Skip to main content
AD Academy
Cloud Computing: Architecture and Security
Beginner12 minLast updated: Topic 3 of 8

Shared Responsibility Model (Microsoft Azure)

What is always yours, what is always the provider's, and what changes according to the service model.

Not read

What you will learn here

  • Always the customer's responsibility
  • Responsibility varies by service model
  • Always the provider's responsibility

Worth reading first:Service Models: IaaS vs. PaaS vs. SaaS

The Shared Responsibility Model is the foundation of all cloud security: the provider is responsible for the security OF the cloud, and the customer is responsible for security IN the cloud.

A table with responsibility areas as rows and SaaS, PaaS, IaaS and on-prem as columns. The top three rows — information and data, devices, accounts and identities — always stay with the customer in every model. The middle rows vary: identity and directory, applications, network controls and operating system are shared or provider-owned in SaaS/PaaS and customer-owned in IaaS. The bottom rows — physical hosts, physical network and datacenter — belong to the provider in every cloud model and to the customer only on-prem.

Short and clear

  • The provider secures the cloud; the customer secures what runs in the cloud.
  • Always yours: data, devices, accounts and identities — in every service model.
  • Varies by model: OS patching, application configuration and network controls.
  • Always the provider's: the physical datacenter, the physical network and the hypervisors.

Real-life exampleA storage account left public — Azure met every obligation, but the leak is on the customer, because the configuration was theirs.

Always the customer's responsibility

  • Information and data — information, files and sharing settings.
  • Devices — phones and computers connecting to the service.
  • Accounts and identities — accounts, permissions and access control.

Responsibility varies by service model

  • Identity and directory infrastructure — local vs. Entra ID.
  • Application logic & configuration — application logic and its configuration.
  • Network controls — NSG, Firewall, .
  • Operating System patching — customer's responsibility in IaaS, provider's responsibility in PaaS.

Always the provider's responsibility

  • Physical security of the Datacenter, power and cooling.
  • Physical network and fiber optics.
  • Physical servers and Hypervisors.

Check yourself

Who is responsible for securing accounts and identities in the cloud?

In IaaS, who installs security updates for the VM's Operating System?

Was this page helpful?