Microsoft.Storage on a subnet) keeps the public IP and public DNS but routes over the backbone and lets the resource firewall allow that subnet. Private Link gives you a private IP and works from on-premises. Use service endpoints only where Private Link is unavailable or the cost matters.
Security, compliance and secrets
| Service | Resource provider / type | Hostname | Notes |
|---|---|---|---|
| Key Vault | Microsoft.KeyVault/vaults | {vault}.vault.azure.net | keys, secrets, certs; RBAC permission model is the default since 2024; soft delete and purge protection |
| Managed HSM | Microsoft.KeyVault/managedHSMs | {name}.managedhsm.azure.net | FIPS 140-3 Level 3, single-tenant; local RBAC |
| Defender for Cloud (CSPM, CWP) | Microsoft.Security/pricings, assessments, alerts | management.azure.com | plans per subscription; MDE integration; regulatory compliance dashboard |
| Microsoft Sentinel | Microsoft.SecurityInsights (on a Log Analytics workspace) | management.azure.com | SIEM/SOAR on Log Analytics; unified portal at security.microsoft.com |
| Defender XDR / Security Graph | Microsoft Graph security API | graph.microsoft.com/v1.0/security | alerts_v2, incidents, advanced hunting (runHuntingQuery) |
| Azure Policy | Microsoft.Authorization/policyDefinitions, policyAssignments Microsoft.PolicyInsights | management.azure.com | effects: audit, deny, deployIfNotExists, modify, denyAction; built-ins in az policy definition list |
| Resource locks | Microsoft.Authorization/locks | CanNotDelete, ReadOnly; inherited | |
| Microsoft Purview | Microsoft.Purview/accounts | {acct}.purview.azure.com purview.microsoft.com | data governance; compliance portal for DLP, retention, audit |
| Attestation | Microsoft.Attestation/attestationProviders | {name}.{region}.attest.azure.net shared{region}.{region}.attest.azure.net | confidential VMs, SGX enclaves |
| Confidential Ledger | Microsoft.ConfidentialLedger/ledgers | {name}.confidential-ledger.azure.com | tamper-proof log on CCF |
| Dedicated HSM | Microsoft.HardwareSecurityModules | (in your VNet) | Thales Luna, you administer it |
| Web Application Firewall | Microsoft.Network/FrontDoorWebApplicationFirewallPolicies Microsoft.Network/ApplicationGatewayWebApplicationFirewallPolicies | same rule sets (DRS, OWASP CRS), two attach points | |
| Entra ID Protection / Conditional Access | Graph identityProtection, identity/conditionalAccess | graph.microsoft.com | risk-based policies, sign-in risk events |
| Microsoft Defender for Identity / Endpoint | (M365 licensing) | *.atp.azure.com, *.securitycenter.windows.com, security.microsoft.com | agents, not ARM resources |
| Activity Log | Microsoft.Insights/eventtypes/management | management.azure.com | 90 days free; export to Log Analytics with a diagnostic setting at subscription scope |
Where the logs are Control plane: Activity Log (AzureActivity table). Identity: Entra sign-in and audit logs via diagnostic settings on the tenant (SigninLogs, AuditLogs). Data plane: per-resource diagnostic settings (StorageBlobLogs, AzureDiagnostics or resource-specific tables). Nothing data-plane is logged until you turn it on.
Observability
| Service | Resource type | Hostname | Notes |
|---|---|---|---|
| Log Analytics workspace | Microsoft.OperationalInsights/workspaces | {ws-id}.ods.opinsights.azure.com (ingest) {ws-id}.oms.opinsights.azure.com (agent) api.loganalytics.azure.com (query) | KQL; one workspace per region/tenant boundary is the usual design |
| Azure Monitor Agent, DCR, DCE | Microsoft.Insights/dataCollectionRules, dataCollectionEndpoints | {dce}-{hash}.{region}.ingest.monitor.azure.com {dce}-{hash}.{region}.handler.control.monitor.azure.com global.handler.control.monitor.azure.com | AMA replaced the Log Analytics agent (MMA retired August 2024) |
| Logs Ingestion API | (DCE + DCR) | POST {dce}/dataCollectionRules/{dcr-id}/streams/Custom-{table}?api-version=2023-01-01 | custom tables; audience https://monitor.azure.com |
| Application Insights | Microsoft.Insights/components | {region}.in.applicationinsights.azure.com (ingest) {region}.livediagnostics.monitor.azure.com (live metrics) api.applicationinsights.io (query) | workspace-based; connection string carries the regional endpoints |
| Metrics | Microsoft.Insights/metricDefinitions | management.azure.com/…/providers/Microsoft.Insights/metrics {region}.metrics.monitor.azure.com (data plane) | platform metrics are free, 93 days |
| Managed Prometheus | Microsoft.Monitor/accounts | {name}-{hash}.{region}.prometheus.monitor.azure.com | remote write and PromQL query |
| Managed Grafana | Microsoft.Dashboard/grafana | {name}-{hash}.{region}.grafana.azure.com | Entra sign-in, managed identity to data sources |
| Alerts and action groups | Microsoft.Insights/metricAlerts, scheduledQueryRules, actionGroups | webhook payloads use the common alert schema | |
| Diagnostic settings | Microsoft.Insights/diagnosticSettings | (extension resource on any resource) | up to 5 per resource; targets: workspace, storage, Event Hub, partner |
| Service Health / Resource Health | Microsoft.ResourceHealth | status.azure.com | alerts via action groups |
| Change Analysis / Resource Graph | Microsoft.ResourceGraph | management.azure.com/providers/Microsoft.ResourceGraph/resources | KQL over your inventory, cross-subscription |
# Query a workspace with KQL from the CLI az monitor log-analytics query -w $WS_ID --analytics-query \ "AzureActivity | where TimeGenerated > ago(1d) | summarize count() by OperationNameValue | top 10 by count_" # Resource Graph: every public IP across all subscriptions you can see az graph query -q "Resources | where type == 'microsoft.network/publicipaddresses' | project name, properties.ipAddress, subscriptionId" -o table # Send Activity Log of a subscription to a workspace az monitor diagnostic-settings subscription create --name to-law \ --location westeurope --workspace $WS_RESOURCE_ID \ --logs '[{"category":"Administrative","enabled":true},{"category":"Security","enabled":true},{"category":"Policy","enabled":true}]'
Messaging and integration
| Service | Resource type | Hostname | Port / protocol | Notes |
|---|---|---|---|---|
| Service Bus | Microsoft.ServiceBus/namespaces | {ns}.servicebus.windows.net | 5671 AMQP, 443 AMQP-over-WebSockets | queues, topics, sessions, dead-letter; Premium for Private Link and VNet |
| Event Hubs | Microsoft.EventHub/namespaces | {ns}.servicebus.windows.net | 5671 AMQP, 9093 Kafka, 443 | Kafka-compatible; Capture to storage; Schema Registry |
| Event Grid | Microsoft.EventGrid/topics, systemTopics, domains, namespaces | {topic}.{region}-1.eventgrid.azure.net {ns}.{region}-1.ts.eventgrid.azure.net (MQTT) | 443 HTTPS push, 8883 MQTT | CloudEvents 1.0; system topics for Azure resource events |
| Relay | Microsoft.Relay/namespaces | {ns}.servicebus.windows.net | 443 WebSocket | expose on-premises endpoints without inbound ports |
| Notification Hubs | Microsoft.NotificationHubs | {ns}.servicebus.windows.net | 443 | APNs, FCM fan-out |
| Logic Apps | Microsoft.Logic/workflows (Consumption) Microsoft.Web/sites kind=workflowapp (Standard) | prod-{nn}.{region}.logic.azure.com (triggers) | 443 | connectors egress from published regional IP ranges |
| API Management | Microsoft.ApiManagement/service | {name}.azure-api.net (gateway) {name}.management.azure-api.net {name}.developer.azure-api.net {name}.configuration.azure-api.net | 443; 3443 management inbound | self-hosted gateway pulls config from configuration endpoint |
| SignalR Service | Microsoft.SignalRService/signalR | {name}.service.signalr.net | 443 WebSocket | |
| Web PubSub | Microsoft.SignalRService/webPubSub | {name}.webpubsub.azure.com | 443 WebSocket | Socket.IO support |
| IoT Hub | Microsoft.Devices/IotHubs | {hub}.azure-devices.net | 8883 MQTT, 5671 AMQP, 443 | Event Hub-compatible endpoint for consumers |
| Device Provisioning Service | Microsoft.Devices/provisioningServices | global.azure-devices-provisioning.net | 8883, 443 | global endpoint, ID scope selects the instance |
| Digital Twins | Microsoft.DigitalTwins/digitalTwinsInstances | {inst}.api.{region}.digitaltwins.azure.net | 443 | |
| Communication Services | Microsoft.Communication/communicationServices | {name}.{region}.communication.azure.com | 443 | SMS, email, voice, chat |
| Azure Functions triggers | Microsoft.Web/sites kind=functionapp | {app}.azurewebsites.net/api/{fn} | 443 | Flex Consumption plan since 2024 |
Data, analytics and AI
| Service | Resource type | Hostname | Notes |
|---|---|---|---|
| Azure OpenAI | Microsoft.CognitiveServices/accounts kind=OpenAI | {resource}.openai.azure.com/openai/deployments/{deployment}/chat/completions?api-version=… | deployment name, not model name, in the path; v1 API at /openai/v1/ since 2025 |
| AI Services (multi-service) | Microsoft.CognitiveServices/accounts kind=AIServices | {resource}.cognitiveservices.azure.com {resource}.services.ai.azure.com | Vision, Language, Speech, Document Intelligence, Content Safety |
| Speech | Microsoft.CognitiveServices/accounts kind=SpeechServices | {region}.stt.speech.microsoft.com {region}.tts.speech.microsoft.com {region}.api.cognitive.microsoft.com | WebSocket for streaming |
| AI Foundry (hub, project) | Microsoft.MachineLearningServices/workspaces kind=Hub, Project Microsoft.CognitiveServices/accounts/projects (new) | ai.azure.com {name}.services.ai.azure.com/api/projects/{project} | Agent Service, evaluations, model catalog |
| AI Search | Microsoft.Search/searchServices | {svc}.search.windows.net | vector, hybrid, semantic ranker; api-key or RBAC |
| Machine Learning | Microsoft.MachineLearningServices/workspaces | {region}.api.azureml.ms {ws-id}.workspace.{region}.api.azureml.ms {endpoint}.{region}.inference.ml.azure.com | managed online endpoints for inference |
| Synapse Analytics | Microsoft.Synapse/workspaces | {ws}.dev.azuresynapse.net {ws}.sql.azuresynapse.net (dedicated) {ws}-ondemand.sql.azuresynapse.net (serverless) | SQL on 1433; Spark pools; being superseded by Fabric |
| Microsoft Fabric | Microsoft.Fabric/capacities | api.fabric.microsoft.com app.fabric.microsoft.com onelake.dfs.fabric.microsoft.com | OneLake speaks the ADLS Gen2 API; capacity is the only ARM resource |
| Power BI | (tenant-level) | api.powerbi.com app.powerbi.com | Fabric workloads now |
| Databricks | Microsoft.Databricks/workspaces | adb-{workspace-id}.{n}.azuredatabricks.net | control plane egress list per region; secure cluster connectivity |
| Data Factory | Microsoft.DataFactory/factories | {df}.{region}.datafactory.azure.net adf.azure.com | self-hosted IR reaches *.servicebus.windows.net and *.frontend.clouddatahub.net |
| Data Explorer | Microsoft.Kusto/clusters | see Database | also dataexplorer.azure.com web UI |
| Stream Analytics | Microsoft.StreamAnalytics/streamingjobs | inputs from Event Hubs, IoT Hub, blob | |
| HDInsight | Microsoft.HDInsight/clusters | {cluster}.azurehdinsight.net {cluster}-ssh.azurehdinsight.net | Hadoop, Spark, Kafka, HBase |
| Azure Maps | Microsoft.Maps/accounts | atlas.microsoft.com | |
| Bot Service | Microsoft.BotService/botServices | directline.botframework.com {bot}.azurewebsites.net/api/messages | |
| Document Intelligence / Content Safety / Translator | Microsoft.CognitiveServices/accounts | {resource}.cognitiveservices.azure.com api.cognitive.microsofttranslator.com | Translator has a global endpoint plus regional ones |
Developer tools and IaC
| Service | Resource type | Hostname | Notes |
|---|---|---|---|
| Azure DevOps | (not ARM; Microsoft.VisualStudio/account is a billing link) | dev.azure.com/{org} {org}.visualstudio.com (legacy) vssps.dev.azure.com (auth), vsrm.dev.azure.com (releases) pkgs.dev.azure.com (Artifacts), vstmr.dev.azure.com (tests) | agents need *.dev.azure.com, *.vsassets.io, *.vstmrblob.vsassets.io |
| GitHub (Enterprise Cloud) | github.com, api.github.com {org}.ghe.com (data residency) | OIDC to Azure via workload identity federation | |
| ARM templates, Bicep | Microsoft.Resources/deployments | management.azure.com | deployment scopes: resource group, subscription, management group, tenant; Bicep compiles to ARM JSON |
| Deployment Stacks | Microsoft.Resources/deploymentStacks | lifecycle-managed deployments, successor to Blueprints (retired July 2026) | |
| Template specs | Microsoft.Resources/templateSpecs | versioned templates as resources | |
| Bicep registry | (ACR) | mcr.microsoft.com/bicep/avm/… | Azure Verified Modules |
| Terraform azurerm / azapi | management.azure.com | azapi covers resources azurerm has not wrapped; state usually in blob with lease locking | |
| App Configuration | Microsoft.AppConfiguration/configurationStores | {name}.azconfig.io | feature flags, Key Vault references |
| Automation | Microsoft.Automation/automationAccounts | {region}-jobruntimedata-prod-su1.azure-automation.net {region}-agentservice-prod-1.azure-automation.net | runbooks, DSC, Hybrid Worker |
| Update Manager | Microsoft.Maintenance/maintenanceConfigurations | replaced Automation Update Management (August 2024) | |
| Dev Box / Deployment Environments | Microsoft.DevCenter/devcenters | {hash}-{devcenter}.{region}.devcenter.azure.com | |
| Load Testing | Microsoft.LoadTestService/loadTests | {id}.{region}.cnt-prod.loadtesting.azure.com | JMeter, Locust |
| Chaos Studio | Microsoft.Chaos/experiments | fault injection with agent or service-direct faults | |
| Cloud Shell | (storage account you own) | shell.azure.com | ephemeral sessions since 2024 need no storage |
Management, billing and support
| Service | Resource provider / path | Hostname | Notes |
|---|---|---|---|
| Portal | portal.azure.com preview.portal.azure.com | also *.portal.azure.net, *.hosting.portal.azure.net for extensions | |
| Cost Management | Microsoft.CostManagement/query, exports Microsoft.Consumption/usageDetails | management.azure.com | FOCUS-format exports to storage; budgets with action groups |
| Billing accounts (EA, MCA) | Microsoft.Billing/billingAccounts | management.azure.com | invoice sections, billing profiles; Partner Center for CSP |
| Advisor | Microsoft.Advisor/recommendations | cost, security, reliability, performance, operational excellence | |
| Quotas | Microsoft.Quota/quotas Microsoft.Compute/usages | az quota; vCPU quotas per family per region | |
| Support | Microsoft.Support/supportTickets | needs a support plan for technical cases | |
| Lighthouse | Microsoft.ManagedServices/registrationDefinitions | cross-tenant delegated management for MSPs | |
| Managed Applications | Microsoft.Solutions/applications | publisher-managed resource groups | |
| Marketplace | Microsoft.Marketplace, MarketplaceOrdering/agreements | azuremarketplace.microsoft.com | accept terms before deploying third-party images |
| Resource Mover / Migrate / Site Recovery | Microsoft.Migrate, Microsoft.RecoveryServices | *.hypervrecoverymanager.windowsazure.com | |
| Tags | Microsoft.Resources/tags (extension) | 50 tag pairs per resource; inherit with Policy modify | |
| Azure mobile app / Copilot in Azure | portal.azure.com |
Resource ID anatomy and providers
# /subscriptions/{sub}/resourceGroups/{rg}/providers/{namespace}/{type}/{name}[/{childType}/{childName}] # Case-insensitive on input, but the stored casing is what Resource Graph returns /subscriptions/0000-.../resourceGroups/rg-prod/providers/Microsoft.Compute/virtualMachines/vm-web-01 /subscriptions/0000-.../resourceGroups/rg-net/providers/Microsoft.Network/virtualNetworks/vnet-hub/subnets/snet-pe /subscriptions/0000-.../resourceGroups/rg-data/providers/Microsoft.Storage/storageAccounts/stprod001 /subscriptions/0000-.../resourceGroups/rg-sec/providers/Microsoft.KeyVault/vaults/kv-prod /subscriptions/0000-.../resourceGroups/rg-aks/providers/Microsoft.ContainerService/managedClusters/aks-prod # Subscription-level and tenant-level resources /subscriptions/0000-.../providers/Microsoft.Authorization/roleAssignments/{guid} /subscriptions/0000-.../providers/Microsoft.Authorization/policyAssignments/{name} /providers/Microsoft.Management/managementGroups/mg-landingzones /providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c # Contributor, built-in # Extension resources hang off any other resource ID .../storageAccounts/stprod001/providers/Microsoft.Insights/diagnosticSettings/to-law .../storageAccounts/stprod001/providers/Microsoft.Authorization/locks/no-delete .../storageAccounts/stprod001/providers/Microsoft.Authorization/roleAssignments/{guid}
| Namespace | Service family | Namespace | Service family |
|---|---|---|---|
| Microsoft.Compute | VMs, VMSS, disks, galleries | Microsoft.Network | everything network: VNet, LB, AppGW, DNS, firewall, PE |
| Microsoft.Storage | storage accounts | Microsoft.KeyVault | vaults, managed HSMs |
| Microsoft.Sql | SQL DB, MI | Microsoft.DocumentDB | Cosmos DB |
| Microsoft.DBforPostgreSQL / DBforMySQL | flexible servers | Microsoft.Cache | Redis |
| Microsoft.Web | App Service, Functions, Logic Apps Standard, Static Web Apps | Microsoft.App | Container Apps |
| Microsoft.ContainerService | AKS | Microsoft.ContainerRegistry | ACR |
| Microsoft.Authorization | RBAC, Policy, locks | Microsoft.Resources | deployments, resource groups, tags |
| Microsoft.Management | management groups | Microsoft.ManagedIdentity | user-assigned identities |
| Microsoft.OperationalInsights | Log Analytics | Microsoft.Insights | Monitor: metrics, alerts, diagnostic settings, App Insights, DCR |
| Microsoft.Security | Defender for Cloud | Microsoft.SecurityInsights | Sentinel |
| Microsoft.EventHub / ServiceBus / EventGrid | messaging | Microsoft.Logic / ApiManagement | integration |
| Microsoft.CognitiveServices | AI Services, Azure OpenAI | Microsoft.MachineLearningServices | ML, AI Foundry hubs |
| Microsoft.DataFactory / Synapse / Databricks / Kusto | data platforms | Microsoft.Fabric | Fabric capacities |
| Microsoft.Cdn | Front Door Standard/Premium, CDN | Microsoft.Devices | IoT Hub, DPS |
| Microsoft.HybridCompute / Kubernetes | Arc servers, Arc Kubernetes | Microsoft.RecoveryServices / DataProtection | Backup, Site Recovery |
| Microsoft.PolicyInsights | compliance state, remediation | Microsoft.CostManagement / Consumption / Billing | money |
Providers must be registered A subscription starts with most namespaces unregistered. az provider register -n Microsoft.ContainerService once per subscription, or let the portal do it on first use. Terraform registers a default set unless skip_provider_registration is set. API versions are per resource type; az provider show lists them.
Endpoint discovery and overrides
# Which cloud, which endpoints az cloud list -o table az cloud show --query endpoints az cloud show --query suffixes # Regions with pairs, geography and zone support az account list-locations --query "[?metadata.regionType=='Physical'].{name:name, geo:metadata.geographyGroup, pair:metadata.pairedRegion[0].name, zones:availabilityZoneMappings[].logicalZone}" -o table # Resource providers: registered state and API versions for a type az provider list --query "[].{ns:namespace, state:registrationState}" -o table az provider show -n Microsoft.Compute --query "resourceTypes[?resourceType=='virtualMachines'].{api:apiVersions[0], regions:locations | length(@)}" # Where a resource lives and its exact ID az resource show --ids "/subscriptions/.../providers/Microsoft.Storage/storageAccounts/stprod001" --query "{id:id, loc:location, kind:kind}" az storage account show -n stprod001 --query "primaryEndpoints" # Service tag IP ranges for firewall rules (also the weekly JSON download) az network list-service-tags --location westeurope --query "values[?name=='Storage.WestEurope'].properties.addressPrefixes[]" -o tsv # Private Link sub-resources a resource type supports, and the zone names az network private-link-resource list --type Microsoft.Storage/storageAccounts -g rg-data -n stprod001 az network private-endpoint-connection list --type Microsoft.Storage/storageAccounts -g rg-data -n stprod001 # See the real HTTP calls the CLI makes az vm list --debug 2>&1 | grep -E "Request URL|api-version" # Who am I, which tenant, which subscription az account show --query "{user:user.name, tenant:tenantId, sub:id}" az ad signed-in-user show --query "{upn:userPrincipalName, id:id}"
# Override endpoints for a sovereign cloud or Azure Stack Hub az cloud register -n MyStack --endpoint-resource-manager "https://management.local.azurestack.external" \ --suffix-storage-endpoint "local.azurestack.external" --suffix-keyvault-dns ".vault.local.azurestack.external" az cloud set -n MyStack # SDK: point at a different cloud (Python) from azure.identity import AzureAuthorityHosts, DefaultAzureCredential cred = DefaultAzureCredential(authority=AzureAuthorityHosts.AZURE_GOVERNMENT) # client = ResourceManagementClient(cred, sub, base_url="https://management.usgovcloudapi.net", # credential_scopes=["https://management.usgovcloudapi.net/.default"]) # Azurite / local emulators: Storage, Cosmos, Event Hubs, Service Bus all have one export AZURE_STORAGE_CONNECTION_STRING="UseDevelopmentStorage=true" # Azurite on 10000-10002 # Terraform provider: cloud selection provider "azurerm" { environment = "usgovernment" # public | usgovernment | china features {} }
Throttling ARM limits reads to 12,000 per hour per subscription and writes to 1,200; most resource providers add their own. The response headers x-ms-ratelimit-remaining-subscription-reads and Retry-After tell you where you stand. Resource Graph is the answer for inventory at scale, not looping az resource list.
0 comments