Four components are ours to run: the Workday inbound provisioning Function, the Cloud Sync agents, the ServiceNow approval connector and the drift detector. Everything else is configured Microsoft service.
Custom code was allowed only where a supported connector does not exist. Each of the four has an owner, a runbook and an alert; that is the price of writing it at all.
The drift detector exists because portal changes cannot be banned outright — a control that blocks incident response gets disabled. Detection within 24 hours and reconciliation into the repository is the workable version.
Numbers
38 Conditional Access policies, 142 SCIM-provisioned applications, 18 Key Vaults (one per environment per landing zone class), 27 Sentinel identity analytics rules.
240 GB per day of identity telemetry into Log Analytics. Log ingestion, not licensing, is the dominant run cost of this platform.
Two Cloud Sync agents per AD forest for availability. They hold no inbound firewall rule: all traffic is outbound 443.
Deliberate omissions
Network placement is not shown here — view 20 has private endpoints, VNet integration and the regional split.
The identity control plane is drawn as one box per service; its internal redundancy is Microsoft's and is out of our control (view 27, row 1).
Only six of the twelve interfaces are drawn, chosen for the ones that carry state. View 06 is the complete catalogue.