Enterprise Identity & Access Management Platform

Solution Architecture v1.0 · Data & AI Global Practice · 2026-08 · 27 views · Microsoft Azure

A multi-tenant, zero-trust identity and access platform on Azure covering human, external and workload identity, authentication, layered authorization, privileged access, governance, secrets and auditability. Five decisions carry the design: a second tenant for customer identity so the boundary is structural rather than procedural; managed identity and workload identity federation so long-lived credentials are eliminated instead of rotated; three separate authorization layers, because an app role can never answer whose data a caller may touch; zero standing privileged access, with PIM as the only path rather than the preferred one; and every role, policy and Conditional Access rule deployed as code with drift reconciled daily.

27 views 27 HTML views27 SVG27 draw.io Updated 2026-08-29
Architecture views

27 views, each in three formats.

Open a view to read it in full. Every SVG carries its diagram source inside it, so it opens in diagrams.net fully editable with no import step; the draw.io files are the same diagrams as plain source.

  1. 01
    System Context

    Who this platform issues identity to, what it governs access to, and what it deliberately never holds.

  2. 02
    High-Level Architecture

    The path from an identity source to an authorized action, in one picture.

  3. 03
    Identity Estate & Tenancy Model

    Which classes of identity exist, and which directory each one lives in.

  4. 04
    Layered Architecture

    What depends on what, and the one dependency that points the wrong way.

  5. 05
    Platform Component Architecture

    What is actually deployed, and the small part of it that we operate.

  6. 06
    Integration Architecture

    Every way an external system touches identity, with its protocol, direction and cadence.

  7. 07
    Tenant, Management Group & Environment Topology

    Where role assignments bind, and why a development identity cannot reach production.

  8. 08
    Authorization Layers

    Four gates, four different questions — and what happens when one is skipped.

  9. 09
    Identity & Entitlement Data Model

    The state an access decision reads, and how a person joins to a permission.

  10. 10
    Identity Data Flow

    How a hire in Workday becomes an entitlement in an application, and evidence in an archive.

  11. 11
    Identity Data Zones, Classification & Retention

    What identity data exists, who owns each zone, and how long it stays.

  12. 12
    Workforce SSO & Conditional Access

    One employee sign-in, including the parts that usually do not happen.

  13. 13
    Conditional Access Policy Matrix

    Eight personas, and what each is required to prove before access is granted.

  14. 14
    API Authorization

    One API call, from client token to the row it is allowed to read.

  15. 15
    Workload Identity Patterns

    Four kinds of workload, and how each proves who it is without holding a secret.

  16. 16
    Privileged Elevation

    How an administrator obtains production rights, and how they go away again.

  17. 17
    Joiner, Mover, Leaver

    The lifecycle, including the population that has no leaver event at all.

  18. 18
    Secret & Certificate Lifecycle

    The loop that has to close without a deployment.

  19. 19
    External Identity

    A customer signing in, a partner employee reaching a corporate resource, and the line between them.

  20. 20
    Deployment & Network Architecture

    What runs where, what is private, and which failure domain belongs to whom.

  21. 21
    Identity as Code

    How an access change reaches production, and what stops a bad one.

  22. 22
    Identity Observability & Detection

    Seven signal families, and what each one causes to happen.

  23. 23
    Access Review & Recertification

    Who still needs what, decided by someone who can actually tell.

  24. 24
    Zero-Trust Zones & Enforcement Points

    Where an attacker arrives, what stops them, and what an administrator still cannot reach.

  25. 25
    Multi-Tenant Isolation

    Three layers, because each one alone has a known bypass.

  26. 26
    Break-Glass & Identity Recovery

    The path that exists precisely because every other path has failed.

  27. 27
    Threats & Failure Modes

    Eight ways this platform is degraded or attacked, and what is left over after the mitigation.

The package

Everything as it was delivered.

These files are served exactly as they were produced — the diagram pages keep their own house style because that is the artifact, not a rendering of it.