Four zones, four owners: IAM platform holds directory data, security engineering holds credential material, SecOps holds hot telemetry, compliance holds the evidence archive. Shared ownership of identity data is how retention obligations get missed.
Credential material is a separate zone with a separate classification because it needs different controls, not merely tighter ones: purge protection, HSM backing, and no export path at all.
Workday remains the system of record for people. The directory holds a projection of person attributes and is authoritative only for access.
Retention
90 days interactive in Log Analytics, two years in the archive tier, seven years immutable for privileged-access evidence. The last is set by audit obligation, not by engineering preference.
Directory data is pinned to the EU data boundary. Confirm residency requirements per client — this is an exercise assumption that changes tenant configuration if wrong.
The evidence archive is immutable with a WORM policy, so a compromised tenant administrator cannot erase the record of the compromise.
Cost note
240 GB per day at analytics-tier pricing dominates the run cost. Sign-in logs are roughly 70% of that volume.
Verbose logs — non-interactive sign-ins in particular — go to the basic tier and the archive, with only the summary in the analytics tier. That split is the single largest cost lever in the platform.
Sentinel commitment tiers are sized against the analytics-tier volume only; re-check whenever the log split changes.