You are on page 1of 11

Microsoft Security, Compliance, and

Identity Fundamentals: Concepts


Cloud Computing: Who Secures What?

Vlad Catrinescu
Office Apps and Services MVP
@vladcatrinescu https://VladTalksTech.com
Types of Cloud Computing Services
Overview
- Infrastructure as a Service
- Platform as a Service
- Software as a Service

Cloud Computing: Who Secures What?


- Some responsibilities are always on the
customer!
Types of Cloud Computing Services

Infrastructure Platform Software


as a Service as a Service as a Service
(IaaS) (PaaS) (SaaS)
Types of Cloud Computing Services
On-premises IaaS PaaS SaaS

Applications Applications Applications Applications


Data Data Data Data
Runtime Runtime Runtime Runtime
Middleware Middleware Middleware Middleware
OS OS OS OS
Virtualization Virtualization Virtualization Virtualization
Servers Servers Servers Servers
Storage Storage Storage Storage
Networking Networking Networking Networking

You manage Managed by vendor


You manage

Pizza as a Service Managed by vendor

On-premises IaaS PaaS SaaS

Dining table Dining table Dining table Dining table


Soda Soda Soda Soda
Electric/Gas Electric/Gas Electric/Gas Electric/Gas
Oven Oven Oven Oven
Fire Fire Fire Fire
Pizza dough Pizza dough Pizza dough Pizza dough
Tomato sauce Tomato sauce Tomato sauce Tomato sauce
Toppings Toppings Toppings Toppings
Cheese Cheese Cheese Cheese

Made at home Take and bake Pizza delivery Dine out


Most Companies Use Products from Each Service Type

IaaS PaaS SaaS

Azure Logic Apps


SharePoint
Azure Compute Azure Functions
(Virtual
Machines) OneDrive for
Azure Business
Web Apps
Azure Storage
Microsoft Teams
Azure
Automation
Security in the Cloud Is a Partnership

The cloud provider operates and secures


- The base infrastructure
- Host operating system layers

You control and secure


- Identities
- Additional application settings (ex: MFA)
The responsibilities and controls for the
security of applications and networks vary by
the service type
Who Secures What? – The Shared Responsibility Model
On-Premises IaaS PaaS SaaS

Information and data Information and data Information and data Information and data

Devices (Mobile and PCs) Devices (Mobile and PCs) Devices (Mobile and PCs) Devices (Mobile and PCs)

Accounts and identities Accounts and identities Accounts and identities Accounts and identities

Identity & directory Identity & directory Identity & directory Identity & directory
infrastructure infrastructure infrastructure infrastructure

Application Application Application Application

Network controls Network controls Network controls Network controls

Operating system Operating system Operating system Operating system

Physical hosts Physical hosts Physical hosts Physical hosts

Physical network Physical network Physical network Physical network

Physical datacenter Physical datacenter Physical datacenter Physical datacenter

Cloud Provider Customer


It’s your duty to know what
your security responsibilities
are for each type of workload
you leverage in the cloud
Types of Cloud Computing Services
- Infrastructure as a Service
- Platform as a Service
Conclusion - Software as a Service

Shared Responsibility Model


- Different responsibilities depending on
cloud service type
- Some responsibilities are always retained
by the customer!
• Information and data
• Devices
• Accounts and identities
Up Next:
Basic Security Concepts & Methodologies
in the Microsoft Cloud

You might also like