Enterprise Identity & Access Management Platform

Architecture Views

27 views, in reading order. Every view ships three ways: an HTML page, an SVG that re-opens in diagrams.net fully editable, and draw.io source.

A multi-tenant, zero-trust identity and access platform on Azure covering human, external and workload identity, authentication, layered authorization, privileged access, governance, secrets and auditability. The set reads in six acts: what sits inside the boundary, how the parts fit, where identity data lives and who owns it, what happens at runtime, how it is operated, and why it is safe. Five decisions carry the whole design — a second tenant for customer identity so the boundary is structural rather than procedural (views 03 and 19); managed identity and workload identity federation so long-lived credentials are eliminated instead of rotated (view 15); three separate authorization layers because an app role can never answer whose data a caller may touch (views 08 and 25); zero standing privileged access, with PIM as the only path rather than the preferred one (view 16); and every role, policy and Conditional Access rule deployed as code with drift reconciled daily (view 21).

Context and scope

What the platform is accountable for, which identity classes exist, and where the tenant boundaries fall.
01
External identities
External identities
Partner workforce
34 partner tenants
Partner workforce...
Customers
1.2M CIAM
Customers...
Human identities
Human identities
Employees
45,000
Employees...
Contractors
8,000 · sponsored
Contractors...
Privileged administrators
190 role holders
Privileged administrators...
Break-glass accounts
2 · standing
Break-glass accounts...
Systems of record
Systems of record
Workday HCM
Workday HCM
On-premises AD DS
On-premises AD DS
SaaS applications
900 apps
SaaS applications...
ServiceNow
ServiceNow
Enterprise Identity & Access Platform
Zero-trust · multi-tenant · Azure
Enterprise Identity & Access Platform...
Workloads and resources under control
Workloads and resources under control
Azure resource estate
22 subscriptions
Azure resource estate...
AKS & app workloads
3,400 workload IDs
AKS & app workloads...
CI/CD pipelines
GitHub · Azure DevOps
CI/CD pipelines...
Security operations
Sentinel · Defender
Security operations...
SSO + passwordless
SSO + passwordless
time-bound package
time-bound package
JIT elevation
JIT elevation
emergency only
emergency only
B2B cross-tenant
B2B cross-tenant
sign-up / sign-in
sign-up / sign-in
worker records, hourly
worker records, hourly
hybrid sync
hybrid sync
SSO + SCIM
SSO + SCIM
approvals, tickets
approvals, tickets
Azure RBAC
Azure RBAC
workload identity
workload identity
OIDC federation
OIDC federation
identity signals
identity signals
Enterprise Identity & Access Platform — System Context
Enterprise Identity & Access Platform — System Context
External / third party
External / third party
Person or role
Person or role
Risk / gap
Risk / gap
synchronous
synchronous
batch
batch
two-way
two-way
event / async
event / async
Every arrow is an identity relationship. Business data flows between these systems are deliberately absent: this platform decides who may move that data, it never carries it.
Every arrow is an identity relationship. Business data flows between these systems are deliberately absent: this platform decides who may move that data, it never carries it.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
System Context Who this platform issues identity to, what it governs access to, and what it deliberately never holds. HTML page SVG draw.io
02
Identity sources
Identity sources
Workday HCM
authoritative for people
Workday HCM...
On-prem AD DS
legacy apps only
On-prem AD DS...
Partner Entra tenants
Partner Entra tenants
Customer sign-up
self-service
Customer sign-up...
Identity authority
Identity authority
Microsoft Entra ID
corporate tenant
Microsoft Entra ID...
Entra External ID
CIAM tenant
Entra External ID...
Inbound provisioning
API-driven, hourly
Inbound provisioning...
Entra Cloud Sync
AD DS to cloud
Entra Cloud Sync...
Access decision
Access decision
Conditional Access
policy decision point
Conditional Access...
Entra ID Protection
risk signals
Entra ID Protection...
Authentication methods
FIDO2 · passkey · TAP
Authentication methods...
Entra PIM
JIT elevation
Entra PIM...
Enforcement & authorization
Enforcement & authorization
API Management
JWT validation
API Management...
Azure RBAC
resource authorization
Azure RBAC...
App roles & scopes
application authorization
App roles & scopes...
Azure Key Vault
RBAC data plane
Azure Key Vault...
Resources & assurance
Resources & assurance
Azure resource estate
22 subscriptions
Azure resource estate...
Applications & AKS
managed identity
Applications & AKS...
Log Analytics
240 GB/day
Log Analytics...
Microsoft Sentinel
identity detections
Microsoft Sentinel...
risk level
risk level
time-bound
time-bound
sign-in & audit logs
sign-in & audit logs
analytics rules
analytics rules
High-Level Architecture — one identity, end to end
High-Level Architecture — one identity, end to end
External / third party
External / third party
Security / platform
Security / platform
Interface / broker
Interface / broker
Application we own
Application we own
Data store
Data store
event / async
event / async
synchronous
synchronous
The control plane drawn once, left to right. Governance, secret rotation and the failure paths are omitted here and carried by views 17, 18 and 27.
The control plane drawn once, left to right. Governance, secret rotation and the failure paths are omitted here and carried by views 17, 18 and 27.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
High-Level Architecture The path from an identity source to an authorized action, in one picture. HTML page SVG draw.io
03
Corporate Entra tenant — contoso.com
Corporate Entra tenant — contoso.com
Workforce identities — HR-sourced, never hand-created
Workforce identities — HR-sourced, never hand-created
Employees
45,000
Employees...
Contractors
8,000 · expiry mandatory
Contractors...
Administrators
190 · eligible only
Administrators...
Break-glass
2 · permanent Global Admin
Break-glass...
Guest identities — governed by cross-tenant access settings
Guest identities — governed by cross-tenant access settings
B2B guests
6,500 · 90-day review
B2B guests...
Partner tenants
34 · inbound trust
Partner tenants...
Trusted MFA claims
cross-tenant inbound
Trusted MFA claims...
Workload identities — no human owner, always an app owner
Workload identities — no human owner, always an app owner
Managed identities
2,600 · user + system
Managed identities...
Federated credentials
640 · OIDC subjects
Federated credentials...
App registrations
900 · roles & scopes
App registrations...
Secret-bearing SPs
170 · legacy, decreasing
Secret-bearing SPs...
Entra External ID tenant — customers.contoso.com
Entra External ID tenant — customers.contoso.com
Customer identities
Customer identities
Customer accounts
1.2M
Customer accounts...
Social & partner IdPs
Google · Apple · SAML
Social & partner IdPs...
Customer-facing applications
Customer-facing applications
Customer web & mobile
user flows
Customer web & mobile...
Customer APIs
tenant-scoped tokens
Customer APIs...
Workday HCM
system of record
Workday HCM...
On-prem AD DS
Kerberos apps
On-prem AD DS...
provisioning, hourly
provisioning, hourly
Cloud Sync
Cloud Sync
invited, sponsored
invited, sponsored
federated sign-up
federated sign-up
migration target
migration target
Identity Estate & Tenancy Model
Identity Estate & Tenancy Model
Person or role
Person or role
Risk / gap
Risk / gap
External / third party
External / third party
Security / platform
Security / platform
Application we own
Application we own
Interface / broker
Interface / broker
batch
batch
synchronous
synchronous
failure / alternate
failure / alternate
Two tenants, one platform. The line between them is a tenant boundary rather than a policy, so no customer identity can ever be evaluated against a corporate administrative role.
Two tenants, one platform. The line between them is a tenant boundary rather than a policy, so no customer identity can ever be evaluated against a corporate administrative role.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Identity Estate & Tenancy Model Which classes of identity exist, and which directory each one lives in. HTML page SVG draw.io

Structure

The layering rule, the components, every interface, the management-group topology, and the three questions authorization has to answer separately.
04
Experience
Experience
Workforce apps
browser · desktop · mobile
Workforce apps...
Admin portals
Azure · Entra · M365
Admin portals...
Customer web & mobile
Customer web & mobile
My Access self-service
request · review · attest
My Access self-service...
Access enforcement
Access enforcement
Front Door + WAF
Front Door + WAF
API Management
validate-jwt policy
API Management...
Entra Private Access
legacy app access
Entra Private Access...
Application Proxy
on-prem web apps
Application Proxy...
Identity authority
Identity authority
Microsoft Entra ID
OIDC · OAuth2 · SAML
Microsoft Entra ID...
Entra External ID
Entra External ID
Conditional Access
policy decision point
Conditional Access...
ID Protection
user & sign-in risk
ID Protection...
Authorization
Authorization
Azure RBAC
MG · sub · RG · resource
Azure RBAC...
App roles & scopes
carried in the token
App roles & scopes...
Entra PIM
eligible, not active
Entra PIM...
Application policy engine
tenant + row decisions
Application policy engine...
Governance & secrets
Governance & secrets
Entra ID Governance
packages · reviews · LCW
Entra ID Governance...
Azure Key Vault
secrets · keys · certs
Azure Key Vault...
Azure Policy
deny · audit · DINE
Azure Policy...
Identity as code
Bicep + Terraform
Identity as code...
Resource plane
Resource plane
Azure subscriptions
22 · 4 environments
Azure subscriptions...
AKS clusters
workload identity
AKS clusters...
Data services
SQL · Cosmos · Storage
Data services...
SaaS applications
SSO + SCIM
SaaS applications...
Telemetry
Telemetry
Azure Monitor
Azure Monitor
Log Analytics
90-day interactive
Log Analytics...
Microsoft Sentinel
identity analytics
Microsoft Sentinel...
Defender for Cloud
posture & CIEM
Defender for Cloud...
OIDC metadata, JWKS
OIDC metadata, JWKS
authorized principal
authorized principal
eligibility & reviews
eligibility & reviews
role assignments
role assignments
diagnostic settings
diagnostic settings
group lookup on the request path
group lookup on the request path
Layered Architecture — what depends on what
Layered Architecture — what depends on what
Application we own
Application we own
Interface / broker
Interface / broker
Security / platform
Security / platform
Data store
Data store
External / third party
External / third party
synchronous
synchronous
event / async
event / async
failure / alternate
failure / alternate
Dependencies point downward. The single upward call, an application resolving group membership from Graph while serving a request, is drawn red because it turns the identity service into a runtime dependency; view 27 carries its mitigation.
Dependencies point downward. The single upward call, an application resolving group membership from Graph while serving a request, is drawn red because it turns the identity service into a runtime dependency; view 27 carries its mitigation.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Layered Architecture What depends on what, and the one dependency that points the wrong way. HTML page SVG draw.io
05
Enterprise Identity & Access Platform — Azure
Enterprise Identity & Access Platform — Azure
Identity control plane — configured SaaS, no infrastructure we run
Identity control plane — configured SaaS, no infrastructure we run
Entra ID tenant
directory + STS
Entra ID tenant...
External ID tenant
CIAM user flows
External ID tenant...
Conditional Access
38 policies
Conditional Access...
PIM
roles + groups
PIM...
Provisioning & lifecycle
Provisioning & lifecycle
Inbound provisioning API
Function · Workday feed
Inbound provisioning API...
Cloud Sync agents
2 per AD forest
Cloud Sync agents...
SCIM outbound
142 gallery apps
SCIM outbound...
Lifecycle Workflows
joiner · mover · leaver
Lifecycle Workflows...
Governance & policy as code
Governance & policy as code
ID Governance
access packages
ID Governance...
Approval connector
Logic Apps to ServiceNow
Approval connector...
IaC repository
Bicep + Terraform azuread
IaC repository...
Drift detector
Function, daily what-if
Drift detector...
Enforcement & secrets
Enforcement & secrets
API Management
internal VNet mode
API Management...
Front Door + WAF
Front Door + WAF
Key Vault per environment
RBAC · purge protection
Key Vault per environment...
Managed HSM
signing & root keys
Managed HSM...
Telemetry & detection
Telemetry & detection
Diagnostic settings
tenant + subscription
Diagnostic settings...
Event Hubs
log fan-out
Event Hubs...
Log Analytics workspace
240 GB/day
Log Analytics workspace...
Sentinel
27 identity rules
Sentinel...
Workday HCM
Workday HCM
AD DS forests
2
AD DS forests...
SaaS estate
900 apps
SaaS estate...
GitHub & Azure DevOps
GitHub & Azure DevOps
ServiceNow
ServiceNow
worker API, hourly
worker API, hourly
LDAP, 2-min delta
LDAP, 2-min delta
SCIM 2.0
SCIM 2.0
REST approval
REST approval
pull request
pull request
streamed events
streamed events
Platform Component Architecture
Platform Component Architecture
Security / platform
Security / platform
Interface / broker
Interface / broker
Queue / topic
Queue / topic
Data store
Data store
External / third party
External / third party
batch
batch
synchronous
synchronous
event / async
event / async
Four components are ours to operate: the provisioning Function, the Cloud Sync agents, the approval connector and the drift detector. Everything else is configured Microsoft service, which is the point.
Four components are ours to operate: the provisioning Function, the Cloud Sync agents, the approval connector and the drift detector. Everything else is configured Microsoft service, which is the point.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Platform Component Architecture What is actually deployed, and the small part of it that we operate. HTML page SVG draw.io
06
Inbound — systems that call the platform
Inbound — systems that call the platform
Workday HCM
worker API
Workday HCM...
AD DS forests
2 forests
AD DS forests...
Partner Entra tenants
34
Partner Entra tenants...
Customer applications
Customer applications
GitHub & Azure DevOps
GitHub & Azure DevOps
AKS clusters
11 clusters
AKS clusters...
Enterprise Identity & Access Platform
Enterprise Identity & Access Platform
Entra ID tenant
STS + directory
Entra ID tenant...
Entra External ID
CIAM tenant
Entra External ID...
API Management
token enforcement
API Management...
Outbound — systems the platform calls
Outbound — systems the platform calls
SaaS estate
900 apps
SaaS estate...
Azure Resource Manager
Azure Resource Manager
ServiceNow
ServiceNow
Key Vault estate
18 vaults
Key Vault estate...
Microsoft Sentinel
Microsoft Sentinel
Teams & Exchange
Teams & Exchange
hourly worker delta
hourly worker delta
Cloud Sync, 2 min
Cloud Sync, 2 min
cross-tenant OIDC
cross-tenant OIDC
OIDC + PKCE
OIDC + PKCE
OIDC federation
OIDC federation
projected SA token
projected SA token
SCIM 2.0 + SAML
SCIM 2.0 + SAML
role assignments
role assignments
approvals & JML tickets
approvals & JML tickets
certificate issuance
certificate issuance
log stream, near real time
log stream, near real time
approval notifications
approval notifications
Integration Architecture — every identity interface
Integration Architecture — every identity interface
External / third party
External / third party
Security / platform
Security / platform
Interface / broker
Interface / broker
batch
batch
synchronous
synchronous
event / async
event / async
Twelve interfaces, none of them bespoke: eleven are Microsoft-supported connectors or standard protocols, and only the Workday inbound feed is custom code we maintain.
Twelve interfaces, none of them bespoke: eleven are Microsoft-supported connectors or standard protocols, and only the Workday inbound feed is custom code we maintain.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Integration Architecture Every way an external system touches identity, with its protocol, direction and cadence. HTML page SVG draw.io
07
Microsoft Entra tenant — contoso.com · the identity boundary for every scope below
Microsoft Entra tenant — contoso.com · the identity boundary for every scope below
Platform management group — run by the platform team, never by application teams
Platform management group — run by the platform team, never by application teams
Identity subscription
Identity subscription
Cloud Sync agents
Cloud Sync agents
Platform Key Vault
Platform Key Vault
Management subscription
Management subscription
Log Analytics
tenant-wide
Log Analytics...
Sentinel
Sentinel
Connectivity subscription
Connectivity subscription
Hub VNet + Firewall
Hub VNet + Firewall
Private DNS zones
Private DNS zones
Landing zone management groups — RBAC differs by environment, and only by environment
Landing zone management groups — RBAC differs by environment, and only by environment
DEV
DEV
6 subscriptions
6 subscriptions
Contributor, standing
team group
Contributor, standing...
TEST
TEST
4 subscriptions
4 subscriptions
Contributor, standing
engineering group
Contributor, standing...
STAGE
STAGE
3 subscriptions
3 subscriptions
PIM eligible
no approval, MFA
PIM eligible...
PROD — stricter by construction
PROD — stricter by construction
5 subscriptions
5 subscriptions
PIM eligible
approval + MFA + 4 h
PIM eligible...
Resource locks
CanNotDelete
Resource locks...
Sandbox & decommissioned — policy-isolated, no connectivity to the hub
Sandbox & decommissioned — policy-isolated, no connectivity to the hub
Sandbox
Sandbox
2 subscriptions
no data, no peering
2 subscriptions...
Decommissioned
Decommissioned
Quarantine
deny all inbound roles
Quarantine...
Entra security groups
one per app per environment
Entra security groups...
Azure Policy
cross-environment deny
Azure Policy...
assigned at MG scope
assigned at MG scope
eligible at MG scope
eligible at MG scope
deny foreign-env principal
deny foreign-env principal
Tenant, Management Group & Environment Topology
Tenant, Management Group & Environment Topology
Interface / broker
Interface / broker
Security / platform
Security / platform
Data store
Data store
Application we own
Application we own
Risk / gap
Risk / gap
synchronous
synchronous
failure / alternate
failure / alternate
There is no cross-environment principal. A group that holds any role in DEV is denied every role assignment in PROD by policy, so an over-permissioned developer identity cannot become a production incident.
There is no cross-environment principal. A group that holds any role in DEV is denied every role assignment in PROD by policy, so an over-permissioned developer identity cannot become a production incident.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Tenant, Management Group & Environment Topology Where role assignments bind, and why a development identity cannot reach production. HTML page SVG draw.io
08
Token presented
Token presented
Access token
JWT, 1 h lifetime
Access token...
Signature & issuer
JWKS cached 24 h
Signature & issuer...
Claims read
tid · oid · roles · scp · amr
Claims read...
Layer 1 — Azure RBAC
Layer 1 — Azure RBAC
Scope resolution
MG to resource
Scope resolution...
Role assignment
group-based, PIM-activated
Role assignment...
Deny assignment
policy-managed
Deny assignment...
Layer 2 — Application RBAC
Layer 2 — Application RBAC
App role check
roles claim
App role check...
Scope check
delegated scp
Scope check...
Consent state
admin consent only
Consent state...
Layer 3 — Data & tenant
Layer 3 — Data & tenant
Tenant predicate
tid from token, never body
Tenant predicate...
Row / partition filter
RLS · partition key
Row / partition filter...
Field-level policy
classification-aware
Field-level policy...
Outcome
Outcome
Allow
with effective scope
Allow...
Deny
403 + reason code
Deny...
Audit record
who · what · which layer
Audit record...
invalid token
invalid token
no assignment
no assignment
role absent
role absent
tenant mismatch
tenant mismatch
Authorization Layers — from claim to row
Authorization Layers — from claim to row
Interface / broker
Interface / broker
Decision point
Decision point
Security / platform
Security / platform
Application we own
Application we own
Risk / gap
Risk / gap
Data store
Data store
failure / alternate
failure / alternate
Four gates, four different questions. Collapsing layer 3 into layer 2 is the most common design error in multi-tenant systems: an app role says what a caller may do, never whose data they may do it to.
Four gates, four different questions. Collapsing layer 3 into layer 2 is the most common design error in multi-tenant systems: an app role says what a caller may do, never whose data they may do it to.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Authorization Layers Four gates, four different questions — and what happens when one is skipped. HTML page SVG draw.io

Data

The entitlement model access decisions read, how an HR record becomes an entitlement, and where identity data lives with its classification and retention.
09
tenant
tenant_id PK
kind ENUM(CORP,CIAM,PARTNER)
home_domain
isolation_tier
data_residency
tenant...
identity
object_id PK
tenant_id FK -> tenant
upn
kind ENUM(EMP,CTR,GUEST,CUST,BG)
hr_worker_id
account_enabled
last_sign_in_at
identity...
group
group_id PK
tenant_id FK -> tenant
name (app-env scoped)
source ENUM(DYNAMIC,ASSIGNED,PIM)
owner_id FK -> identity
group...
application
app_id PK
tenant_id FK -> tenant
display_name
sign_in_audience
owner_group_id FK -> group
application...
workload_identity
principal_id PK
tenant_id FK -> tenant
kind ENUM(SYS_MI,USER_MI,SP)
app_id FK -> application
credential ENUM(MI,FIC,SECRET)
owner_group_id
workload_identity...
group_membership
group_id FK -> group
member_id FK -> identity
source ENUM(HR,PACKAGE,PIM)
granted_at
expires_at NULL = permanent
group_membership...
access_package
package_id PK
catalog_id
name
approver_group_id FK -> group
duration_days
review_cadence_days
access_package...
app_role
role_id PK
app_id FK -> application
value (roles claim)
allowed_member_types
requires_admin_consent
app_role...
federated_credential
fic_id PK
principal_id FK -> workload_identity
issuer (OIDC)
subject (repo:env / ns:sa)
audience
created_by
federated_credential...
rbac_role_assignment
assignment_id PK
principal_id (group preferred)
role_definition_id
scope (MG/sub/RG/resource)
condition ABAC NULL
is_pim_eligible
rbac_role_assignment...
entitlement_assignment
assignment_id PK
package_id FK -> access_package
identity_id FK -> identity
state ENUM(PENDING,ACTIVE,EXPIRED)
justification
expires_at
entitlement_assignment...
pim_activation
activation_id PK
assignment_id FK -> rbac_role_assignment
ticket_ref
approver_id FK -> identity
activated_at
expires_at (max 8 h)
auth_strength_met
pim_activation...
access_review_decision
review_id PK
assignment_id FK -> entitlement_assignment
reviewer_id FK -> identity
decision ENUM(APPROVE,DENY,NO_RESP)
decided_at
evidence_uri
access_review_decision...
1 : N
1 : N
1 : N
1 : N
1 : N
1 : N
1 : N
1 : N
grants N : M
grants N : M
grants N : M
grants N : M
1 : N
1 : N
1 : N
1 : N
1 : N
1 : N
principal N : 1
principal N : 1
1 : N
1 : N
1 : N
1 : N
Identity & Entitlement Data Model
Identity & Entitlement Data Model
Sign-in and audit events are deliberately absent: they are append-only telemetry with a different owner and retention, and view 11 places them. Everything drawn here is state that access decisions read.
Sign-in and audit events are deliberately absent: they are append-only telemetry with a different owner and retention, and view 11 places them. Everything drawn here is state that access decisions read.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Identity & Entitlement Data Model The state an access decision reads, and how a person joins to a permission. HTML page SVG draw.io
10
Sources of truth
Sources of truth
Workday worker record
hire · transfer · leave
Workday worker record...
AD DS objects
legacy apps only
AD DS objects...
Customer sign-up
self-service
Customer sign-up...
Application catalogue
owner-attested
Application catalogue...
Ingest & correlate
Ingest & correlate
Inbound provisioning
hourly, 45k workers
Inbound provisioning...
Cloud Sync
2-minute delta
Cloud Sync...
Attribute mapping
employeeId is the join key
Attribute mapping...
Quality gate
manager & cost centre required
Quality gate...
Exception queue
~40 defects/day
Exception queue...
Identity store
Identity store
Entra directory
corporate tenant
Entra directory...
External ID directory
1.2M customers
External ID directory...
Dynamic group evaluation
~4 min to converge
Dynamic group evaluation...
Entitlement state
packages & assignments
Entitlement state...
Distribution
Distribution
SCIM outbound
142 apps, 40-min cycle
SCIM outbound...
Claims at token issuance
roles · groups · tid
Claims at token issuance...
Azure RBAC writes
IaC only
Azure RBAC writes...
Group writeback
cloud groups to AD DS
Group writeback...
Consumption & evidence
Consumption & evidence
Applications
900
Applications...
Azure resources
Azure resources
Log Analytics
90 days interactive
Log Analytics...
Immutable archive
7 years, privileged evidence
Immutable archive...
reject, no identity created
reject, no identity created
membership in token
membership in token
provisioning logs
provisioning logs
nightly export
nightly export
Identity Data Flow — HR record to entitlement to evidence
Identity Data Flow — HR record to entitlement to evidence
External / third party
External / third party
Interface / broker
Interface / broker
Security / platform
Security / platform
Decision point
Decision point
Risk / gap
Risk / gap
Data store
Data store
Application we own
Application we own
failure / alternate
failure / alternate
synchronous
synchronous
event / async
event / async
batch
batch
One join key carries the whole flow. If Workday does not emit employeeId, no identity is created and the record lands in the exception queue: a missing person is a visible defect, an unmatched duplicate is a silent one.
One join key carries the whole flow. If Workday does not emit employeeId, no identity is created and the record lands in the exception queue: a missing person is a visible defect, an unmatched duplicate is a silent one.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Identity Data Flow How a hire in Workday becomes an entitlement in an application, and evidence in an archive. HTML page SVG draw.io
11
Identity state — read on every access decision, replicated by Microsoft
Identity state — read on every access decision, replicated by Microsoft
Directory data · Confidential · owner: IAM platform
Directory data · Confidential · owner: IAM platform
Entra directory objects
geo-pinned to EU
Entra directory objects...
External ID directory
customer PII
External ID directory...
Entitlement & review state
retained 7 years
Entitlement & review state...
Credential material · Secret · owner: security engineering
Credential material · Secret · owner: security engineering
Key Vault
soft delete + purge protection
Key Vault...
Managed HSM
FIPS 140-3 Level 3
Managed HSM...
Authentication methods
non-exportable by design
Authentication methods...
Identity telemetry — append-only, ours to retain and defend
Identity telemetry — append-only, ours to retain and defend
Hot · 90 days interactive · owner: SecOps
Hot · 90 days interactive · owner: SecOps
Sign-in logs
2.6M/day
Sign-in logs...
Audit logs
every directory write
Audit logs...
Provisioning logs
Provisioning logs
Risk detections
ID Protection
Risk detections...
Long-term · evidence · owner: compliance
Long-term · evidence · owner: compliance
Log Analytics archive
2 years, low cost tier
Log Analytics archive...
Immutable storage
7 years, WORM policy
Immutable storage...
Privileged-access evidence
PIM + review packs
Privileged-access evidence...
Workday HCM
system of record for people
Workday HCM...
Microsoft Sentinel
detection consumer
Microsoft Sentinel...
Internal audit & regulator
Internal audit & regulator
person attributes only
person attributes only
continuous
continuous
at 90 days
at 90 days
on request, read-only
on request, read-only
Identity Data Zones, Classification & Retention
Identity Data Zones, Classification & Retention
Data store
Data store
Security / platform
Security / platform
External / third party
External / third party
Person or role
Person or role
batch
batch
event / async
event / async
synchronous
synchronous
Nothing here is a copy of the directory. The one deliberate duplication is the evidence archive, because an audit trail that a tenant administrator can delete is not an audit trail.
Nothing here is a copy of the directory. The one deliberate duplication is the evidence archive, because an audit trail that a tenant administrator can delete is not an audit trail.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Identity Data Zones, Classification & Retention What identity data exists, who owns each zone, and how long it stays. HTML page SVG draw.io

Runtime

The flows that matter: workforce sign-in, API authorization, workload identity, privileged elevation, the joiner-mover-leaver lifecycle, secret rotation and external identity.
12
Employee
Employee
Application
Application
Entra ID
Entra ID
Conditional Access
Conditional Access
Intune device state
Intune device state
FIDO2 passkey
FIDO2 passkey
Log Analytics
Log Analytics
1. open application
1. open application
2. 302 /authorize — OIDC + PKCE
2. 302 /authorize — OIDC + PKCE
3. evaluate existing session (PRT)
3. evaluate existing session (PRT)
4. evaluate policies: user, app, risk
4. evaluate policies: user, app, risk
5. device compliance state
5. device compliance state
6. compliant, Entra-joined
6. compliant, Entra-joined
7. grant: phishing-resistant MFA
7. grant: phishing-resistant MFA
8. WebAuthn challenge
8. WebAuthn challenge
9. signed assertion
9. signed assertion
10. authorization code
10. authorization code
11. code + verifier -> /token
11. code + verifier -> /token
12. id_token + access_token (CAE)
12. id_token + access_token (CAE)
13. session established
13. session established
14. sign-in log + CA result
14. sign-in log + CA result
15. CAE event: session revoked
15. CAE event: session revoked
Workforce SSO & Conditional Access — one sign-in
Workforce SSO & Conditional Access — one sign-in
Steps 8 and 9 are skipped when the session already meets the required authentication strength, which covers roughly 71% of sign-ins. Step 15 is the leaver path: revocation reaches CAE-aware resources in about a minute rather than waiting an hour for token expiry.
Steps 8 and 9 are skipped when the session already meets the required authentication strength, which covers roughly 71% of sign-ins. Step 15 is the leaver path: revocation reaches CAE-aware resources in about a minute rather than waiting an hour for token expiry.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Workforce SSO & Conditional Access One employee sign-in, including the parts that usually do not happen. HTML page SVG draw.io
13
Signals evaluated
Signals evaluated
Authentication strength
Authentication strength
Device & network
Device & network
Session control
Session control
Outcome
Outcome
Employee, managed device
Employee, managed device
Low user & sign-in risk
Low user & sign-in risk
Passkey or MFA
Passkey or MFA
Compliant device
Compliant device
Sign-in frequency 12 h
Sign-in frequency 12 h
Grant
Grant
Administrator to portals
Administrator to portals
Any privileged role
Any privileged role
Phishing-resistant only
Phishing-resistant only
Privileged workstation
Privileged workstation
No persistent session
No persistent session
Grant
Grant
PIM role activation
PIM role activation
Activation request
Activation request
Phishing-resistant + approval
Phishing-resistant + approval
Compliant PAW
Compliant PAW
Lifetime = activation
Lifetime = activation
Grant, time-bound
Grant, time-bound
High-risk sign-in
High-risk sign-in
ID Protection: high
ID Protection: high
Password change + MFA
Password change + MFA
Any
Any
Revoke all sessions
Revoke all sessions
Block until remediated
Block until remediated
B2B guest
B2B guest
Guest + resource app
Guest + resource app
MFA trusted from home tenant
MFA trusted from home tenant
Unmanaged permitted
Unmanaged permitted
1 h, no download
1 h, no download
Grant, restricted
Grant, restricted
Workload identity
Workload identity
Service principal sign-in
Service principal sign-in
Not interactive
Not interactive
Named location allowlist
Named location allowlist
Not applicable
Not applicable
Block outside allowlist
Block outside allowlist
Legacy authentication
Legacy authentication
POP · IMAP · SMTP basic
POP · IMAP · SMTP basic
Cannot satisfy MFA
Cannot satisfy MFA
Any
Any
Not applicable
Not applicable
Block, all users
Block, all users
Break-glass accounts
Break-glass accounts
Excluded from all but one
Excluded from all but one
FIDO2 hardware key only
FIDO2 hardware key only
Any — lockout safety
Any — lockout safety
Alert on every sign-in
Alert on every sign-in
Grant + P1 alert
Grant + P1 alert
Conditional Access Policy Matrix
Conditional Access Policy Matrix
Read as rows, not policies: a persona is the unit a reviewer can reason about. The eight rows compile to 38 Conditional Access policies deployed as code, each in report-only for 14 days before enforcement.
Read as rows, not policies: a persona is the unit a reviewer can reason about. The eight rows compile to 38 Conditional Access policies deployed as code, each in report-only for 14 days before enforcement.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Conditional Access Policy Matrix Eight personas, and what each is required to prove before access is granted. HTML page SVG draw.io
14
Client application
Client application
Entra ID
Entra ID
API Management
API Management
Orders API
Orders API
Downstream API
Downstream API
Azure SQL
Azure SQL
1. auth code or client credentials
1. auth code or client credentials
2. access_token aud=api://orders
2. access_token aud=api://orders
3. GET /orders/{id} + Bearer
3. GET /orders/{id} + Bearer
4. validate-jwt: iss, aud, exp, signature
4. validate-jwt: iss, aud, exp, signature
5. require scp Orders.Read, quota by tid
5. require scp Orders.Read, quota by tid
6. forward + tenant id from claim
6. forward + tenant id from claim
7. app role check, then tenant predicate
7. app role check, then tenant predicate
8. on-behalf-of exchange
8. on-behalf-of exchange
9. downstream token, user-scoped
9. downstream token, user-scoped
10. call with delegated token
10. call with delegated token
11. result
11. result
12. managed identity + RLS context
12. managed identity + RLS context
13. rows for this tenant only
13. rows for this tenant only
14. 200 OK
14. 200 OK
15. 200 + correlation id
15. 200 + correlation id
16. 401 invalid_token / 403 insufficient_scope
16. 401 invalid_token / 403 insufficient_scope
API Authorization — token to gateway to backend to data
API Authorization — token to gateway to backend to data
No connection string and no client secret appears anywhere in this flow. The gateway rejects a malformed or foreign-tenant token before the backend is reached, and the backend still re-checks: the gateway is defence, not the authority.
No connection string and no client secret appears anywhere in this flow. The gateway rejects a malformed or foreign-tenant token before the backend is reached, and the backend still re-checks: the gateway is defence, not the authority.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
API Authorization One API call, from client token to the row it is allowed to read. HTML page SVG draw.io
15
Identity issued
Identity issued
Credential held
Credential held
Token acquired
Token acquired
Resource authorized
Resource authorized
Evidence
Evidence
Azure-hosted app — App Service, Functions
Azure-hosted app — App Service, F...
System-assigned identity
created with the resource
System-assigned identity...
None to hold
platform-managed
None to hold...
IMDS token endpoint
no network egress
IMDS token endpoint...
Azure RBAC
Key Vault, SQL, Storage
Azure RBAC...
MI sign-in log
+ resource activity
MI sign-in log...
AKS pod — workload identity
AKS pod — workload identity
User-assigned identity
bound to service account
User-assigned identity...
Projected SA token
1 h, auto-rotated
Projected SA token...
Federated exchange
cluster OIDC issuer
Federated exchange...
RBAC at namespace RG
one identity per workload
RBAC at namespace RG...
AKS audit + SP sign-in
AKS audit + SP sign-in
CI/CD pipeline — GitHub, Azure DevOps
CI/CD pipeline — GitHub, Azure De...
App registration
one per repo per env
App registration...
Federated credential
subject = repo:env
Federated credential...
OIDC exchange at job start
no stored secret
OIDC exchange at job start...
PIM-activated deploy role
60 minutes
PIM-activated deploy role...
Run log + activation record
Run log + activation record
Legacy SaaS or on-premises — the exception path
Legacy SaaS or on-premises — the...
Service principal
170 remaining
Service principal...
Client secret in Key Vault
never in config
Client secret in Key Vault...
Client credentials grant
Client credentials grant
Least-privilege app role
no Graph write
Least-privilege app role...
Secret access log
90-day rotation SLA
Secret access log...
Workload Identity Patterns — four ways in, one authority
Workload Identity Patterns — four ways in, one authority
Three lanes hold no credential at all. The fourth exists only because 170 integrations cannot yet federate; it is tracked as a burn-down with a named owner per principal, not accepted as a steady state.
Three lanes hold no credential at all. The fourth exists only because 170 integrations cannot yet federate; it is tracked as a burn-down with a named owner per principal, not accepted as a steady state.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Workload Identity Patterns Four kinds of workload, and how each proves who it is without holding a secret. HTML page SVG draw.io
16
Administrator
Administrator
Entra PIM
Entra PIM
Conditional Access
Conditional Access
Approver
Approver
Azure RBAC
Azure RBAC
Production resource
Production resource
Sentinel
Sentinel
1. activate Contributor, 4 h, ticket INC-4471
1. activate Contributor, 4 h, ticket INC-4471
2. evaluate activation policy
2. evaluate activation policy
3. phishing-resistant MFA + PAW met
3. phishing-resistant MFA + PAW met
4. approval request to 2 eligible approvers
4. approval request to 2 eligible approvers
5. approved with justification
5. approved with justification
6. create time-bound assignment
6. create time-bound assignment
7. active until 14:32 UTC
7. active until 14:32 UTC
8. elevated
8. elevated
9. perform the change
9. perform the change
10. authorize at scope
10. authorize at scope
11. allow
11. allow
12. expiry: remove assignment
12. expiry: remove assignment
13. request, approval, expiry events
13. request, approval, expiry events
14. alert: no ticket reference
14. alert: no ticket reference
15. denied — request closed, no access
15. denied — request closed, no access
Privileged Elevation — zero standing access
Privileged Elevation — zero standing access
Nobody holds the role between activations, so the compromise of an administrator account yields eligibility rather than privilege. Median activation is 3.2 per day and the approval path is the only path — PIM cannot be bypassed because the standing assignment does not exist to fall back on.
Nobody holds the role between activations, so the compromise of an administrator account yields eligibility rather than privilege. Median activation is 3.2 per day and the approval path is the only path — PIM cannot be bypassed because the standing assignment does not exist to fall back on.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Privileged Elevation How an administrator obtains production rights, and how they go away again. HTML page SVG draw.io
17
Trigger
Trigger
Identity action
Identity action
Entitlement action
Entitlement action
Access effect
Access effect
Evidence
Evidence
Joiner
Joiner
Workday hire event
with effective date
Workday hire event...
Account created day -7
disabled until start
Account created day -7...
Birthright package
by job family
Birthright package...
SSO + baseline apps
live 08:00 day 1
SSO + baseline apps...
Provisioning log
+ manager notification
Provisioning log...
Mover
Mover
Transfer or manager change
Transfer or manager change
Attributes updated
converges in ~4 min
Attributes updated...
Entitlements recalculated
dynamic groups + review
Entitlements recalculated...
Old access removed 24 h
new access granted
Old access removed 24 h...
Mover exception report
weekly to line manager
Mover exception report...
Leaver
Leaver
Termination event
Termination event
Disable + revoke sessions
immediate
Disable + revoke sessions...
Packages expired
group memberships stripped
Packages expired...
CAE revocation under 1 min
licences released day 7
CAE revocation under 1 min...
30-day hold + evidence pack
30-day hold + evidence pack
Contractor expiry — no HR event exists
Contractor expiry — no HR event...
Package end date
set at grant, mandatory
Package end date...
Sponsor attests or lapses
14-day warning
Sponsor attests or lapses...
Auto-expire, no grace
Auto-expire, no grace
Access ends 00:00
account disabled day 30
Access ends 00:00...
Sponsor attestation record
Sponsor attestation record
Joiner, Mover, Leaver — the identity lifecycle
Joiner, Mover, Leaver — the identity lifecycle
The fourth lane exists because contractors have no leaver event in HR. Expiry is therefore a property of the grant rather than of a downstream process, which is the only version of this that survives a sponsor who leaves first.
The fourth lane exists because contractors have no leaver event in HR. Expiry is therefore a property of the grant rather than of a downstream process, which is the only version of this that survives a sponsor who leaves first.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Joiner, Mover, Leaver The lifecycle, including the population that has no leaver event at all. HTML page SVG draw.io
19
Customer
Customer
Partner employee
Partner employee
Customer application
Customer application
Entra External ID
Entra External ID
Corporate Entra ID
Corporate Entra ID
Partner home tenant
Partner home tenant
Tenant-scoped API
Tenant-scoped API
1. sign up or sign in
1. sign up or sign in
2. OIDC user flow + PKCE
2. OIDC user flow + PKCE
3. local account or Google / Apple
3. local account or Google / Apple
4. step-up: email OTP or authenticator
4. step-up: email OTP or authenticator
5. tokens, tid = CIAM tenant
5. tokens, tid = CIAM tenant
6. call with customer token
6. call with customer token
7. subject to customer_id, load org scope
7. subject to customer_id, load org scope
8. that customer's data only
8. that customer's data only
9. access a contoso resource
9. access a contoso resource
10. cross-tenant: was MFA satisfied?
10. cross-tenant: was MFA satisfied?
11. MFA + device claims, trusted
11. MFA + device claims, trusted
12. guest object + collaboration settings
12. guest object + collaboration settings
13. token: guest, restricted app role
13. token: guest, restricted app role
14. guest predicate: no export, no admin scope
14. guest predicate: no export, no admin scope
15. restricted view
15. restricted view
16. no trust in this direction, by design
16. no trust in this direction, by design
External Identity — customer sign-in and partner federation
External Identity — customer sign-in and partner federation
Two journeys, one rule: the tenant a subject came from is a claim the API reads, never a parameter the caller supplies. The red line is the point of the view — the CIAM tenant can obtain nothing in the corporate tenant, so a customer-facing compromise has no path to an administrative role.
Two journeys, one rule: the tenant a subject came from is a claim the API reads, never a parameter the caller supplies. The red line is the point of the view — the CIAM tenant can obtain nothing in the corporate tenant, so a customer-facing compromise has no path to an administrative role.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
External Identity A customer signing in, a partner employee reaching a corporate resource, and the line between them. HTML page SVG draw.io

Operations

Where it runs, how an access change reaches production, what is watched, and how entitlements are recertified.
20
Microsoft-operated identity plane — global, outside every customer network
Microsoft-operated identity plane — global, outside every customer network
Microsoft Entra ID
Microsoft Entra ID
STS endpoints
99.99% SLA
STS endpoints...
Microsoft Graph
Microsoft Graph
Directory replicas
EU data boundary
Directory replicas...
Entra External ID
Entra External ID
CIAM STS
CIAM STS
User flows
sign-up, reset, MFA
User flows...
Azure — West Europe (primary)
Azure — West Europe (primary)
Hub VNet — platform team
Hub VNet — platform team
Azure Firewall
egress FQDN allowlist
Azure Firewall...
Azure Bastion
no public RDP or SSH
Azure Bastion...
Private DNS resolver
Private DNS resolver
Platform spoke
Platform spoke
Front Door + WAF
global anycast
Front Door + WAF...
API Management
internal VNet mode
API Management...
Key Vault
private endpoint only
Key Vault...
Log Analytics
Log Analytics
Application spoke
Application spoke
AKS private cluster
workload identity on
AKS private cluster...
App Service
VNet integrated
App Service...
Azure SQL
private endpoint, Entra auth
Azure SQL...
Azure — North Europe (secondary)
Azure — North Europe (secondary)
Warm standby — RTO 4 h
Warm standby — RTO 4 h
APIM secondary unit
same gateway config
APIM secondary unit...
AKS standby
scaled to zero
AKS standby...
Key Vault
backup + restore runbook
Key Vault...
Evidence
Evidence
Immutable archive
GRS, WORM
Immutable archive...
Internet clients
Internet clients
Administrators on PAW
Administrators on PAW
On-premises sync agents
outbound 443 only
On-premises sync agents...
HTTPS 443
HTTPS 443
OIDC metadata + JWKS
OIDC metadata + JWKS
managed identity, private
managed identity, private
PIM-gated session
PIM-gated session
Cloud Sync, outbound only
Cloud Sync, outbound only
geo-replicated export
geo-replicated export
Deployment & Network Architecture
Deployment & Network Architecture
Security / platform
Security / platform
Interface / broker
Interface / broker
Data store
Data store
Application we own
Application we own
External / third party
External / third party
Person or role
Person or role
synchronous
synchronous
batch
batch
The identity plane is not a failure domain we own. A West Europe outage stops our APIs and leaves authentication working, which is why the recovery runbook in view 26 restores gateways and workloads rather than identity.
The identity plane is not a failure domain we own. A West Europe outage stops our APIs and leaves authentication working, which is why the recovery runbook in view 26 restores gateways and workloads rather than identity.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Deployment & Network Architecture What runs where, what is private, and which failure domain belongs to whom. HTML page SVG draw.io
21
Author
Author
IaC repository
Bicep + Terraform azuread
IaC repository...
Policy definitions
deny, audit, DINE
Policy definitions...
CA policies as JSON
38 policies
CA policies as JSON...
Validate
Validate
PR checks
format, lint, PSRule
PR checks...
What-if / plan
no silent role deletes
What-if / plan...
IAM code owners
two-person rule
IAM code owners...
Non-production
Non-production
Deploy DEV
federated credential
Deploy DEV...
Deploy TEST
integration suite
Deploy TEST...
Report-only CA
14 days of signal
Report-only CA...
Gate to production
Gate to production
PIM-activated deployer
60-minute window
PIM-activated deployer...
Change approval
standard or emergency
Change approval...
Compliance scan
Azure Policy, blocking
Compliance scan...
Production & drift
Production & drift
Deploy PROD
5 subscriptions
Deploy PROD...
Drift detector
daily what-if
Drift detector...
Rollback
revert commit, re-apply
Rollback...
destructive plan blocked
destructive plan blocked
non-compliant
non-compliant
raises a PR for manual change
raises a PR for manual change
Identity as Code — how an access change reaches production
Identity as Code — how an access change reaches production
Security / platform
Security / platform
Decision point
Decision point
Interface / broker
Interface / broker
Risk / gap
Risk / gap
failure / alternate
failure / alternate
event / async
event / async
The deploy identity itself holds no standing role: the pipeline federates, activates through PIM, deploys, and expires. Portal changes are not blocked outright — they are detected within 24 hours and reconciled back into the repository, because a control that stops an incident response gets switched off.
The deploy identity itself holds no standing role: the pipeline federates, activates through PIM, deploys, and expires. Portal changes are not blocked outright — they are detected within 24 hours and reconciled back into the repository, because a control that stops an incident response gets switched off.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Identity as Code How an access change reaches production, and what stops a bad one. HTML page SVG draw.io
22
Emit
Emit
Collect
Collect
Store
Store
Detect
Detect
Act
Act
Authentication
Authentication
Sign-in logs
2.6M/day
Sign-in logs...
Diagnostic setting
Diagnostic setting
Log Analytics 90 d
Log Analytics 90 d
Impossible travel, MFA fatigue
Impossible travel, MFA fatigue
Sentinel incident to SOC
Sentinel incident to SOC
Directory change
Directory change
Audit logs
every write
Audit logs...
Diagnostic setting
Diagnostic setting
LAW + 7-year archive
LAW + 7-year archive
Role assigned outside IaC
Role assigned outside IaC
Auto-revert, page IAM
Auto-revert, page IAM
Privileged access
Privileged access
PIM activation events
PIM activation events
Diagnostic setting
Diagnostic setting
Evidence archive
Evidence archive
Activation without ticket
Activation without ticket
Weekly approver review
Weekly approver review
Workload identity
Workload identity
SP sign-ins, MI usage
SP sign-ins, MI usage
Diagnostic setting
Diagnostic setting
Log Analytics
Log Analytics
New IP or ASN for an SP
New IP or ASN for an SP
CA block, rotate credential
CA block, rotate credential
Secrets
Secrets
Key Vault data-plane log
Key Vault data-plane log
Diagnostic setting
Diagnostic setting
LAW + archive
LAW + archive
Bulk read, unusual principal
Bulk read, unusual principal
Disable version, rotate
Disable version, rotate
Entitlement
Entitlement
Provisioning + review logs
Provisioning + review logs
Graph scheduled export
Graph scheduled export
Governance store
Governance store
Dormant 60 days, orphaned
Dormant 60 days, orphaned
Auto-remove, notify owner
Auto-remove, notify owner
Posture
Posture
Defender for Cloud, CIEM
Defender for Cloud, CIEM
Continuous assessment
Continuous assessment
Defender workspace
Defender workspace
Permission creep score
Permission creep score
Right-size in next sprint
Right-size in next sprint
Identity Observability & Detection
Identity Observability & Detection
The matrix exists to make gaps visible. Every row must reach the Act column: a signal that is collected and stored but never acted on is cost without control, and three of these rows were exactly that before this design.
The matrix exists to make gaps visible. Every row must reach the Act column: a signal that is collected and stored but never acted on is cost without control, and three of these rows were exactly that before this design.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Identity Observability & Detection Seven signal families, and what each one causes to happen. HTML page SVG draw.io
23
Scope
Scope
Review scope
packages, groups, roles, guests
Review scope...
Risk tier
privileged every 30 days
Risk tier...
Cadence
apps 90 d, guests 90 d
Cadence...
Assign reviewers
Assign reviewers
Resource owner
named, not a queue
Resource owner...
Line manager
for people-based access
Line manager...
Self-attestation
low risk only
Self-attestation...
Decide
Decide
System recommendation
30-day inactivity signal
System recommendation...
Decision
approve · deny · no response
Decision...
Escalation
no response to owner's manager
Escalation...
Apply
Apply
Remove access
automatic on deny
Remove access...
No-response default
remove — deny by default
No-response default...
Documented exception
14 days, owner accountable
Documented exception...
Evidence
Evidence
Evidence pack
7-year retention
Evidence pack...
Coverage metric
100% privileged, 98% apps
Coverage metric...
Auditor export
read-only, on request
Auditor export...
still no response
still no response
re-reviewed next cycle
re-reviewed next cycle
revocation evidence
revocation evidence
Access Review & Recertification Campaign
Access Review & Recertification Campaign
Security / platform
Security / platform
Decision point
Decision point
Person or role
Person or role
Risk / gap
Risk / gap
Interface / broker
Interface / broker
Data store
Data store
failure / alternate
failure / alternate
event / async
event / async
synchronous
synchronous
The default on silence is removal. A campaign whose no-response path is approval measures reviewer engagement and nothing else, and the exception route is deliberately visible rather than tidy: 14 days, a named owner, re-reviewed next cycle.
The default on silence is removal. A campaign whose no-response path is approval measures reviewer engagement and nothing else, and the exception route is deliberately visible rather than tidy: 14 days, a named owner, re-reviewed next cycle.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Access Review & Recertification Who still needs what, decided by someone who can actually tell. HTML page SVG draw.io

Assurance

The trust boundaries and what crosses them, how tenants are isolated at three layers, the emergency path, and what still fails.
24
Untrusted
Untrusted
Stolen password
spray or replay
Stolen password...
Consent phishing
OAuth lure
Consent phishing...
Unmanaged device
Unmanaged device
Legitimate user
Legitimate user
Identity perimeter
Identity perimeter
Front Door + WAF
Front Door + WAF
Entra STS
smart lockout
Entra STS...
Conditional Access
policy decision point
Conditional Access...
ID Protection
risk evaluation
ID Protection...
Application
Application
API Management
validate-jwt
API Management...
Application workloads
managed identity
Application workloads...
App roles & scopes
App roles & scopes
Privileged
Privileged
Entra PIM
no standing role
Entra PIM...
Privileged workstation
Privileged workstation
Azure Bastion
no public management port
Azure Bastion...
Break-glass
2 accounts, alerted
Break-glass...
Data
Data
Azure SQL & Cosmos
Entra auth, RLS
Azure SQL & Cosmos...
Key Vault
RBAC data plane
Key Vault...
Storage
private endpoint
Storage...
Evidence archive
immutable
Evidence archive...
blocked: lockout + MFA
blocked: lockout + MFA
blocked: consent workflow
blocked: consent workflow
blocked: not compliant
blocked: not compliant
HTTPS 443
HTTPS 443
bearer token required
bearer token required
token issued, 1 h
token issued, 1 h
scope + tenant claim
scope + tenant claim
managed identity, private
managed identity, private
activated session only
activated session only
no data-plane role
no data-plane role
emergency reach, alerted
emergency reach, alerted
Zero-Trust Zones & Enforcement Points
Zero-Trust Zones & Enforcement Points
Risk / gap
Risk / gap
External / third party
External / third party
Person or role
Person or role
Interface / broker
Interface / broker
Security / platform
Security / platform
Application we own
Application we own
Data store
Data store
failure / alternate
failure / alternate
synchronous
synchronous
Every crossing is labelled with what authorises it or what stops it. The two red lines out of the privileged zone are deliberate: an administrator holds control-plane rights and no data-plane rights, so reading a secret is a separate, separately audited grant.
Every crossing is labelled with what authorises it or what stops it. The two red lines out of the privileged zone are deliberate: an administrator holds control-plane rights and no data-plane rights, so reading a secret is a separate, separately audited grant.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Zero-Trust Zones & Enforcement Points Where an attacker arrives, what stops them, and what an administrator still cannot reach. HTML page SVG draw.io
25
Identity layer — separate directories, no shared principal
Identity layer — separate directories, no shared principal
Tenant A
Tenant A
Users
Users
Workload identities
Workload identities
Tenant B
Tenant B
Users
Users
Workload identities
Workload identities
Platform tenant
Platform tenant
Platform operators
PIM + customer approval
Platform operators...
Platform workload identity
no tenant data role
Platform workload identity...
Authorization layer — tid is a mandatory predicate, never an optional filter
Authorization layer — tid is a mandatory predicate, never an optional filter
Claims in the token
Claims in the token
tid
issuing tenant
tid...
oid / sub
subject
oid / sub...
roles / scp
roles / scp
Decisions made from them
Decisions made from them
Tenant predicate
fails closed
Tenant predicate...
App role check
App role check
ABAC condition on RBAC
scope + attribute
ABAC condition on RBAC...
Data layer — isolation proved by storage, not by code review
Data layer — isolation proved by storage, not by code review
Shared services, partitioned
Shared services, partitioned
Cosmos DB
partition key = tenant_id
Cosmos DB...
Azure SQL
row-level security
Azure SQL...
Storage
container per tenant
Storage...
Dedicated, on request
Dedicated, on request
Dedicated database
premium tier
Dedicated database...
Customer-managed key
tenant holds revocation
Customer-managed key...
Private endpoint per tenant
Private endpoint per tenant
Cross-tenant reporting
the one place tenants mix
Cross-tenant reporting...
Support engineer
Support engineer
read from token only
read from token only
session context per request
session context per request
revoke key
revoke key
aggregate only, no row export
aggregate only, no row export
elevation needs tenant approval
elevation needs tenant approval
Multi-Tenant Isolation — identity, authorization, data
Multi-Tenant Isolation — identity, authorization, data
Person or role
Person or role
Security / platform
Security / platform
Decision point
Decision point
Data store
Data store
Risk / gap
Risk / gap
synchronous
synchronous
batch
batch
failure / alternate
failure / alternate
Three layers, because any one of them alone has a known bypass. The honest weak point is drawn: cross-tenant reporting is the single component with a legitimate reason to read every tenant, and it is therefore the component with the smallest surface and the tightest review.
Three layers, because any one of them alone has a known bypass. The honest weak point is drawn: cross-tenant reporting is the single component with a legitimate reason to read every tenant, and it is therefore the component with the smallest surface and the tightest review.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Multi-Tenant Isolation Three layers, because each one alone has a known bypass. HTML page SVG draw.io
26
Detect
Detect
Tenant lockout
CA misconfiguration
Tenant lockout...
Federation outage
external IdP down
Federation outage...
Admin compromise
hostile sessions active
Admin compromise...
Severity call
SecOps duty manager
Severity call...
Authorise use
Authorise use
Two-person rule
holder + witness
Two-person rule...
Credential retrieval
sealed, offline, split
Credential retrieval...
P1 alert fires
on sign-in, no exception
P1 alert fires...
Recover
Recover
Break-glass sign-in
FIDO2 hardware key
Break-glass sign-in...
Re-apply configuration
from the IaC repository
Re-apply configuration...
Revoke hostile sessions
and reset credentials
Revoke hostile sessions...
Microsoft escalation
if break-glass also fails
Microsoft escalation...
Verify
Verify
Normal access restored
sample sign-in per persona
Normal access restored...
Root cause captured
Root cause captured
Evidence pack
every action, timestamped
Evidence pack...
Reset
Reset
Rotate credential
within 24 hours
Rotate credential...
Re-seal and witness
Re-seal and witness
Post-incident review
outcome is a policy change
Post-incident review...
authentication fails
authentication fails
still broken, iterate
still broken, iterate
quarterly rehearsal
quarterly rehearsal
Break-Glass & Identity Recovery
Break-Glass & Identity Recovery
Risk / gap
Risk / gap
Decision point
Decision point
Security / platform
Security / platform
Interface / broker
Interface / broker
Data store
Data store
failure / alternate
failure / alternate
event / async
event / async
Break-glass is tested, not trusted. The quarterly rehearsal drives the loop back to the first stage on purpose: a credential nobody has signed in with for a year is an assumption, and RTO for tenant-level recovery is 4 hours only because it has been measured.
Break-glass is tested, not trusted. The quarterly rehearsal drives the loop back to the first stage on purpose: a credential nobody has signed in with for a year is an assumption, and RTO for tenant-level recovery is 4 hours only because it has been measured.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Break-Glass & Identity Recovery The path that exists precisely because every other path has failed. HTML page SVG draw.io
27
Cause
Cause
First signal
First signal
Containment
Containment
Recovery
Recovery
Residual risk
Residual risk
Entra authentication outage
Entra authentication outage
Regional STS degradation
Regional STS degradation
Token issuance errors
Token issuance errors
Issued tokens valid to 1 h
Issued tokens valid to 1 h
Wait — no local IdP exists
Wait — no local IdP exists
Accepted, no alternative
Accepted, no alternative
Break-glass misuse
Break-glass misuse
Credential taken from vault
Credential taken from vault
P1 on every sign-in
P1 on every sign-in
Revoke sessions, isolate
Revoke sessions, isolate
Rotate, re-seal, review
Rotate, re-seal, review
Two-person rule is procedural
Two-person rule is procedural
Illicit consent grant
Illicit consent grant
OAuth lure to a user
OAuth lure to a user
New SP with Graph scopes
New SP with Graph scopes
Admin consent workflow blocks
Admin consent workflow blocks
Revoke grant, delete SP
Revoke grant, delete SP
Low-risk user consent allowed
Low-risk user consent allowed
Service principal secret leak
Service principal secret leak
Secret in a repo or log
Secret in a repo or log
Sign-in from new ASN
Sign-in from new ASN
CA block, disable version
CA block, disable version
Rotate, migrate to federation
Rotate, migrate to federation
170 principals still hold one
170 principals still hold one
Guest over-entitlement
Guest over-entitlement
Nested group inheritance
Nested group inheritance
90-day guest review
90-day guest review
Remove from nested group
Remove from nested group
Flatten the group model
Flatten the group model
Nesting still two deep
Nesting still two deep
PIM approver compromise
PIM approver compromise
Approver account phished
Approver account phished
Activation without a ticket
Activation without a ticket
Two approvers for tier 0
Two approvers for tier 0
Revoke, reset, re-review
Revoke, reset, re-review
Tier 1 needs one approver
Tier 1 needs one approver
HR feed failure
HR feed failure
Workday API down over 6 h
Workday API down over 6 h
Provisioning job alert
Provisioning job alert
Freeze: no bulk disable on empty feed
Freeze: no bulk disable on empty feed
Backfill after restore
Backfill after restore
Leaver removal delayed
Leaver removal delayed
Dynamic group storm
Dynamic group storm
Reorg touches 40k users
Reorg touches 40k users
Evaluation lag over 30 min
Evaluation lag over 30 min
One rule change per window
One rule change per window
Wait for convergence
Wait for convergence
Access lag during reorgs
Access lag during reorgs
Threats & Failure Modes
Threats & Failure Modes
Every row ends in a residual risk, because a failure-mode table with an empty last column has not been finished. The first row is the honest one: this architecture cannot survive a total identity-provider outage, and no design on Azure can.
Every row ends in a residual risk, because a failure-mode table with an empty last column has not been finished. The first row is the honest one: this architecture cannot survive a total identity-provider outage, and no design on Azure can.
v 1.0 · owner Data & AI Global Practice · date 2026-08
v 1.0 · owner Data & AI Global Practice · date 2026-08
Text is not SVG - cannot display
Threats & Failure Modes Eight ways this platform is degraded or attacked, and what is left over after the mitigation. HTML page SVG draw.io
Open svg/<view>.svg or drawio/<view>.drawio in draw.io Desktop or at app.diagrams.net to edit. The SVG carries the diagram inside it, so it is both the picture and the source. This folder is self-contained — copy it whole and every link still resolves.