Skip to main content
AD Academy
Cloud Computing: Architecture and Security
Beginner15 minLast updated: Topic 6 of 8

Cloud Security Controls: Zero Trust, MFA, and Conditional Access

How to protect identities and permissions when there is no physical perimeter.

Not read

What you will learn here

  • Identity Protection Layers
  • Protecting Data and Resources
  • How to protect identities and permissions when there is no physical perimeter.

Worth reading first:Networking in the Cloud: VNet, Subnet, NSG, and On-Premises Connection

In the cloud, there is no firewall — identity is the new perimeter. The Zero Trust principle states: 'Never trust, always verify' — every request is re-evaluated based on user, device, location, and risk, even if it comes from within.

Identity Protection Layers

  • MFA — The foundation; blocks the vast majority of password attacks. Number Matching or FIDO2 is preferred over SMS.
  • Conditional Access — Decision engine: 'If a user is in the Admins group and connects from an unmanaged device — require MFA or block'.
  • RBAC — Role-based permissions on a defined Scope (Subscription / Resource Group / Resource).
  • PIM (Privileged Identity Management) — Just-In-Time permissions: an admin receives the role for two hours with approval and auditing.
  • Identity Protection — Risk scoring based on behavior (Impossible Travel, Leaked Credentials).

Signals on the left: user and group, device state, location and IP, sign-in risk, target application. They all feed the Conditional Access policy engine. On the right the possible outcomes: grant with MFA, require a compliant device, or block access outright. The rule is never trust, always verify. The bottom bar covers privileges after sign-in: RBAC by role, PIM for just-in-time admin rights, and managed identities instead of secrets in code.

Short and clear

  • In the cloud identity is the perimeter — every request is re-verified, even from 'inside'.
  • Conditional Access weighs signals: user, device, location, risk and application.
  • Outcome: allow with MFA, require a compliant device, or block.
  • After sign-in, privileges decide: least-privilege RBAC, time-bound PIM and managed identities.

Real-life exampleAn admin signs in to the Azure portal from a personal laptop abroad and is blocked; from the managed device they pass MFA and elevate for 4 hours through PIM.

Protecting Data and Resources

  • Encryption: At-Rest (Storage Service Encryption) and In-Transit (TLS 1.2+).
  • Key Vault — Managing keys, secrets, and certificates instead of configuration files.
  • Defender for Cloud — Secure Score and Misconfiguration alerts.
  • Managed Identity — Instead of storing a password in the application, the resource itself receives a managed identity.

Check yourself

What does PIM offer that regular RBAC does not?

What is the core principle of Zero Trust?

Was this page helpful?