Cloud Security Stack
Architecture notes

Architecture

Identity is the control plane, everything else is downstream

Why buying another security product rarely fixes what a weak identity design broke, and the four decisions that determine whether the rest of your controls can work at all.

11 min read · Reviewed 22 August 2026 · Architecture notes. Opinionated, and drawn from tenant builds rather than reference architectures.

The pattern

Work through enough incidents in Microsoft estates and the same shape keeps appearing. The proximate cause is a phished credential, a token replay, an over-permissioned service principal. The actual cause is an identity decision made years earlier by someone with no reason to think it mattered, and every control layered on top has been quietly compensating for it since.

This is why buying another product so often fails to change the outcome. Endpoint, network and data controls all evaluate a request that identity has already decided to trust. If that decision is wrong, the downstream controls are being asked to catch something they were never positioned to see.

The four decisions that determine everything else

01

What counts as a trusted device

If device compliance is not a condition of access, then every access decision reduces to whether someone holds a credential. Conditional Access without a device signal is a policy about passwords wearing the language of Zero Trust.

02

Who holds standing privilege

Permanent Global Administrator assignments are the single most common finding worth acting on. Privileged Identity Management exists precisely so that privilege is a thing you request, hold briefly and give back. An estate with five permanent Global Admins has five permanent single points of compromise.

03

How service principals are governed

The identities nobody reviews. Application registrations accumulate, consent is granted once by someone who has since left, and the permissions outlive the project. These have no MFA, no device state and frequently no owner.

04

What happens at offboarding

Whether access genuinely stops the day someone leaves, including their tokens, their app passwords and the shared account they set up. Offboarding is where identity design is honestly tested, and it is almost never rehearsed.

Where control effort usually goes, against where the leverage is

An argument rather than a measurement. It reflects how budget tends to be allocated in the estates these notes come from.

  • Identity and access design45
  • Endpoint tooling25
  • Network segmentation20
  • Data controls10

Values express relative leverage in our view. They are not survey data and should not be cited as such.

What breaks in year two

Almost nothing breaks in year one, which is the difficulty. A tenant built quickly works well while the people who built it are still there and the exception list is short.

Year two is when the exception list has grown. A break-glass account created during a migration is still enabled. A Conditional Access exclusion group added for one contractor now has eleven members. A legacy authentication allowance kept for one scanner is still open. None of these is a mistake exactly. Together they are the architecture, and nobody decided on them.

The uncomfortable part

Identity work is difficult to fund because it produces nothing to demonstrate. There is no console to show the board, no dashboard, no reduction in alert volume to point at. Removing standing privilege and enforcing device compliance mostly produces complaints from people who were previously unblocked.

It remains the highest-leverage work available in a Microsoft estate, and the only honest way to fund it is to be specific about which incident it prevents rather than describing it as maturity or hygiene.

The verdict

Our pick

Fix standing privilege first

It is the cheapest of the four, it needs no new licence in most tenants with Entra ID P2, and it removes the specific condition that turns one phished account into a tenant-wide event.

Who should skip

Do not start with network segmentation. It is the most expensive, the slowest, and it protects least while identity remains the weak point.

Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.