Events
Microsoft 365 Community Conference
May 6, 2 PM - May 9, 12 AM
Skill up for the era of AI at the ultimate community-led Microsoft 365 event, May 6-8 in Las Vegas.
Learn moreThis browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Note
This is article 5 of 6 in Build applications on the Microsoft Cloud.
Good security protects your systems, and therefore your organization, against accidental and intentional damage. It assures that only the right people can access your resources and minimizes the possibility that they can do inadvertent harm. It also warns you of dangers, violations, and other important security events.
This article discusses ways that Microsoft Cloud can help you secure your systems.
In our cloud-based world, employees and customers can access your custom applications from many devices in many different locations. Granting access to the right people, with the right restrictions, depends fundamentally on identity. Good security requires that each user prove their identity before they can access systems, and that they only access the resources they require to do their job.
Building the software to do this is hard. It requires specialists, and it takes time to get right, so you definitely don’t want to build your own. Just as important, identity should be as simple to use as possible, both for your users and your developers. Ideally, you’d like a uniform way to manage identity throughout your environment.
This is what the Microsoft Cloud provides with Microsoft Entra ID, the world’s largest cloud identity service. If your organization uses any components of the Microsoft Cloud today, such as Azure, Power Platform, Microsoft 365, or Dynamics 365, you’re already using Microsoft Entra ID. It's used throughout the Microsoft Cloud, giving your users a single identity for all of its components.
Your custom applications built on the Microsoft Cloud should also use Microsoft Entra ID. Figure 9 shows how this looks for our sample application.
Figure 9: Microsoft Entra ID and Azure Active Directory B2C provide a common identity service for applications built on the Microsoft cloud.
As the figure shows, custom applications can use two related identity services:
Using Microsoft Entra ID for identity brings several benefits:
Getting identity and access management right is a fundamental part of doing security well. Building applications on the Microsoft Cloud with Microsoft Entra ID makes this goal easier to achieve.
Everybody building applications today should assume that their software is targeted by attackers. Given this, your organization must continuously monitor and manage the security of your applications and the environment that they run in. The Microsoft Cloud provides several tools for doing this.
One of the most important of these is Microsoft Sentinel. Microsoft Sentinel provides security information and event management (SIEM), letting you capture and analyze a wide range of security-related data. It can also respond automatically to threats, providing security orchestration, automation, and response (SOAR). Microsoft Sentinel can help your organization find and fix security problems more effectively.
Microsoft Sentinel’s broad reach encompasses the Microsoft Cloud and beyond through a large set of connectors. These connectors let Microsoft Sentinel interact with many other services and technologies. Among the most important of these are the Microsoft Defender tools, including:
Microsoft Sentinel can also import Office 365 audit logs, Azure activity logs, and other security relevant information within the Microsoft Cloud. Microsoft Sentinel can also access security related information from many other sources provided by a diverse set of vendors. Once you’ve connected Microsoft Sentinel to your information sources, you can analyze the data to understand security incidents and respond to them.
Security isn’t a simple topic. Because of this, Microsoft provides Microsoft Sentinel and other security offerings to address this area. All these technologies work together to improve the security of applications running on the Microsoft Cloud.
See a summary of Build applications on the Microsoft Cloud and find out how to learn more about succeeding as an enterprise application development leader.
Events
Microsoft 365 Community Conference
May 6, 2 PM - May 9, 12 AM
Skill up for the era of AI at the ultimate community-led Microsoft 365 event, May 6-8 in Las Vegas.
Learn more