Identity, Access, and Security

Covers Microsoft Entra ID, MFA, Conditional Access, RBAC, Zero Trust, and Defender for Cloud.

Security is one of the most important topics in cloud environments. In the cloud, the key is precisely controlling who can access which resources. This guide explains Azure's identity, authentication, access control, and security services with easy analogies so that even first-time learners can understand them clearly.

 

Microsoft Entra ID — The Cloud ID Office

Microsoft Entra ID (formerly Azure Active Directory, Azure AD) is Azure's cloud-based identity and access management (IAM) service. Think of it as the ID office in a corporate building. It issues ID cards (accounts) to employees and controls which areas (resources) each ID card can access.

If traditional Windows Server Active Directory was designed for on-premises internal networks, Microsoft Entra ID is a modern identity management system built for the cloud and internet age. It lets you log in to various services — Azure Portal, Microsoft 365, SaaS apps, and more — using a single account.

Key roles: Manage user accounts (create, delete, group management) Control application access permissions Support SSO, MFA, and Conditional Access Manage external partner and customer accounts (B2B, B2C)

 

Authentication vs. Authorization — ID Check vs. Boarding Pass

These two concepts are the foundation of security. They look similar but are completely different.

Authentication is "proving who you are." Like presenting your passport at the airport for identity verification, authentication is the process of confirming your identity when you log in — using a username and password, biometrics, or other means. It answers the question: "Are you really you?"

Authorization is "deciding what a verified identity can do." Like being allowed only to the seat listed on your boarding pass (economy or business class) after your identity is confirmed, authorization determines what resources a logged-in user can read, write, or delete. It answers the question: "Are you allowed to do this?"

| Concept | Question | Azure Service | Example | |---------|---------|--------------|--------| | Authentication | Who are you? | Microsoft Entra ID | Login, MFA | | Authorization | What can you do? | RBAC, Policies | Read/write/delete permissions |

!Authentication versus authorization

MFA (Multi-Factor Authentication) — The Double Lock

MFA requires proving your identity through two or more methods. It is like a bank vault with two locks. Even if someone steals one key, the second lock still protects the vault.

Authentication factors fall into three categories: Something you know: Password, PIN Something you have: Smartphone authenticator app, SMS code, hardware token Something you are: Fingerprint, face recognition, and other biometrics

With MFA, even if a password is leaked, an attacker who does not have the second factor (for example, your smartphone) cannot log in. Activating MFA in Microsoft Entra ID requires additional verification for every login.

 

SSO (Single Sign-On) — The Master Key

SSO lets you log in once and access multiple services without logging in again separately. Like receiving an entry stamp at a large shopping mall that lets you move between stores without showing ID again, logging in once with Microsoft Entra ID gives you access to thousands of connected apps — Azure Portal, Microsoft 365, Salesforce, GitHub, and more — without additional logins.

Benefits of SSO: Better user experience (remember only one password) Simplified IT management (manage only one account) Improved security (reduces password reuse)

 

Conditional Access — The Smart Gate

Conditional Access lets you define policies for when to allow access or require additional authentication, based on conditions. It evaluates the entire access situation, going beyond a simple username and password check.

For example, you can set policies like these: "Allow through if accessing from the internal company network. Require MFA if accessing from a foreign IP. Always require MFA for administrator accounts. Block access from non-compliant devices."

Evaluation factors: Users and groups (who is accessing?) Location (where is the access coming from? Based on IP address) Device state (is it a managed device? Is it compliant?) Application (which app is being accessed?) Risk level (is the login risk level high?)

Conditional Access requires a Microsoft Entra ID Premium license.

 

RBAC (Role-Based Access Control) — Access Rights Based on Job Title

RBAC assigns roles to users and defines what permissions each role has over resources. It is like a company where access to different areas depends on your job title (role). A security guard can enter the warehouse, a developer can access the server room, and an executive can go everywhere.

Azure's major built-in roles: Owner: Can perform all actions and grant permissions to other users Contributor: Can create, modify, and delete resources, but cannot grant permissions to others Reader: Can only view resources, cannot make changes User Access Administrator: Can only manage access permissions

The core principle of RBAC is the Principle of Least Privilege. You grant users only the minimum permissions needed for their work. More permissions than necessary create potential security risks.

The scope at which a role is applied also matters: Management Group level Subscription level Resource Group level Individual resource level

Roles assigned at a higher scope are inherited by lower scopes.

 

Zero Trust Model — Trust Nobody

Zero Trust is a security philosophy that says "being inside the network does not mean you are trusted." Traditional security used the "Castle-and-Moat" model — once inside the company firewall, you are assumed to be safe. Anyone who made it inside the castle walls was considered trustworthy.

But insider threats, the spread of remote work, and cloud adoption have broken this model. Zero Trust follows three principles: Verify Explicitly, Use Least Privilege, and Assume Breach.

Verify Explicitly: Always authenticate and authorize based on location, device, user, and service Use Least Privilege: Grant only the minimum necessary permissions using JIT (Just-In-Time) and JEA (Just-Enough-Access) Assume Breach: Design as if a breach has already occurred, minimizing potential damage

In Azure, Microsoft Entra ID, Conditional Access, RBAC, Microsoft Defender for Cloud, and Azure Firewall work together to implement a Zero Trust architecture.

 

Microsoft Defender for Cloud — Security Posture Monitoring Center

Microsoft Defender for Cloud is an integrated security management platform that monitors security posture and detects threats across Azure, on-premises, and multi-cloud environments. Think of it as the control room for a network of security cameras. It monitors all resources at a glance and sends immediate alerts when anomalies are detected.

Key features: Secure Score: Displays current security posture as a score and provides recommendations to improve it Security recommendations: Guides you on how to fix misconfigured resources Threat protection: Detects and alerts on abnormal behavior and attack attempts Compliance: Evaluates compliance status against standards like PCI DSS and ISO 27001

 

Azure Key Vault — The Digital Safe

Azure Key Vault is a service for securely storing and managing sensitive information such as passwords, API keys, encryption keys, and certificates. Think of it as a bank vault. Important keys (secrets) are locked in the vault, and only authorized parties can retrieve them.

Why do you need Key Vault? If a developer hard-codes a database password or API key inside code, the password is exposed when the code leaks. By storing secrets in Key Vault, the code only contains a Key Vault reference, while the actual values are managed securely by Key Vault.

Main items stored: Secrets: Passwords, connection strings, API keys Keys: Cryptographic keys used for encryption and decryption (HSM protection available) Certificates: SSL/TLS certificate management and automatic renewal

Access is controlled through RBAC or Key Vault access policies, and all access history is recorded in audit logs.

 

Microsoft Sentinel — The AI Security Analyst

Microsoft Sentinel is a cloud-based SIEM (Security Information and Event Management) + SOAR (Security Orchestration, Automation, and Response) service. Think of it as an AI analyst at a large security firm. It analyzes millions of security event logs in real time, identifies genuine threats, and automatically takes response actions.

Key features: Data collection: Collects and integrates security logs from Azure, Office 365, firewalls, third-party solutions, and more Threat detection: Uses AI and machine learning to analyze patterns and detect attacks Incident investigation: Visualizes attack timelines and scope of damage Automated response (SOAR): Automates actions like blocking suspicious accounts and sending alerts through Playbooks

 

Azure DDoS Protection — The Flood Defense Dam

A DDoS (Distributed Denial of Service) attack sends massive amounts of traffic from many computers simultaneously to overwhelm and disable a server. Like a flood of water (traffic) rushing in all at once. Azure DDoS Protection is a defense dam that automatically detects and blocks such attacks.

Two tiers are available: DDoS Network Protection (Basic): Basic protection automatically applied to all Azure services. No additional cost. DDoS IP Protection (Standard): More sophisticated mitigation, attack analysis reports, cost protection (refund of Azure costs incurred during an attack), and expert support. Additional cost applies.

 

Azure Firewall — The Cloud Firewall

Back to blog list