Skip to content

Latest commit

 

History

68 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

Enterprise Cloud & AI Governance Deployment

A hands-on, $0-cost simulation of a secure enterprise cloud deployment — covering Azure infrastructure governance, Zero Trust identity security, and AI/Copilot data governance.

TL;DR

  • Built and secured a 3-phase enterprise cloud environment spanning cloud infrastructure governance, identity & access management (IAM), and AI data governance, using Microsoft Azure and Microsoft 365.
  • Implemented Zero Trust controls (Conditional Access, PIM, Identity Protection) and enterprise data protection (Purview DLP, sensitivity labels, AI governance policies) aligned to real-world frameworks (NIST 800-53, CIS Controls).
  • Total cost: $0 — built entirely on Azure free-tier services and time-boxed Microsoft 365 / Azure trial licensing, with trial resources monitored and decommissioned before any charges could apply.

Table of Contents


Technologies & Cloud Services Utilized

Category Technologies & Microsoft Services
Core Infrastructure Azure Virtual Networks (VNet), Azure Resource Groups
Identity & Access Microsoft Entra ID, Azure RBAC, Dynamic Security Groups
Zero Trust Security Conditional Access, Privileged Identity Management (PIM), MFA
Automation PowerShell, Microsoft Graph API
Data Governance Microsoft Purview, Sensitivity Labels, Data Loss Prevention (DLP)

Skills & Certification Alignment

Phase Certification Domain(s) Job-Posting Keywords Covered
Phase 1 — Foundation & Governance AZ-900 (Cloud Concepts); building toward AZ-104 (Governance, RBAC, IaC) Resource governance, cost management, RBAC, Infrastructure as Code
Phase 2 — Identity & Security SC-900 (Identity Fundamentals); building toward SC-300 (Identity & Access Administrator) IAM, Zero Trust, Conditional Access, PIM, MFA, access reviews, identity lifecycle
Phase 3 — AI & Data Governance AB-900 (Microsoft 365 Certified: Copilot and Agent Administration Fundamentals) DLP, sensitivity labels, data governance, AI/Copilot security, insider risk

Phase 1: The Foundation & Governance (AZ-900 → AZ-104 Focus)

Objective: Provision the core Azure infrastructure to establish a secure, software-defined network boundary, and apply strict governance controls to protect foundational assets.

Technical Execution:

  • Resource Management: Deployed a centralized Azure Resource Group (rg-enterprise-foundation) in the East US region to logically contain and manage the lifecycle of foundational assets.
  • Virtual Networking (VNet): Engineered a secure Virtual Network (vnet-enterprise-primary) utilizing a standard 10.0.0.0/16 IP address space to facilitate isolated internal routing and future subnetting.
  • Cloud Governance: Deployed an Azure Resource Lock (Delete type) to the foundational resource group, strictly preventing accidental or unauthorized deletion of mission-critical cloud infrastructure.
  • Financial Governance: Engineered an automated cloud spend guardrail by deploying a strict $1.00 Azure Budget Alert (Zero-Cost-Guardrail) to instantaneously trigger email notifications upon any billing deviations.
  • Infrastructure as Code (IaC): Authored a Bicep template (main.bicep) to codify and redeploy the network foundation, provisioning a Virtual Network (vnet-enterprise-iac, 10.1.0.0/16) with a dedicated subnet (snet-workload, 10.1.1.0/24) via the Azure CLI. Demonstrates repeatable, version-controlled infrastructure deployment as an alternative to manual portal configuration.
  • Governance & Compliance Auditing (Azure Policy): Authored a custom Azure Policy definition (Audit-Environment-Tag) — cloned from a built-in Microsoft policy and modified from a blocking Deny effect to a non-disruptive Audit effect — to continuously evaluate resources in rg-enterprise-foundation for a required Environment tag. A triggered compliance scan (az policy state trigger-scan) confirmed the policy correctly identified vnet-enterprise-primary as non-compliant, validating real-time governance-as-code enforcement.
  • Cost & Reliability Review (Azure Advisor): Reviewed Azure Advisor's built-in recommendations engine across all five categories (Cost, Security, Reliability, Operational Excellence, Performance). Identified 2 active reliability recommendations — a High-impact recommendation (Create an Azure Service Health alert) and a Medium-impact recommendation (Use NAT gateway for outbound connectivity) — demonstrating proactive infrastructure health monitoring.

Why this matters: Resource locks and controlled resource-group boundaries map to CIS Control 3 (Data Protection) and NIST 800-53 CM-5 (Access Restrictions for Change) — preventing unauthorized or accidental modification of production infrastructure. Codifying infrastructure as version-controlled templates (rather than manual portal clicks) ensures consistent, auditable, and repeatable deployments — a core practice in modern cloud administration and a direct AZ-104 exam objective. Custom policy authoring — including deliberately choosing Audit over Deny for a first rollout — reflects real-world governance rollout practice (test/observe before enforcing) and CIS Control 4 (Secure Configuration of Enterprise Assets). Regularly reviewing Advisor recommendations reflects FinOps and operational-excellence best practices — catching reliability and cost risks before they become incidents, rather than reacting after the fact.

Project Evidence:

Source Code: /iac/main.bicep


Phase 2: Identity & Security Perimeter (SC-900 → SC-300 Focus)

Objective: Secure the cloud foundation by establishing robust identity management and a programmatic security perimeter.

Technical Execution:

  • Automated Identity Provisioning: Executed a PowerShell automation script utilizing the Microsoft Graph API (New-MgUser) to programmatically deploy simulated corporate departments into Entra ID.
  • Dynamic Group Automation: Engineered an Entra ID Dynamic Security Group (Auto-Finance-Team) utilizing attribute-based queries (user.department -eq "Finance") to automate user lifecycle management and access provisioning.
  • Role-Based Access Control (RBAC): Enforced the Principle of Least Privilege by assigning targeted Network Contributor permissions to specific administrative accounts.
  • Zero Trust Architecture: Disabled baseline security defaults to engineer a custom Conditional Access policy (Require-MFA-Privileged-Roles), strictly enforcing Multi-Factor Authentication (MFA) for privileged cloud identities.
  • Privileged Access: Configured Privileged Identity Management (PIM) for the Global Administrator role, enforcing Just-In-Time (JIT) access with a maximum 2-hour activation window, requiring Azure MFA and written justification.
  • Attack Surface Reduction: Deployed a Conditional Access policy (Block-Legacy-Authentication) targeting all cloud apps to strictly block legacy authentication protocols (e.g., Exchange ActiveSync), mitigating MFA bypass vulnerabilities while retaining a break-glass admin exclusion.
  • Identity Lifecycle Management: Deployed an automated quarterly Access Review (Quarterly-Finance-Access-Audit) targeting the Auto-Finance-Team to continuously audit standing privileges, ensuring access is programmatically revoked if denied by the reviewer.
  • Risk-Based Conditional Access (Identity Protection): Migrated from the legacy Identity Protection risk-policy blade (now deprecated in favor of Conditional Access) to author two modern, risk-based Conditional Access policies: Report-Only-Block-High-User-Risk (blocks access for High user risk) and Report-Only-Block-Medium-SignIn-Risk (blocks access for Medium-and-above sign-in risk). Both policies were deployed in Report-only mode — the industry-standard practice of validating a policy's real-world impact before enforcing it — consistent with the Audit-before-Deny approach used in Phase 1's governance work.
  • Identity Governance (Entitlement Management): Designed and deployed a self-service Access Package (Finance-Team-Access-Package) via a dedicated governance catalog, granting time-limited (90-day) membership to a Finance resource group with mandatory approval and justification requirements. Discovered and documented a key platform constraint during testing: dynamic security groups cannot be used as Entitlement Management resources (membership is rule-computed, not assignable), requiring a purpose-built static group (Finance-Package-Members). Validated the end-to-end request workflow by submitting a live test request, confirming Microsoft Entra's built-in separation-of-duties control that prevents a requestor from approving their own access request.
  • Enterprise Application SSO (SAML): Configured a full bidirectional SAML 2.0 trust relationship between Microsoft Entra ID and a test service provider (Microsoft Entra SAML Toolkit), including Identifier/Entity ID, Reply URL (ACS), Sign-on URL, signing certificate, and default attribute claim mappings (givenname, surname, email, UPN) on the Entra side, matched by an equivalent SAML configuration (Login URL, Logout URL, Entra Identifier, and certificate) on the service provider side. Live SP-initiated login testing surfaced a known limitation in the third-party test tool (self-documented as "Alpha stage"), which was diagnosed and documented rather than treated as a configuration failure.

Why this matters: Conditional Access, PIM, and access reviews implement the Zero Trust principles of "verify explicitly" and "least privilege," aligning with NIST 800-53 AC-6 (Least Privilege) and CIS Control 6 (Access Control Management). Risk-based Conditional Access embodies the Zero Trust principle of "assume breach" — continuously evaluating identity signals (impossible travel, leaked credentials, anomalous sign-in patterns) rather than trusting a session just because MFA was satisfied once. Deploying in Report-only mode first — rather than immediately enforcing — mirrors real enterprise change-management practice and avoids the risk of self-lockout, a mistake that has caused real production outages. Entitlement Management operationalizes the access-request lifecycle a Jr. IAM Analyst manages daily — self-service requests, approval routing, justification capture, and time-bound expiration — rather than relying on ad hoc manual provisioning. The self-approval restriction encountered during testing reflects a real separation-of-duties control (NIST 800-53 AC-5) that prevents a single individual from both requesting and authorizing their own access, a common audit finding in poorly-governed environments. SAML-based SSO configuration — mapping Entity IDs, ACS URLs, and signing certificates between an Identity Provider and Service Provider — is core IAM work for onboarding any enterprise SaaS application. Correctly diagnosing a third-party tool limitation, rather than assuming a personal misconfiguration, reflects the troubleshooting discipline expected of an IAM analyst working with vendor integrations of varying quality and maturity.

Project Evidence:


Phase 3: AI SaaS Rollout & Data Governance (AB-900 / Purview Focus)

Objective: Establish a secure data boundary prior to deploying AI tools (like Microsoft 365 Copilot) to prevent unauthorized extraction and exfiltration of confidential corporate data.

AB-900 = Microsoft 365 Certified: Copilot and Agent Administration Fundamentals — a newly released certification covering Copilot/agent governance across Purview, Defender, and Entra ID.

Technical Execution:

  • Information Protection: Engineered a Microsoft Purview Sensitivity Label (Confidential-Finance) to classify and encrypt highly sensitive financial datasets, ensuring artificial intelligence agents cannot bypass human security clearances.
  • Data Loss Prevention (DLP): Designed an enterprise-wide DLP policy (Block-External-Financial-Data) to monitor and block the transmission of high-risk data.
  • DLP Logic Enforced: Configured pattern-matching for Sensitive Information Types (SITs) targeting U.S. Bank Account and Credit Card Number parameters within a custom rule (Enforce Financial Data Protection), programmatically blocking external sharing while satisfying mandatory Microsoft user notifications.
  • AI Governance & Compliance: Authored and deployed a custom Entra ID Terms of Use document (Generative-AI-Acceptable-Use-Policy) establishing strict data privacy guardrails for enterprise AI utilization.
  • Conditional Access Gateway: Engineered a Conditional Access policy (Enforce-AI-Terms-of-Use) targeting Office 365 applications to serve as a programmatic gateway, strictly forcing users to read, expand, and explicitly consent to the AI ToU prior to accessing Copilot or Microsoft 365 services.
  • Security Operations (Microsoft Defender XDR): Activated Microsoft Defender XDR's Unified role-based access control (RBAC) model — a permissions-default change Microsoft began enforcing on new tenants in mid-2026 — by diagnosing a Global Administrator access restriction and authoring a custom XDR-Full-Access-Admin role scoped to Security operations and Security posture permissions. Reviewed baseline security posture via Microsoft Secure Score, then designed and launched a live Credential Harvest phishing simulation (Phishing-Simulation-Direct) via Attack Simulation Training, tracking full attack-chain telemetry (message delivery, link click, credential submission — 100% compromise rate on a single-target test). Diagnosed and documented that Attack Simulation Training deliberately excludes simulated phishing from the Incidents queue via a dedicated Advanced Delivery override, distinguishing safe security-awareness testing from genuine threat-detection alerting.
  • AI Data Security Posture (Purview DSPM for AI): Deployed Microsoft Purview's unified Data Security Posture Management (DSPM) experience, activating included Auditing and Analytics while deliberately declining three Pay-as-you-go-tagged AI collection policies (Copilot interaction capture, Enterprise AI app capture, network-based sensitive-data detection) to preserve zero-cost operation. Reviewed AI-specific Data Security Objectives and the Posture dashboard, confirming the existing Block-External-Financial-Data DLP policy from this phase was already satisfying the "Prevent exfiltration to risky destinations" objective with a passing status — direct evidence that earlier governance work is actively reducing measured data-security risk.
  • SIEM Deployment (Microsoft Sentinel): Provisioned a dedicated Log Analytics workspace (law-enterprise-sentinel) and enabled Microsoft Sentinel on it, using Azure's 31-day / 10GB-per-day free trial allowance. Confirmed Sentinel auto-connected to 7 existing Microsoft security data sources — including Microsoft Entra ID Protection (tying directly into this project's Phase 2 risk-based Conditional Access policies) and Microsoft Defender XDR — without any manual connector configuration required. Authored and executed a KQL query (SecurityAlert | take 10) against the live workspace via Sentinel's Logs blade to validate query functionality and data connectivity.

Why this matters: Sensitivity labels and DLP enforce data-centric security so AI tools like Copilot can't surface data a user wouldn't otherwise have access to — directly addressing the "oversharing" risk in Microsoft's Zero Trust guidance for Copilot, and mapping to NIST 800-53 SC-28 (Protection of Information at Rest). Diagnosing and resolving the Unified RBAC access restriction reflects a real, current change security administrators are encountering as Microsoft rolls out this permission model — troubleshooting access issues under a live task is itself a core Defender-admin skill. Running phishing simulations and interpreting compromise-rate telemetry is standard security-awareness practice (NIST 800-53 AT-2, Security Awareness Training), and correctly identifying why simulated attacks are excluded from the real incident pipeline — rather than assuming a misconfiguration — demonstrates the same "verify before escalating" judgment expected of a Tier-1 SOC analyst. Recognizing and declining a metered/consumption-billed feature during a hands-on walkthrough — rather than enabling it by default — reflects the same cost-governance discipline applied throughout this project (see Phase 1's Azure Advisor review). KQL query authoring is the single most-requested technical skill in SOC L1/Jr SOC job postings, and a SIEM that automatically ingests from Entra ID Protection and Defender XDR demonstrates a genuinely integrated security stack rather than disconnected point tools.

Project Evidence:


Roadmap: Planned Enhancements

This project is actively being expanded to deepen coverage of AZ-104, SC-300, and AB-900 exam objectives — and to reflect real-world SOC, IAM, and cloud admin job requirements.

  • Phase 1: Infrastructure as Code — redeploy RG/VNet via Bicep
  • Phase 1: Azure Policy — custom governance policy assignment
  • Phase 1: Azure Advisor — cost & security recommendations review
  • Phase 2: Entra ID Identity Protection — risk-based Conditional Access
  • Phase 2: Identity Governance — Entitlement Management (Access Packages)
  • Phase 2: Enterprise App SSO — SAML/OIDC test app integration
  • Phase 3: Microsoft Defender XDR — Unified RBAC setup, Secure Score review, and live phishing simulation
  • Phase 3: Purview DSPM for AI — Copilot/agent data risk assessment
  • Phase 3: Microsoft Sentinel — SIEM data connector + KQL query (free-trial workspace)
  • Phase 3 (stretch, requires isolated VM): Full Defender for Endpoint incident triage — deferred to avoid onboarding real personal-device telemetry to the tenant

Cost Transparency

Every resource in this project was built using Azure free-tier services, always-free Azure features, and time-boxed Microsoft 365 E5 / Azure trial licensing. Total cost: $0. Where a service includes a time-limited free trial (e.g., Microsoft Sentinel's 31-day / 10 GB-per-day free allowance), resources were monitored and decommissioned before the trial period ended to avoid any charges.

About

End-to-end deployment of a secure corporate cloud environment simulating Microsoft's core cloud, identity, zero-trust, and AI data governance frameworks.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages