https://support.microsoft.com/en-us/help/4073225/guidance-pr...
https://support.microsoft.com/en-us/help/4073225/guidance-pr...
If your server is not reachable from untrusted sources, and you are running only what you trust, it is prudent to disable mitigation’s and make use of the extra performance.
Example, I run many compute nodes (only private network) in my HPC cluster with mitigation’s off. If an attacker could reach the compute nodes over the network to push the attack payload, I’ve already been heavily compromised that these attacks are just insult to the injury.
If you run a database server that can never be reached directly by an attacker. You may spend your time watching your application server and let the DB server use the extra oomph.
Naturally, everyone must determine their level of risk aversion and take the steps they feel most prudent. I've not heard this perspective before. Thank you for sharing!
Microsoft has deployed mitigations across all our cloud services.
https://docs.microsoft.com/en-us/azure/virtual-machines/wind...