Architecture
Identity is the control plane, everything else is downstream
Why buying another security product rarely fixes what a weak identity design broke, and the four decisions that determine whether the rest of your controls can work at all.
The pattern
Work through enough incidents in Microsoft estates and the same shape keeps appearing. The proximate cause is a phished credential, a token replay, an over-permissioned service principal. The actual cause is an identity decision made years earlier by someone with no reason to think it mattered, and every control layered on top has been quietly compensating for it since.
This is why buying another product so often fails to change the outcome. Endpoint, network and data controls all evaluate a request that identity has already decided to trust. If that decision is wrong, the downstream controls are being asked to catch something they were never positioned to see.
The four decisions that determine everything else
What counts as a trusted device
If device compliance is not a condition of access, then every access decision reduces to whether someone holds a credential. Conditional Access without a device signal is a policy about passwords wearing the language of Zero Trust.
Who holds standing privilege
Permanent Global Administrator assignments are the single most common finding worth acting on. Privileged Identity Management exists precisely so that privilege is a thing you request, hold briefly and give back. An estate with five permanent Global Admins has five permanent single points of compromise.
How service principals are governed
The identities nobody reviews. Application registrations accumulate, consent is granted once by someone who has since left, and the permissions outlive the project. These have no MFA, no device state and frequently no owner.
What happens at offboarding
Whether access genuinely stops the day someone leaves, including their tokens, their app passwords and the shared account they set up. Offboarding is where identity design is honestly tested, and it is almost never rehearsed.
Where control effort usually goes, against where the leverage is
An argument rather than a measurement. It reflects how budget tends to be allocated in the estates these notes come from.
- Identity and access design45
- Endpoint tooling25
- Network segmentation20
- Data controls10
Values express relative leverage in our view. They are not survey data and should not be cited as such.
What breaks in year two
Almost nothing breaks in year one, which is the difficulty. A tenant built quickly works well while the people who built it are still there and the exception list is short.
Year two is when the exception list has grown. A break-glass account created during a migration is still enabled. A Conditional Access exclusion group added for one contractor now has eleven members. A legacy authentication allowance kept for one scanner is still open. None of these is a mistake exactly. Together they are the architecture, and nobody decided on them.
The uncomfortable part
Identity work is difficult to fund because it produces nothing to demonstrate. There is no console to show the board, no dashboard, no reduction in alert volume to point at. Removing standing privilege and enforcing device compliance mostly produces complaints from people who were previously unblocked.
It remains the highest-leverage work available in a Microsoft estate, and the only honest way to fund it is to be specific about which incident it prevents rather than describing it as maturity or hygiene.
The verdict
Fix standing privilege first
It is the cheapest of the four, it needs no new licence in most tenants with Entra ID P2, and it removes the specific condition that turns one phished account into a tenant-wide event.
Do not start with network segmentation. It is the most expensive, the slowest, and it protects least while identity remains the weak point.
Disclosure. Some links on this site are affiliate links. Scoring weights are published before any programme is joined, and commission is never a ranking input. Full policy, and the method behind this guide.