Azure SC-900 Security Fundamentals: Zero Trust, Defense-in-Depth, and the Shared Responsibility Model
For those just starting to learn about cloud security, this post explains the core concepts of Microsoft Azure security in everyday language. Whether you are preparing for an exam or simply want to deepen your understanding of cloud security, this is a great starting point.
Zero Trust Model: "Trust No One"
In the old days, simply entering a company building meant you were trusted as an insider. Once your badge got you through the door, you could move around relatively freely inside. But this approach has a glaring flaw. What if someone steals a badge, or an insider turns malicious?
Zero Trust flips this idea entirely. Instead of "you're inside the building, so I trust you," it means verifying every single action, every single time: "Are you really who you say you are? Do you have the right to do this?"
The 3 Core Principles of Zero Trust
First Principle: Verify Explicitly
Identity is checked every time access is requested. Every data point available — who is connecting, where they are connecting from, what device they are using, when they are connecting — is used to make a decision. The concept of "logged in once, trusted all day" does not exist.
Second Principle: Use Least Privilege
A cashier at a supermarket does not need access to the entire inventory management system. They only need access to what is required for checkout. Similarly, users and systems are given only the minimum permissions required for their specific task. Excess privilege is the seed of risk.
Third Principle: Assume Breach
Discard the complacency of "our system can never be breached." Operate under the assumption that an attack can happen at any time, and design systems in small, isolated zones to minimize the blast radius. If one zone is compromised, the others remain safe.
!Zero Trust's 3 core principles
Why Zero Trust Matters
In the past, being inside the corporate network was considered safe. But today, employees work from cafes, from home, from abroad. They use cloud services. The traditional concept of a "network perimeter" has collapsed. Zero Trust is the security philosophy designed precisely for this reality.
Defense-in-Depth: Layers Like an Onion
Relying on a single outer wall to defend a castle is risky. If that wall falls, it is over. That is why medieval castles were built with multiple lines of defense: outer walls, moats, a second wall, watchtowers, an inner keep, and more.
Defense-in-Depth applies this exact principle to IT security. Rather than depending on a single security measure, multiple layers of security are stacked so that even if an attacker breaks through one, the next barrier stops them.
7 Security Layers
Starting from the outermost layer and moving inward:
Physical Security Prevents unauthorized physical entry into a data center. Locks, guards, security cameras, and access controls all apply here. Even the most sophisticated software security is meaningless if someone can walk into the server room and pull out a hard drive.
Identity and Access Controls who can access what. Multi-factor authentication (MFA), Conditional Access, and similar mechanisms belong here.
Perimeter Defends against large-scale, network-level attacks like DDoS. Services such as Azure DDoS Protection serve this role.
Network Restricts movement within the network. Defines which servers can communicate with which other servers. NSGs (Network Security Groups) serve this role.
Compute Protects actual computing resources such as virtual machines and containers. Unnecessary ports are closed and patches are kept up to date.
Application Security at the application code level. Defends against SQL injection, XSS, and similar attacks, and securely manages passwords and API keys.
Data The innermost and most critical layer. Data itself is encrypted and access is strictly limited. The ultimate goal of all security efforts is to protect the data.
Shared Responsibility Model: Like a Landlord and a Tenant
Think about renting a home. The landlord handles the building structure, rooftop waterproofing, and plumbing. But furniture arrangement, locking windows, and securing valuables are the tenant's responsibility.
Cloud works the same way. Microsoft (the landlord) and the customer (the tenant) each have clearly defined responsibilities. This is the Shared Responsibility Model.
Responsibility by Service Type
On-premises: The customer manages everything — servers, networking, operating systems, applications, and data. Like building and maintaining your own home.
IaaS (Infrastructure as a Service): Azure is responsible for the physical infrastructure (servers, networking, storage). The customer manages everything from the operating system up. Example: Azure Virtual Machines.
PaaS (Platform as a Service): Azure manages infrastructure, the operating system, and the runtime. The customer is responsible only for the application and data. Examples: Azure App Service, Azure SQL Database.
SaaS (Software as a Service): Azure manages nearly everything. The customer is responsible only for data and user access management. Example: Microsoft 365.
What Is Always the Customer's Responsibility
Regardless of the service type, there are things the customer must always own: Data Devices (PCs, smartphones, etc.) Accounts and user access management
The CIA Triad: The Three Pillars of Security
If the three elements of health are body, mind, and spirit, then the three elements of information security are Confidentiality, Integrity, and Availability.
Confidentiality
Only authorized individuals should be able to access information. Medical records should be visible only to the patient and their treating physician. Payroll data should be known only to HR and the employee concerned.
How to protect confidentiality: encryption (transforming data so it cannot be read), access control (allowing only authorized individuals to access), authentication (verifying identity).
Integrity
Information must not be altered without authorization. What if the dosage of a medication prescribed by a doctor was secretly changed by someone? It could be catastrophic. Data must remain as it was originally created.
How to protect integrity: hashing (leaving a unique fingerprint on data to detect changes), digital signatures, change history management.
Availability
Information and systems must be accessible when needed. No matter how secure something is, if it cannot be used, it has no value. If an emergency room system goes down, patient lives are at risk.
How to protect availability: redundancy (running backup systems), disaster recovery planning, DDoS protection.
GRC: How Organizations Manage Security Systematically
The reason a company follows traffic laws, requires seatbelts, and prohibits drunk driving is not simply because the law demands it. It is to prevent accidents, reduce damage when accidents do occur, and avoid legal liability. GRC is a similar concept.
Governance
This is about how an organization makes decisions and what policies and rules it follows to achieve its goals. It includes establishing security policies, defining roles and responsibilities, and setting the direction for security.
Risk Management
This involves evaluating what threats exist, how likely they are to materialize, and how much damage they would cause if they did. Identifying risks allows organizations to decide where to invest.
Compliance