IaaS
You manage more. With virtual machines, the cloud provider handles physical infrastructure, but you still manage the operating system, patches, apps, identity choices, and data.
Cloud security basics
In cloud computing, security is not entirely Microsoft’s job and not entirely the customer’s job. The shared responsibility model explains where the line is.
Simple version
Microsoft secures the physical datacenters, physical network, and physical hosts. Customers always retain responsibility for their data, identities, accounts, and endpoints. Responsibility for operating systems, applications, network controls, and other components shifts from the customer to Microsoft as you move from IaaS to PaaS to SaaS.
You manage more. With virtual machines, the cloud provider handles physical infrastructure, but you still manage the operating system, patches, apps, identity choices, and data.
Responsibility shifts toward the provider. You focus more on your application, data, users, and configuration while the provider manages the runtime and operating system.
The provider manages most of the application stack. You still manage users, data, access policies, endpoint security, and tenant-level security settings.
Common exam trap
Even with SaaS, the customer must control access, classify and protect data, secure user accounts and endpoints, and configure the tenant appropriately. The service model changes which responsibilities remain with the customer.
Practice-style examples
The customer. The provider secures the underlying platform, but the customer controls access decisions, identities, roles, and data handling.
The customer. An Azure virtual machine is IaaS, so the customer is responsible for patching and securing the guest operating system.
Yes. The provider runs the service, but the customer still manages users, data, access policies, device practices, and security settings.