Enterprise Identity & Access Management Platform  ·  View 05 of 27  ·  Structure

Platform Component Architecture

What is actually deployed, and the small part of it that we operate.

Editable source SVG draw.io All views
Enterprise Identity & Access Platform — Azure
Enterprise Identity & Access Platform — Azure
Identity control plane — configured SaaS, no infrastructure we run
Identity control plane — configured SaaS, no infrastructure we run
Entra ID tenant
directory + STS
Entra ID tenant...
External ID tenant
CIAM user flows
External ID tenant...
Conditional Access
38 policies
Conditional Access...
PIM
roles + groups
PIM...
Provisioning & lifecycle
Provisioning & lifecycle
Inbound provisioning API
Function · Workday feed
Inbound provisioning API...
Cloud Sync agents
2 per AD forest
Cloud Sync agents...
SCIM outbound
142 gallery apps
SCIM outbound...
Lifecycle Workflows
joiner · mover · leaver
Lifecycle Workflows...
Governance & policy as code
Governance & policy as code
ID Governance
access packages
ID Governance...
Approval connector
Logic Apps to ServiceNow
Approval connector...
IaC repository
Bicep + Terraform azuread
IaC repository...
Drift detector
Function, daily what-if
Drift detector...
Enforcement & secrets
Enforcement & secrets
API Management
internal VNet mode
API Management...
Front Door + WAF
Front Door + WAF
Key Vault per environment
RBAC · purge protection
Key Vault per environment...
Managed HSM
signing & root keys
Managed HSM...
Telemetry & detection
Telemetry & detection
Diagnostic settings
tenant + subscription
Diagnostic settings...
Event Hubs
log fan-out
Event Hubs...
Log Analytics workspace
240 GB/day
Log Analytics workspace...
Sentinel
27 identity rules
Sentinel...
Workday HCM
Workday HCM
AD DS forests
2
AD DS forests...
SaaS estate
900 apps
SaaS estate...
GitHub & Azure DevOps
GitHub & Azure DevOps
ServiceNow
ServiceNow
worker API, hourly
worker API, hourly
LDAP, 2-min delta
LDAP, 2-min delta
SCIM 2.0
SCIM 2.0
REST approval
REST approval
pull request
pull request
streamed events
streamed events
Platform Component Architecture
Platform Component Architecture
Security / platform
Security / platform
Interface / broker
Interface / broker
Queue / topic
Queue / topic
Data store
Data store
External / third party
External / third party
batch
batch
synchronous
synchronous
event / async
event / async
Four components are ours to operate: the provisioning Function, the Cloud Sync agents, the approval connector and the drift detector. Everything else is configured Microsoft service, which is the point.
Four components are ours to operate: the provisioning Function, the Cloud Sync agents, the approval connector and the drift detector. Everything else is configured Microsoft service, which is the point.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display

Build versus configure

  • Four components are ours to run: the Workday inbound provisioning Function, the Cloud Sync agents, the ServiceNow approval connector and the drift detector. Everything else is configured Microsoft service.
  • Custom code was allowed only where a supported connector does not exist. Each of the four has an owner, a runbook and an alert; that is the price of writing it at all.
  • The drift detector exists because portal changes cannot be banned outright — a control that blocks incident response gets disabled. Detection within 24 hours and reconciliation into the repository is the workable version.

Numbers

  • 38 Conditional Access policies, 142 SCIM-provisioned applications, 18 Key Vaults (one per environment per landing zone class), 27 Sentinel identity analytics rules.
  • 240 GB per day of identity telemetry into Log Analytics. Log ingestion, not licensing, is the dominant run cost of this platform.
  • Two Cloud Sync agents per AD forest for availability. They hold no inbound firewall rule: all traffic is outbound 443.

Deliberate omissions

  • Network placement is not shown here — view 20 has private endpoints, VNet integration and the regional split.
  • The identity control plane is drawn as one box per service; its internal redundancy is Microsoft's and is out of our control (view 27, row 1).
  • Only six of the twelve interfaces are drawn, chosen for the ones that carry state. View 06 is the complete catalogue.