Skip to main content

Security and Governance on Microsoft Azure

Security and governance on Microsoft Azure

If your organisation already runs Microsoft 365, a large part of the identity and detection capability you need is either in the tenant already or one licence tier away. We connect Microsoft Entra ID, Defender, Microsoft Sentinel and Microsoft Intune into a single control set with one owner per control, instead of five products configured by five people at five different times. The first deliverable is usually an entitlement review, because the common finding is unused capability rather than a missing product.

Why Azure

When this is the right platform.

  • Microsoft Entra ID is usually the identity plane for Microsoft 365 already, so access reviews, lifecycle workflows and privileged elevation extend a directory you trust rather than introducing a parallel one to keep in sync.
  • Much of the required capability sits inside entitlements many Microsoft 365 customers already hold. Auditing enabled service plans first often removes the need for new spend in the first phase.
  • Microsoft Defender XDR correlates identity, endpoint, email, SaaS and cloud workload signal into a single investigation, which matters when the security function is two people rather than a rostered team.
  • Azure Policy can remediate as well as block. The deployIfNotExists and modify effects bring existing resources to a required state, which changes the economics of remediation compared with a platform that can only refuse.
  • Conditional Access is the single enforcement point for identity, device health, network location and session risk, and Global Secure Access extends the same decision to internet and private application traffic where a VPN used to sit.

Where it is less suited

We would rather say this now than after a migration.

  • Microsoft security licensing is genuinely complicated. Capability is split across Entra ID P1 and P2, the Entra Suite, several Defender plans, Purview add-ons and the E5 bundle, so it is easy to buy overlapping entitlements or to design a control that needs a tier you do not hold. Treat licensing as a design decision, not an afterthought, and expect at least one control to be re-specified once the entitlement is confirmed.
  • Microsoft Sentinel cost scales with ingestion, and the tiering model has changed more than once. Onboarding every available connector without deciding a tier and retention per table produces a bill that outgrows the value. Log selection is a deliberate exercise repeated as the estate changes, not a one-off configuration.
  • Sentinel now lives in the Microsoft Defender portal, and Microsoft has set 31 March 2027 as the end of support for Sentinel in the Azure portal. That is a straightforward change to work with and you can plan it on your own schedule, but it invalidates bookmarks, screenshots, runbooks and training material, and stale instructions during an incident are a real operational risk rather than a cosmetic one.
  • Conditional access is the strongest control here and the one most capable of locking out your own organisation. Break-glass accounts have to be named, excluded, monitored and actually tested, and any programme that skips the report-only phase will eventually block a legitimate business process at the worst possible moment.
  • Governance across multiple tenants, common after an acquisition, is harder than the single-tenant story suggests. Several controls do not span tenants cleanly, which forces either a consolidation project or duplicated administration for a period, and the duplicated period is usually longer than anyone plans for.
  • Purview classification and loss prevention deploy in weeks and take months to become accurate, because the taxonomy depends on sustained input from data owners. We treat that as a data governance programme with its own budget rather than a task inside a security uplift, and programmes that confuse the two tend to stall at pilot.

Business outcomes

What Azure delivers here.

Privileged access with a time limit
Administrators activate the role they need for the window they need it, with approval and justification recorded. Standing access becomes the exception that needs a written reason rather than the default nobody questions.Agreed measure: Permanent Global Administrator and Owner assignments remaining, counted at each monthly review.
One investigation surface, not five consoles
Analysts and the IT manager work a single incident queue that already correlates identity, endpoint, email and SaaS signal, so the first 20 minutes of an investigation are not spent assembling context by hand.Agreed measure: Time from alert to first analyst action, baselined before the consolidation and reported monthly.
Strong authentication with no quiet exclusions
Phishing-resistant methods are the default, legacy authentication is closed, and every exclusion in the policy set has a name against it and a date it expires. This is the control that closes the most real risk per dollar.Agreed measure: Share of sign-ins covered by a phishing-resistant method, plus the number of policy exclusions still in place.
Guardrails that prevent rather than report
Engineers get immediate, specific feedback when a deployment would breach an encryption, region or public-exposure rule, and existing resources are brought up to standard rather than listed as non-compliant forever.Agreed measure: Compliance against the agreed policy initiative per management group, with exemptions listed separately.
Devices that must be healthy before they reach data
Access to corporate data is conditional on enrolment, compliance state and patch level rather than on knowing a password. This is also where two of the Essential Eight patching strategies are genuinely evidenced.Agreed measure: Proportion of the device population reaching corporate data while compliant, measured against the full fleet.
Entitlement value realised before new spend
Finance sees the security capability already funded inside existing licences turned on and in use before any additional purchase is proposed. Every recommendation to buy arrives with the entitlement gap it closes written next to it.Agreed measure: Controls delivered from existing entitlement versus controls requiring new licence, listed before procurement.

Common client problems

What we usually hear first.

  • We are paying for E5 and I honestly could not tell you what we have turned on.

    We map enabled service plans per licence against the controls your risk profile actually requires, and mark each one as in use, available but unconfigured, or genuinely absent. You get a short list of things to switch on and a much shorter list of things worth buying. Be prepared for the reverse finding too: some organisations are paying for E5 to get two features and would be better off on E3 plus targeted add-ons.

  • Defender is showing us thousands of recommendations and we have no idea which ones matter.

    We group findings by exposed workload and internet reachability, then suppress the recommendations that do not apply to your architecture with the reason recorded. What remains is a ranked backlog assigned to the subscription owner who can actually change it. Secure score is useful as a trend and misleading as a target, because some of the cheapest points come from controls that reduce almost no real risk.

  • Half our admins hold Global Administrator because it was quicker than working out the right role.

    We match each administrator to the least-privileged built-in role that covers their real tasks, taken from sign-in and audit activity rather than from job titles. The remaining highly privileged roles move into eligible-only assignments with approval, activation limits and alerting. The friction point is real: if activation takes longer than the task, people will ask for standing access back, so we tune the approval path before enforcing it.

  • Sentinel is costing more than we budgeted and we are talking about turning data sources off.

    We review ingestion table by table against the detections and investigations each source genuinely supports, then place each table in the tier that matches how it is actually queried rather than leaving everything in the analytics tier. Verbose sources that are only ever read during an investigation belong in a low-cost tier, and some belong nowhere. The aim is to keep the detections that matter and stop paying analytics rates to store logs nobody queries.

  • Contractors keep their access long after the project has finished.

    We move external and project access into Entra ID Governance access packages with a fixed lifetime, a sponsor and an automatic review before extension. Access lapses by default at the end of the engagement rather than requiring somebody to remember. This needs Entra ID P2 or the Entra Suite, which is worth checking against your current licence before the design assumes it.

  • Our Sentinel runbooks and links all point at the Azure portal and half of them no longer work.

    That is the portal consolidation catching up with you rather than anything broken in your tenant. Microsoft Sentinel is now operated from the Microsoft Defender portal, and Microsoft has set 31 March 2027 as the date after which it is no longer supported in the Azure portal, so bookmarks, screenshots in runbooks, training material and any automation that assumed the old paths all need a pass before then. We treat it as a documentation and enablement task with a date on it, because analysts working from stale instructions during an incident is the actual risk.

How we deliver

Our Azure delivery approach.

  1. 01

    Assessment and advisory

    The Azure review covers the tenant and the subscriptions together, because most real incidents cross that line. Everything we report is exportable configuration you can reproduce without us.

    • Every privileged assignment exported. Entra ID eligible and active role assignments, service principals holding application permissions, and guest accounts carrying directory roles, exported rather than described.
    • Enabled service plans versus controls. Which Microsoft 365 and Entra ID service plans are actually enabled per licence against the controls the target design requires, separating unused entitlement from a real gap.
    • Conditional access gap analysis. Which policies exist, which users and applications are excluded, and whether legacy authentication or an unenforced device requirement leaves a route around the policy set.
    • Defender for Cloud baseline captured. Secure score per subscription with every exempted recommendation listed alongside its reason and approver, because the exemptions are usually where the story is.
    • Intune coverage against the real fleet. Enrolment and compliance measured against the full device population that reaches corporate data, including personal and unmanaged devices nobody counted.
    • Essential Eight rating with evidence. The tenant and subscriptions assessed against the maturity model, documenting the Azure and Microsoft 365 configuration behind each rating so a challenge can be answered.
  2. 02

    Architecture and implementation

    Identity comes first, then platform guardrails, then edge protection. Each layer is deployed from a repository so the configuration is reviewable and repeatable across environments.

    • PIM for directory and resource roles. Privileged Identity Management with approval, justification, a maximum activation duration and alerting on every activation, applied to Azure resource roles as well as directory roles.
    • Access packages with an expiry. Entra ID Governance access packages and scheduled reviews so joiners, movers, leavers and external collaborators change entitlement by policy and lapse by default.
    • Conditional access in report-only first. The policy set modelled in report-only mode with named break-glass accounts excluded, monitored and periodically tested, then enforced wave by wave.
    • Azure Policy at management group scope. Initiatives for encryption, public network exposure, allowed regions and diagnostic settings, deployed from source control rather than clicked into the portal.
    • Key Vault behind managed identities. Keys, certificates and application secrets moved into Azure Key Vault behind managed identities and private endpoints, with rotation configured and secrets stripped from pipelines.
    • Edge protection tuned on real traffic. Azure Web Application Firewall in front of public applications with rule sets tuned against your own traffic, and DDoS protection on the networks carrying public endpoints.
  3. 03

    Governance, detection and assurance

    Detection content and governance artefacts are treated as products with owners and version history. Nothing depends on a configuration only one person remembers making.

    • One incident queue across signals. Microsoft Defender XDR and Defender for Cloud Apps connected so identity, endpoint, email and SaaS signal arrive in a single queue with one triage owner.
    • Sentinel sources chosen by detection. Only the data sources that support an agreed detection are onboarded, because a connector switched on with no rule behind it is a bill rather than a control.
    • Sentinel content deployed from a repo. Analytics rules, watchlists and automation rules held in version control and promoted through a pipeline, so a detection can be reviewed and rolled back.
    • Log tiering decided per table. Each table placed in the tier that matches how it is queried, with verbose investigation-only sources kept out of the analytics tier and the retention period set deliberately.
    • Security Copilot with a human owner. Introduced where it shortens hunting and incident write-ups, with a standing rule that an analyst reviews and owns its output before it reaches an incident record.
    • Control library traceable to a setting. Entra ID, Defender, Intune and Azure Policy configuration mapped to Essential Eight and ISO 27001 control themes, so an assessor can trace a claim to a specific setting. The assessment itself is performed by an independent party.
  4. 04

    Adoption and enablement

    Identity changes are the ones users feel, so they are rolled out in waves with a measured feedback loop. The service desk is trained before the first user is affected, not after.

    • Conditional access released in waves. Rolled out by user population, watching sign-in failure patterns and support ticket volume before each wave widens rather than after the complaints arrive.
    • Service desk trained on real screens. Privileged Identity Management activation, access package requests and Intune enrolment walked through in the tenant, with a one-page decision guide left behind.
    • Elevation made quick enough to use. Approval paths and activation durations tuned so requesting a role is faster than the habit it replaces, because a slow elevation process gets argued back into standing access.
    • Defender findings scoped to owners. Application owners given scoped access to their own subscription findings with a short guide to which recommendation classes must be cleared before a release.
    • Break-glass and device wipe rehearsed. An emergency sign-in and an Intune wipe practised with the people who would actually perform them, and the runbook corrected from what went wrong.
    • Portal change communicated early. Analysts moved onto the Defender portal for Sentinel work with runbooks, links and training material updated, so nobody is following stale instructions mid-incident.
  5. 05

    Managed security operations

    We keep the Microsoft control set current as the tenant changes and as Microsoft ships new capability. Work happens during agreed support hours with an escalation path you have reviewed, and we are explicit that this is not overnight monitoring.

    • Secure score movement per subscription. Reported monthly alongside Entra ID risky sign-in trend and findings still open past their agreed age, with movement explained rather than just charted.
    • Incidents triaged to a named playbook. Defender XDR and Sentinel incidents triaged against an agreed severity model and escalated through a playbook with a documented fallback contact.
    • Quarterly access reviews enforced. Entra ID Governance reviews run and the assignments nobody re-justifies removed, with the removals recorded for the next assurance cycle.
    • Policy and analytics in version control. Sentinel analytics rules, Azure Policy definitions and automation runbooks kept in a repository and tested in a non-production scope before promotion.
    • Ingestion reviewed table by table. Monthly review of what each table costs against what it detects, with re-tiering or retirement decisions recorded against the ceiling agreed at design time.
    • Compliance and update rings chased. Intune compliance and update ring health tracked, with drifting devices chased before they become a conditional access lockout on a Monday morning.

Reference architecture

The Azure security control set, layer by layer.

How the pieces fit together on Microsoft Azure. Every engagement adapts this, and we will tell you which layers you already have.

  1. 01

    Identity

    One directory decides who may do what, with elevation that expires.

    • Microsoft Entra ID
    • Conditional Access
    • Privileged Identity Management
  2. 02

    Access conditions

    Sign-in judged on device health, risk and location before data is reached.

    • Microsoft Intune
    • Global Secure Access
    • Named break-glass accounts
  3. 03

    Guardrails

    Non-conforming resources blocked or repaired at management group scope.

    • Azure Policy
    • Microsoft Defender for Cloud
    • Azure Key Vault
  4. 04

    Detect and respond

    Correlated incidents over logs chosen for the detections they support.

    • Microsoft Defender XDR
    • Microsoft Sentinel
    • Log Analytics workspace
  5. 05

    Assurance

    Control evidence, exceptions and framework mapping kept current between reviews.

    • Control library
    • Exception register
    • Essential Eight mapping

Across every layer

  • Every control deployed from version-controlled code
  • One named owner per finding and per exception
  • A log ingestion cost ceiling agreed at design time
  • Named approver and expiry date on every exemption
Most programmes start at layer 04, because that is where the product demonstration was. Detection over an identity plane nobody has cleaned is expensive noise: layers 01 and 03 are what make 04 affordable. Layer 05 is the one that gets dropped when the budget tightens, and it is the reason the next client questionnaire takes two weeks.

Technology reference

The Microsoft Azure services we build with.

A reference architecture view of the platform services used in this domain, and what each one does in the design.

Identity and access governance

  • Microsoft Entra IDThe identity plane. We use it for conditional access, phishing-resistant authentication, risk-based sign-in policy, workload identities and the sign-in and audit evidence behind every access decision.
  • Entra ID GovernanceAccess packages, lifecycle workflows and scheduled access reviews, so joiners, movers, leavers and external collaborators change entitlement by policy and expire by default.
  • Privileged Identity ManagementTime-bound, approval-gated elevation for directory and Azure resource roles, replacing standing administrative rights and producing an auditable activation trail.

Threat detection and response

  • Microsoft Defender for CloudCloud posture management and workload protection across subscriptions. We use its recommendations as the prioritised remediation backlog and its secure score as a monthly trend rather than a target.
  • Microsoft Defender XDRThe correlated incident queue across identity, endpoint, email and collaboration signal, so one investigation replaces four disconnected alert streams.
  • Defender for Cloud AppsDiscovery and control of sanctioned and unsanctioned SaaS, including the AI tools staff adopt on their own, with session policy where an outright block would push usage onto personal devices.
  • Microsoft SentinelCentral analytics, hunting and automation over the log sources that support agreed detections, operated from the Defender portal with rules deployed from source control and ingestion reviewed monthly.
  • Microsoft Security CopilotAssisted hunting, summarisation and incident write-up where it shortens analyst time, always with a human reviewing and owning the output before it enters an incident record.

Logging and evidence

  • Azure MonitorThe Log Analytics workspace behind Sentinel, where table tiering, retention and diagnostic settings decide both what you can detect and what you pay each month.
  • Azure Key VaultCentral custody of keys, certificates and application secrets behind managed identities and private endpoints, with rotation scheduled and credentials removed from pipelines and config files.

Platform guardrails and edge protection

  • Azure PolicyPreventative guardrails at management group scope for encryption, allowed regions, public exposure and diagnostic settings, authored as code and promoted through the same pipeline as infrastructure.
  • Azure Web Application FirewallManaged and custom rule sets in front of public web applications and APIs, tuned against real traffic so protection does not arrive as a wall of false positives.
  • Azure DDoS ProtectionNetwork-layer volumetric protection with telemetry and attack analytics on the virtual networks that carry internet-facing endpoints.

Endpoint, patching and data boundary

  • Microsoft IntuneDevice enrolment, compliance policy, configuration baselines, update rings and application protection, providing the device health signal conditional access depends on and the patching evidence the Essential Eight asks for.
  • Microsoft PurviewUsed here for the sensitivity boundary that identity and AI controls depend on. The classification, cataloguing and loss prevention programme itself belongs to our data governance and compliance work.

Product names and icons are trademarks of Microsoft and Amazon Web Services, reproduced unmodified from their official architecture icon libraries to identify the technologies used in these architectures. Their presence does not indicate partnership, certification or endorsement by either vendor.

Azure questions

What people ask about doing this on Azure.

Cost, lock-in and the parts that go wrong, answered before you have to ask twice.

  • Do we need E5, or can we do this with E3 and add-ons?

    It depends on which controls you actually need, and the answer is genuinely not always E5. Entra ID P2 is what unlocks Privileged Identity Management, risk-based conditional access and access reviews, which is the identity work that matters most. If those plus endpoint protection are the requirement, E3 with targeted add-ons is often cheaper than E5 across a whole user base. If you want Defender XDR breadth, Purview capability and Sentinel together, E5 usually wins on price. We price both against your user count and licence mix before recommending either.

  • How much does Microsoft Sentinel cost per month?

    It is a function of gigabytes ingested per day and the tier each table sits in, so anyone quoting a figure before seeing your log sources is guessing. The practical drivers are the same in most tenants: firewall and network logs, verbose audit sources and anything from a busy application. We model daily volume per source during assessment, place each table in the tier matching how it is queried, and check whether a commitment tier is cheaper than pay-as-you-go at your volume. Expect ingestion to grow every time a new workload is onboarded, which is why the monthly review exists.

  • Is Microsoft Sentinel good enough, or do we need a third-party SIEM?

    For an organisation whose estate is mostly Microsoft, Sentinel is usually the right answer, because the connectors and the correlation with Defender XDR are work you would otherwise build. It is a weaker choice where most of your logs come from non-Microsoft sources, where you have an existing detection library with real engineering investment behind it, or where your team has deep skill in another platform. There is also a soft lock-in worth naming: detections written in KQL against Sentinel tables do not port anywhere, so a later migration means rewriting them.

  • Will conditional access lock our staff out?

    It can, which is why nothing goes straight to enforcement. Every policy runs in report-only mode first so we can see exactly which sign-ins would have failed, break-glass accounts are named and excluded and then tested rather than assumed, and enforcement moves by user wave with ticket volume watched between waves. The failure we are avoiding is the one where a policy blocks a legitimate process, the response is a broad exclusion, and the control is quietly disabled for everyone.

  • Can our IT team run this without a security specialist?

    The Microsoft controls, largely yes, once they are designed and documented, and we would rather hand over than create a dependency. The parts that reliably need either a specialist or an outside party are detection tuning, incident triage when something real happens, and the discipline of reviewing exceptions that have expired. A capable IT team plus a quarterly outside review beats a full-time security hire for many mid-sized organisations, and we will tell you when your situation is the exception.

  • Does Azure keep our data in Australia?

    Azure has Australian regions and you can pin resources and log retention to them, and we design to that requirement where it exists. What we will not do is guarantee residency on Microsoft's behalf, because some capabilities process data outside the region you selected and the detail changes between services and over time. We confirm the specific commitment for each service in your architecture at design time and record it with the date, so what you hold is a dated verification rather than an assurance from us.

Related industries

Where this work has the most leverage.

  • Professional Services

    Governed enterprise search, document intelligence and secure copilots that respect matter confidentiality and conflict boundaries.

  • Healthcare and Community Services

    Administrative automation, policy search, workforce analytics and privacy uplift for healthcare and community providers, with clinical decisions left entirely to clinicians.

  • Construction and Property

    Tender intelligence, addenda tracking and project reporting that keep estimators and contract administrators ahead of the documents instead of buried in them.

Free discovery workshop

Start with a security and governance discovery workshop.

Bring one challenge. We will assess whether Microsoft Azure is the right platform for it before recommending anything.