In the cloud, there is no firewall — identity is the new perimeter. The Zero Trust principle states: 'Never trust, always verify' — every request is re-evaluated based on user, device, location, and risk, even if it comes from within.
Identity Protection Layers
- MFA — The foundation; blocks the vast majority of password attacks. Number Matching or FIDO2 is preferred over SMS.
- Conditional Access — Decision engine: 'If a user is in the Admins group and connects from an unmanaged device — require MFA or block'.
- RBAC — Role-based permissions on a defined Scope (Subscription / Resource Group / Resource).
- PIM (Privileged Identity Management) — Just-In-Time permissions: an admin receives the role for two hours with approval and auditing.
- Identity Protection — Risk scoring based on behavior (Impossible Travel, Leaked Credentials).
Signals on the left: user and group, device state, location and IP, sign-in risk, target application. They all feed the Conditional Access policy engine. On the right the possible outcomes: grant with MFA, require a compliant device, or block access outright. The rule is never trust, always verify. The bottom bar covers privileges after sign-in: RBAC by role, PIM for just-in-time admin rights, and managed identities instead of secrets in code.
Protecting Data and Resources
- Encryption: At-Rest (Storage Service Encryption) and In-Transit (TLS 1.2+).
- Key Vault — Managing keys, secrets, and certificates instead of configuration files.
- Defender for Cloud — Secure Score and Misconfiguration alerts.
- Managed Identity — Instead of storing a password in the application, the resource itself receives a managed identity.