Skip to main content
emnode
Learning path

Harden Azure identity

MFA, least-privilege RBAC and managed identities across Entra and your subscriptions.

5 lessons·~70 min total

Lessons in this path

  1. 1
    Compliance AZURE

    Require Microsoft Entra authentication

    One capability across virtual machines, SQL, Synapse, Cosmos DB and Service Fabric: make sure access is proven by a managed Microsoft Entra identity rather than a shared password, account key or local credential that nobody can revoke centrally.

    14 min
  2. 2
    Compliance AZURE

    Keep Azure privileged access clean

    One capability across every subscription and resource group: make sure nobody, and nothing, holds standing high privilege they do not actively use. Revoke the access of identities that have gone quiet, and convert permanent Owner and Contributor assignments to just-in-time access that expires on its own.

    14 min
  3. 3
    Compliance AZURE

    Apply least-privilege RBAC on Azure subscriptions

    One capability across every subscription: make sure the people with the most power, the Owners and other privileged role holders, are the smallest possible set of named, current, internal accounts, and that nobody and nothing keeps standing access it no longer needs.

    14 min
  4. 4
    Compliance AZURE

    Remove stale and external Azure identities

    One capability across blocked, deprecated, external and guest accounts: make sure no identity that has left, been disabled, or belongs to another organisation still carries standing access to your Azure subscriptions and resources, unless you genuinely intend it.

    14 min
  5. 5
    Compliance AZURE

    Use managed identities instead of stored secrets

    One capability across web apps and function apps: stop authenticating to Azure services with a connection string or client secret baked into config, and let the platform issue and rotate the credential for you so there is nothing left to leak.

    14 min