A hands-on, $0-cost simulation of a secure enterprise cloud deployment — covering Azure infrastructure governance, Zero Trust identity security, and AI/Copilot data governance.
- Built and secured a 3-phase enterprise cloud environment spanning cloud infrastructure governance, identity & access management (IAM), and AI data governance, using Microsoft Azure and Microsoft 365.
- Implemented Zero Trust controls (Conditional Access, PIM, Identity Protection) and enterprise data protection (Purview DLP, sensitivity labels, AI governance policies) aligned to real-world frameworks (NIST 800-53, CIS Controls).
- Total cost: $0 — built entirely on Azure free-tier services and time-boxed Microsoft 365 / Azure trial licensing, with trial resources monitored and decommissioned before any charges could apply.
- Technologies & Cloud Services Utilized
- Skills & Certification Alignment
- Phase 1: The Foundation & Governance
- Phase 2: Identity & Security Perimeter
- Phase 3: AI SaaS Rollout & Data Governance
- Roadmap: Planned Enhancements
- Cost Transparency
| Category | Technologies & Microsoft Services |
|---|---|
| Core Infrastructure | Azure Virtual Networks (VNet), Azure Resource Groups |
| Identity & Access | Microsoft Entra ID, Azure RBAC, Dynamic Security Groups |
| Zero Trust Security | Conditional Access, Privileged Identity Management (PIM), MFA |
| Automation | PowerShell, Microsoft Graph API |
| Data Governance | Microsoft Purview, Sensitivity Labels, Data Loss Prevention (DLP) |
| Phase | Certification Domain(s) | Job-Posting Keywords Covered |
|---|---|---|
| Phase 1 — Foundation & Governance | AZ-900 (Cloud Concepts); building toward AZ-104 (Governance, RBAC, IaC) | Resource governance, cost management, RBAC, Infrastructure as Code |
| Phase 2 — Identity & Security | SC-900 (Identity Fundamentals); building toward SC-300 (Identity & Access Administrator) | IAM, Zero Trust, Conditional Access, PIM, MFA, access reviews, identity lifecycle |
| Phase 3 — AI & Data Governance | AB-900 (Microsoft 365 Certified: Copilot and Agent Administration Fundamentals) | DLP, sensitivity labels, data governance, AI/Copilot security, insider risk |
Objective: Provision the core Azure infrastructure to establish a secure, software-defined network boundary, and apply strict governance controls to protect foundational assets.
Technical Execution:
- Resource Management: Deployed a centralized Azure Resource Group (
rg-enterprise-foundation) in the East US region to logically contain and manage the lifecycle of foundational assets. - Virtual Networking (VNet): Engineered a secure Virtual Network (
vnet-enterprise-primary) utilizing a standard10.0.0.0/16IP address space to facilitate isolated internal routing and future subnetting. - Cloud Governance: Deployed an Azure Resource Lock (
Deletetype) to the foundational resource group, strictly preventing accidental or unauthorized deletion of mission-critical cloud infrastructure. - Financial Governance: Engineered an automated cloud spend guardrail by deploying a strict
$1.00Azure Budget Alert (Zero-Cost-Guardrail) to instantaneously trigger email notifications upon any billing deviations. - Infrastructure as Code (IaC): Authored a Bicep template (
main.bicep) to codify and redeploy the network foundation, provisioning a Virtual Network (vnet-enterprise-iac,10.1.0.0/16) with a dedicated subnet (snet-workload,10.1.1.0/24) via the Azure CLI. Demonstrates repeatable, version-controlled infrastructure deployment as an alternative to manual portal configuration. - Governance & Compliance Auditing (Azure Policy): Authored a custom Azure Policy definition (
Audit-Environment-Tag) — cloned from a built-in Microsoft policy and modified from a blockingDenyeffect to a non-disruptiveAuditeffect — to continuously evaluate resources inrg-enterprise-foundationfor a requiredEnvironmenttag. A triggered compliance scan (az policy state trigger-scan) confirmed the policy correctly identifiedvnet-enterprise-primaryas non-compliant, validating real-time governance-as-code enforcement. - Cost & Reliability Review (Azure Advisor): Reviewed Azure Advisor's built-in recommendations engine across all five categories (
Cost,Security,Reliability,Operational Excellence,Performance). Identified 2 active reliability recommendations — aHigh-impact recommendation (Create an Azure Service Health alert) and aMedium-impact recommendation (Use NAT gateway for outbound connectivity) — demonstrating proactive infrastructure health monitoring.
Why this matters: Resource locks and controlled resource-group boundaries map to CIS Control 3 (Data Protection) and NIST 800-53 CM-5 (Access Restrictions for Change) — preventing unauthorized or accidental modification of production infrastructure. Codifying infrastructure as version-controlled templates (rather than manual portal clicks) ensures consistent, auditable, and repeatable deployments — a core practice in modern cloud administration and a direct AZ-104 exam objective. Custom policy authoring — including deliberately choosing
AuditoverDenyfor a first rollout — reflects real-world governance rollout practice (test/observe before enforcing) and CIS Control 4 (Secure Configuration of Enterprise Assets). Regularly reviewing Advisor recommendations reflects FinOps and operational-excellence best practices — catching reliability and cost risks before they become incidents, rather than reacting after the fact.
Project Evidence:
- View Azure Resource Group Deployment
- View Virtual Network Deployment
- View Azure Resource Lock
- View Cost Management Budget Guardrail
- View Bicep Template Code
- View CLI Deployment Success
- View Portal Verification - VNet
- View Portal Verification - Subnet
- View Azure Policy Assignment
- View Policy Compliance Results
- View Azure Advisor Dashboard
- View Reliability Recommendations
Source Code: /iac/main.bicep
Objective: Secure the cloud foundation by establishing robust identity management and a programmatic security perimeter.
Technical Execution:
- Automated Identity Provisioning: Executed a PowerShell automation script utilizing the Microsoft Graph API (
New-MgUser) to programmatically deploy simulated corporate departments into Entra ID. - Dynamic Group Automation: Engineered an Entra ID Dynamic Security Group (
Auto-Finance-Team) utilizing attribute-based queries (user.department -eq "Finance") to automate user lifecycle management and access provisioning. - Role-Based Access Control (RBAC): Enforced the Principle of Least Privilege by assigning targeted
Network Contributorpermissions to specific administrative accounts. - Zero Trust Architecture: Disabled baseline security defaults to engineer a custom Conditional Access policy (
Require-MFA-Privileged-Roles), strictly enforcing Multi-Factor Authentication (MFA) for privileged cloud identities. - Privileged Access: Configured Privileged Identity Management (PIM) for the
Global Administratorrole, enforcing Just-In-Time (JIT) access with a maximum2-houractivation window, requiring Azure MFA and written justification. - Attack Surface Reduction: Deployed a Conditional Access policy (
Block-Legacy-Authentication) targeting all cloud apps to strictly block legacy authentication protocols (e.g., Exchange ActiveSync), mitigating MFA bypass vulnerabilities while retaining a break-glass admin exclusion. - Identity Lifecycle Management: Deployed an automated quarterly Access Review (
Quarterly-Finance-Access-Audit) targeting theAuto-Finance-Teamto continuously audit standing privileges, ensuring access is programmatically revoked if denied by the reviewer. - Risk-Based Conditional Access (Identity Protection): Migrated from the legacy Identity Protection risk-policy blade (now deprecated in favor of Conditional Access) to author two modern, risk-based Conditional Access policies:
Report-Only-Block-High-User-Risk(blocks access for High user risk) andReport-Only-Block-Medium-SignIn-Risk(blocks access for Medium-and-above sign-in risk). Both policies were deployed inReport-onlymode — the industry-standard practice of validating a policy's real-world impact before enforcing it — consistent with theAudit-before-Denyapproach used in Phase 1's governance work. - Identity Governance (Entitlement Management): Designed and deployed a self-service Access Package (
Finance-Team-Access-Package) via a dedicated governance catalog, granting time-limited (90-day) membership to a Finance resource group with mandatory approval and justification requirements. Discovered and documented a key platform constraint during testing: dynamic security groups cannot be used as Entitlement Management resources (membership is rule-computed, not assignable), requiring a purpose-built static group (Finance-Package-Members). Validated the end-to-end request workflow by submitting a live test request, confirming Microsoft Entra's built-in separation-of-duties control that prevents a requestor from approving their own access request. - Enterprise Application SSO (SAML): Configured a full bidirectional SAML 2.0 trust relationship between Microsoft Entra ID and a test service provider (Microsoft Entra SAML Toolkit), including Identifier/Entity ID, Reply URL (ACS), Sign-on URL, signing certificate, and default attribute claim mappings (
givenname,surname,email,UPN) on the Entra side, matched by an equivalent SAML configuration (Login URL, Logout URL, Entra Identifier, and certificate) on the service provider side. Live SP-initiated login testing surfaced a known limitation in the third-party test tool (self-documented as "Alpha stage"), which was diagnosed and documented rather than treated as a configuration failure.
Why this matters: Conditional Access, PIM, and access reviews implement the Zero Trust principles of "verify explicitly" and "least privilege," aligning with NIST 800-53 AC-6 (Least Privilege) and CIS Control 6 (Access Control Management). Risk-based Conditional Access embodies the Zero Trust principle of "assume breach" — continuously evaluating identity signals (impossible travel, leaked credentials, anomalous sign-in patterns) rather than trusting a session just because MFA was satisfied once. Deploying in
Report-onlymode first — rather than immediately enforcing — mirrors real enterprise change-management practice and avoids the risk of self-lockout, a mistake that has caused real production outages. Entitlement Management operationalizes the access-request lifecycle a Jr. IAM Analyst manages daily — self-service requests, approval routing, justification capture, and time-bound expiration — rather than relying on ad hoc manual provisioning. The self-approval restriction encountered during testing reflects a real separation-of-duties control (NIST 800-53 AC-5) that prevents a single individual from both requesting and authorizing their own access, a common audit finding in poorly-governed environments. SAML-based SSO configuration — mapping Entity IDs, ACS URLs, and signing certificates between an Identity Provider and Service Provider — is core IAM work for onboarding any enterprise SaaS application. Correctly diagnosing a third-party tool limitation, rather than assuming a personal misconfiguration, reflects the troubleshooting discipline expected of an IAM analyst working with vendor integrations of varying quality and maturity.
Project Evidence:
- View API Execution & Verification
- View Dynamic Group Automation
- View Azure RBAC Assignment
- View Conditional Access MFA Policy
- View Privileged Identity Management Guardrails
- View Legacy Authentication Block Policy
- View Automated Access Review Configuration
- View Identity Protection Overview
- View User Risk Policy Configuration
- View Sign-in Risk Policy Configuration
- View Access Package Configuration
- View Access Package Policy Summary
- View Access Package Request Submitted
- View SAML SSO Configuration (Entra/IdP Side)
- View SAML SSO Configuration (Toolkit/SP Side)
Objective: Establish a secure data boundary prior to deploying AI tools (like Microsoft 365 Copilot) to prevent unauthorized extraction and exfiltration of confidential corporate data.
AB-900 = Microsoft 365 Certified: Copilot and Agent Administration Fundamentals — a newly released certification covering Copilot/agent governance across Purview, Defender, and Entra ID.
Technical Execution:
- Information Protection: Engineered a Microsoft Purview Sensitivity Label (
Confidential-Finance) to classify and encrypt highly sensitive financial datasets, ensuring artificial intelligence agents cannot bypass human security clearances. - Data Loss Prevention (DLP): Designed an enterprise-wide DLP policy (
Block-External-Financial-Data) to monitor and block the transmission of high-risk data. - DLP Logic Enforced: Configured pattern-matching for Sensitive Information Types (SITs) targeting
U.S. Bank AccountandCredit Card Numberparameters within a custom rule (Enforce Financial Data Protection), programmatically blocking external sharing while satisfying mandatory Microsoft user notifications. - AI Governance & Compliance: Authored and deployed a custom Entra ID Terms of Use document (
Generative-AI-Acceptable-Use-Policy) establishing strict data privacy guardrails for enterprise AI utilization. - Conditional Access Gateway: Engineered a Conditional Access policy (
Enforce-AI-Terms-of-Use) targetingOffice 365applications to serve as a programmatic gateway, strictly forcing users to read, expand, and explicitly consent to the AI ToU prior to accessing Copilot or Microsoft 365 services. - Security Operations (Microsoft Defender XDR): Activated Microsoft Defender XDR's Unified role-based access control (RBAC) model — a permissions-default change Microsoft began enforcing on new tenants in mid-2026 — by diagnosing a Global Administrator access restriction and authoring a custom
XDR-Full-Access-Adminrole scoped toSecurity operationsandSecurity posturepermissions. Reviewed baseline security posture via Microsoft Secure Score, then designed and launched a live Credential Harvest phishing simulation (Phishing-Simulation-Direct) via Attack Simulation Training, tracking full attack-chain telemetry (message delivery, link click, credential submission — 100% compromise rate on a single-target test). Diagnosed and documented that Attack Simulation Training deliberately excludes simulated phishing from the Incidents queue via a dedicated Advanced Delivery override, distinguishing safe security-awareness testing from genuine threat-detection alerting. - AI Data Security Posture (Purview DSPM for AI): Deployed Microsoft Purview's unified Data Security Posture Management (DSPM) experience, activating included Auditing and Analytics while deliberately declining three
Pay-as-you-go-tagged AI collection policies (Copilot interaction capture, Enterprise AI app capture, network-based sensitive-data detection) to preserve zero-cost operation. Reviewed AI-specific Data Security Objectives and the Posture dashboard, confirming the existingBlock-External-Financial-DataDLP policy from this phase was already satisfying the "Prevent exfiltration to risky destinations" objective with a passing status — direct evidence that earlier governance work is actively reducing measured data-security risk. - SIEM Deployment (Microsoft Sentinel): Provisioned a dedicated Log Analytics workspace (
law-enterprise-sentinel) and enabled Microsoft Sentinel on it, using Azure's 31-day / 10GB-per-day free trial allowance. Confirmed Sentinel auto-connected to 7 existing Microsoft security data sources — includingMicrosoft Entra ID Protection(tying directly into this project's Phase 2 risk-based Conditional Access policies) andMicrosoft Defender XDR— without any manual connector configuration required. Authored and executed a KQL query (SecurityAlert | take 10) against the live workspace via Sentinel's Logs blade to validate query functionality and data connectivity.
Why this matters: Sensitivity labels and DLP enforce data-centric security so AI tools like Copilot can't surface data a user wouldn't otherwise have access to — directly addressing the "oversharing" risk in Microsoft's Zero Trust guidance for Copilot, and mapping to NIST 800-53 SC-28 (Protection of Information at Rest). Diagnosing and resolving the Unified RBAC access restriction reflects a real, current change security administrators are encountering as Microsoft rolls out this permission model — troubleshooting access issues under a live task is itself a core Defender-admin skill. Running phishing simulations and interpreting compromise-rate telemetry is standard security-awareness practice (NIST 800-53 AT-2, Security Awareness Training), and correctly identifying why simulated attacks are excluded from the real incident pipeline — rather than assuming a misconfiguration — demonstrates the same "verify before escalating" judgment expected of a Tier-1 SOC analyst. Recognizing and declining a metered/consumption-billed feature during a hands-on walkthrough — rather than enabling it by default — reflects the same cost-governance discipline applied throughout this project (see Phase 1's Azure Advisor review). KQL query authoring is the single most-requested technical skill in SOC L1/Jr SOC job postings, and a SIEM that automatically ingests from Entra ID Protection and Defender XDR demonstrates a genuinely integrated security stack rather than disconnected point tools.
Project Evidence:
- View Purview Data Governance Label
- View Data Loss Prevention Logic Setup
- View AI Acceptable Use Policy Configuration
- View Terms of Use Conditional Access Gateway
- View Secure Score Baseline
- View Incidents Queue Baseline
- View Phishing Simulation Landing Page
- View Simulation Report Dashboard
- View Pay-as-you-go Collection Policies Declined
- View Data Security Objectives
- View DSPM Posture Overview
- View Sentinel Workspace Creation
- View Connected Data Sources
- View KQL Query Execution
This project is actively being expanded to deepen coverage of AZ-104, SC-300, and AB-900 exam objectives — and to reflect real-world SOC, IAM, and cloud admin job requirements.
- Phase 1: Infrastructure as Code — redeploy RG/VNet via Bicep
- Phase 1: Azure Policy — custom governance policy assignment
- Phase 1: Azure Advisor — cost & security recommendations review
- Phase 2: Entra ID Identity Protection — risk-based Conditional Access
- Phase 2: Identity Governance — Entitlement Management (Access Packages)
- Phase 2: Enterprise App SSO — SAML/OIDC test app integration
- Phase 3: Microsoft Defender XDR — Unified RBAC setup, Secure Score review, and live phishing simulation
- Phase 3: Purview DSPM for AI — Copilot/agent data risk assessment
- Phase 3: Microsoft Sentinel — SIEM data connector + KQL query (free-trial workspace)
- Phase 3 (stretch, requires isolated VM): Full Defender for Endpoint incident triage — deferred to avoid onboarding real personal-device telemetry to the tenant
Every resource in this project was built using Azure free-tier services, always-free Azure features, and time-boxed Microsoft 365 E5 / Azure trial licensing. Total cost: $0. Where a service includes a time-limited free trial (e.g., Microsoft Sentinel's 31-day / 10 GB-per-day free allowance), resources were monitored and decommissioned before the trial period ended to avoid any charges.