Harden Azure identity
MFA, least-privilege RBAC and managed identities across Entra and your subscriptions.
Lessons in this path
- 1 Compliance AZURE
Require Microsoft Entra authentication
One capability across virtual machines, SQL, Synapse, Cosmos DB and Service Fabric: make sure access is proven by a managed Microsoft Entra identity rather than a shared password, account key or local credential that nobody can revoke centrally.
14 min - 2 Compliance AZURE
Keep Azure privileged access clean
One capability across every subscription and resource group: make sure nobody, and nothing, holds standing high privilege they do not actively use. Revoke the access of identities that have gone quiet, and convert permanent Owner and Contributor assignments to just-in-time access that expires on its own.
14 min - 3 Compliance AZURE
Apply least-privilege RBAC on Azure subscriptions
One capability across every subscription: make sure the people with the most power, the Owners and other privileged role holders, are the smallest possible set of named, current, internal accounts, and that nobody and nothing keeps standing access it no longer needs.
14 min - 4 Compliance AZURE
Remove stale and external Azure identities
One capability across blocked, deprecated, external and guest accounts: make sure no identity that has left, been disabled, or belongs to another organisation still carries standing access to your Azure subscriptions and resources, unless you genuinely intend it.
14 min - 5 Compliance AZURE
Use managed identities instead of stored secrets
One capability across web apps and function apps: stop authenticating to Azure services with a connection string or client secret baked into config, and let the platform issue and rotate the credential for you so there is nothing left to leak.
14 min