A support engineer at CRED gets paged at 2 AM because a production database ran out of disk space - an event that a properly configured Azure Monitor alert would have flagged hours earlier, giving the team time to react before customers noticed anything. This pillar covers what it actually takes to run Azure in production long-term - identity security beyond basic passwords, proactive monitoring instead of reactive firefighting, and backup strategies that are actually tested, not just configured and forgotten.
What This Pillar Covers
- Enforcing Multi-Factor Authentication and Conditional Access policies based on real risk signals
- Using Managed Identities so application code never contains a hardcoded credential
- Building Azure Monitor alert rules and Action Groups that notify the right people at the right time
- Querying logs with Kusto Query Language (KQL) to actually find the root cause of an incident
- Configuring Azure Backup and Recovery Services Vaults with retention that matches business needs
- Improving Secure Score with Microsoft Defender for Cloud's prioritized recommendations
- Distinguishing Azure AD (Entra ID) from traditional on-premises Active Directory
Who This Is For
Site reliability engineers, cloud administrators, and security-focused DevOps engineers responsible for keeping Azure identities secure, catching production incidents before customers do, and ensuring data can actually be recovered when something goes wrong.
Why This Matters in Production
At a trading platform like Zerodha, a compromised account without MFA enforced can mean an attacker walks straight into production systems with a single stolen password - Conditional Access policies that require additional verification from unfamiliar locations close exactly this gap. Elsewhere, a completed backup job that was never actually test-restored is not a safety net at all - it is an unverified assumption that only gets tested during the worst possible moment, a real incident.
Prerequisites
- Completion of Azure Fundamentals and Governance, or equivalent familiarity with Resource Groups and RBAC
- Basic understanding of authentication concepts (passwords, tokens, multi-factor authentication)
- Familiarity with reading logs or basic query languages is helpful for the KQL topic