This directory contains whitepapers related to Azure security, identity, compliance, and threat protection.
- Zero Trust Architecture with Azure Services — Identity-first controls, microsegmentation, Private Link, data protection, and Sentinel-driven detection/response for Azure landing zones.
- Azure AD Implementation and Best Practices — Tenant baseline, Conditional Access, PIM JIT, app SSO/provisioning, workload identities, and continuous monitoring.
- Key Vault Deployment and Secret Rotation Strategies — Hardened vault deployments, private endpoints, RBAC-only access, automated secret/key/cert rotation, monitoring, and policy guardrails.
- Compliance Automation and Governance with Azure — Policy/initiative guardrails, Defender for Cloud regulatory standards, landing zone governance, Purview data protection, evidence/monitoring pipelines, and automated remediation.
- Azure Security Center and Threat Protection — Defender for Cloud onboarding, secure score/initiative baselines, threat detections, Sentinel analytics, and automated incident response playbooks.
Security patterns are also embedded throughout existing whitepapers:
- Securing Data Platforms in Azure Commercial
- Azure Network Security Best Practices
- Azure Well-Architected Framework — Security pillar
Interested in authoring a security whitepaper? Open a whitepaper request or see CONTRIBUTING.md.
Last Updated: August 2026