Enterprise Identity & Access Management Platform  ·  View 11 of 27  ·  Data

Identity Data Zones, Classification & Retention

What identity data exists, who owns each zone, and how long it stays.

Editable source SVG draw.io All views
Identity state — read on every access decision, replicated by Microsoft
Identity state — read on every access decision, replicated by Microsoft
Directory data · Confidential · owner: IAM platform
Directory data · Confidential · owner: IAM platform
Entra directory objects
geo-pinned to EU
Entra directory objects...
External ID directory
customer PII
External ID directory...
Entitlement & review state
retained 7 years
Entitlement & review state...
Credential material · Secret · owner: security engineering
Credential material · Secret · owner: security engineering
Key Vault
soft delete + purge protection
Key Vault...
Managed HSM
FIPS 140-3 Level 3
Managed HSM...
Authentication methods
non-exportable by design
Authentication methods...
Identity telemetry — append-only, ours to retain and defend
Identity telemetry — append-only, ours to retain and defend
Hot · 90 days interactive · owner: SecOps
Hot · 90 days interactive · owner: SecOps
Sign-in logs
2.6M/day
Sign-in logs...
Audit logs
every directory write
Audit logs...
Provisioning logs
Provisioning logs
Risk detections
ID Protection
Risk detections...
Long-term · evidence · owner: compliance
Long-term · evidence · owner: compliance
Log Analytics archive
2 years, low cost tier
Log Analytics archive...
Immutable storage
7 years, WORM policy
Immutable storage...
Privileged-access evidence
PIM + review packs
Privileged-access evidence...
Workday HCM
system of record for people
Workday HCM...
Microsoft Sentinel
detection consumer
Microsoft Sentinel...
Internal audit & regulator
Internal audit & regulator
person attributes only
person attributes only
continuous
continuous
at 90 days
at 90 days
on request, read-only
on request, read-only
Identity Data Zones, Classification & Retention
Identity Data Zones, Classification & Retention
Data store
Data store
Security / platform
Security / platform
External / third party
External / third party
Person or role
Person or role
batch
batch
event / async
event / async
synchronous
synchronous
Nothing here is a copy of the directory. The one deliberate duplication is the evidence archive, because an audit trail that a tenant administrator can delete is not an audit trail.
Nothing here is a copy of the directory. The one deliberate duplication is the evidence archive, because an audit trail that a tenant administrator can delete is not an audit trail.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display

Ownership

  • Four zones, four owners: IAM platform holds directory data, security engineering holds credential material, SecOps holds hot telemetry, compliance holds the evidence archive. Shared ownership of identity data is how retention obligations get missed.
  • Credential material is a separate zone with a separate classification because it needs different controls, not merely tighter ones: purge protection, HSM backing, and no export path at all.
  • Workday remains the system of record for people. The directory holds a projection of person attributes and is authoritative only for access.

Retention

  • 90 days interactive in Log Analytics, two years in the archive tier, seven years immutable for privileged-access evidence. The last is set by audit obligation, not by engineering preference.
  • Directory data is pinned to the EU data boundary. Confirm residency requirements per client — this is an exercise assumption that changes tenant configuration if wrong.
  • The evidence archive is immutable with a WORM policy, so a compromised tenant administrator cannot erase the record of the compromise.

Cost note

  • 240 GB per day at analytics-tier pricing dominates the run cost. Sign-in logs are roughly 70% of that volume.
  • Verbose logs — non-interactive sign-ins in particular — go to the basic tier and the archive, with only the summary in the analytics tier. That split is the single largest cost lever in the platform.
  • Sentinel commitment tiers are sized against the analytics-tier volume only; re-check whenever the log split changes.